SC-400 Audit and Monitoring 2 — Questions and Answers
Question 1: An administrator needs to search audit logs for all activities performed by a specific user over the last 90 days. Which Microsoft Purview portal section should they use?
- Content Search
- Audit (Standard) (Correct answer)
- Communication Compliance
- Insider Risk Management
Correct answer: Audit (Standard)
Audit (Standard) in the Microsoft Purview compliance portal allows searching audit logs for user and admin activities up to 90 days.
Question 2: Which license is required to retain audit logs for up to one year with Microsoft Purview Audit (Premium)?
- Microsoft 365 E1
- Microsoft 365 E3
- Microsoft 365 E5 or Microsoft 365 E5 Compliance add-on (Correct answer)
- Microsoft 365 Business Basic
Correct answer: Microsoft 365 E5 or Microsoft 365 E5 Compliance add-on
Microsoft Purview Audit (Premium) with one-year retention requires Microsoft 365 E5 or the E5 Compliance add-on.
Question 3: A security team wants to be alerted whenever a user downloads more than 50 files from SharePoint within one hour. Which feature should they configure?
- Audit log search
- Alert policy in Microsoft Purview (Correct answer)
- Communication Compliance policy
- Data Loss Prevention policy
Correct answer: Alert policy in Microsoft Purview
Alert policies in Microsoft Purview can trigger notifications based on activity thresholds such as file downloads exceeding a defined count.
Question 4: What is the primary benefit of high-value audit events available in Microsoft Purview Audit (Premium)?
- They extend retention to 10 years automatically
- They provide granular mail access events like MailItemsAccessed for forensic investigation (Correct answer)
- They allow real-time streaming to Azure Event Hub
- They replace the need for Microsoft Sentinel integration
Correct answer: They provide granular mail access events like MailItemsAccessed for forensic investigation
Audit (Premium) includes high-value events such as MailItemsAccessed, which provide detailed forensic data for investigating email compromise.
Question 5: An organization wants to export audit log results for analysis in a SIEM tool. What file format does the Microsoft Purview audit log export produce?
- XML
- JSON
- CSV (Correct answer)
- PARQUET
Correct answer: CSV
Audit log search results in Microsoft Purview can be exported as a CSV file for use in external analysis tools.
Question 6: Which PowerShell cmdlet is used to search the unified audit log programmatically in Microsoft 365?
- Get-AuditLog
- Search-UnifiedAuditLog (Correct answer)
- Get-ComplianceSearch
- Invoke-AuditSearch
Correct answer: Search-UnifiedAuditLog
Search-UnifiedAuditLog is the Exchange Online PowerShell cmdlet used to query the Microsoft 365 unified audit log.
Question 7: Audit logging must be enabled before audit records are generated. Which statement about audit log enablement in Microsoft 365 is correct?
- Auditing is disabled by default for all tenants and must be manually enabled
- Auditing is enabled by default for Microsoft 365 tenants created after 2019 (Correct answer)
- Auditing requires a minimum of Microsoft 365 E3 to be enabled
- Auditing can only be enabled through PowerShell
Correct answer: Auditing is enabled by default for Microsoft 365 tenants created after 2019
For Microsoft 365 tenants created after October 2019, auditing is turned on by default; older tenants may need manual enablement.
An administrator needs to search audit logs for all activities performed by a specific user over the last 90 days.
Which Microsoft Purview portal section should they use?