SC-400 Audit and Monitoring 3 — Questions and Answers
Question 1: A compliance officer needs audit log data retained for 5 years to meet regulatory requirements. Which Microsoft Purview Audit (Premium) feature supports this?
- Default audit retention policy
- Custom audit retention policy with 5-year duration (Correct answer)
- Litigation Hold
- eDiscovery case hold
Correct answer: Custom audit retention policy with 5-year duration
Custom audit retention policies in Audit (Premium) allow organizations to retain audit logs for up to 10 years with appropriate licensing.
Question 2: Which workloads are covered by the Microsoft 365 unified audit log? (Select the best answer)
- Only Exchange Online and SharePoint Online
- Exchange Online, SharePoint Online, OneDrive, Teams, and Azure AD (Correct answer)
- Only Azure AD and Microsoft Teams
- Only on-premises Exchange and SharePoint
Correct answer: Exchange Online, SharePoint Online, OneDrive, Teams, and Azure AD
The unified audit log captures events across Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, Azure AD, and other Microsoft 365 services.
Question 3: A security analyst notices audit records are missing for the period when a suspected breach occurred. What is the most likely reason?
- The audit log was purged by an admin
- Auditing was not enabled during that period (Correct answer)
- Audit logs are only retained for 24 hours by default
- The user accessed resources from outside the US
Correct answer: Auditing was not enabled during that period
If auditing was disabled during the breach window, no records would exist for that period, creating gaps in the audit trail.
Question 4: Which Microsoft Purview feature allows you to stream audit log data in near real-time to Azure services like Event Hub or Storage?
- Audit log export (CSV)
- Microsoft Purview Audit streaming via Office 365 Management Activity API (Correct answer)
- Content Search export
- Compliance Manager assessments
Correct answer: Microsoft Purview Audit streaming via Office 365 Management Activity API
The Office 365 Management Activity API enables near real-time streaming of audit events to external systems such as Azure Event Hub or Storage.
Question 5: When configuring an audit log search, which date/time zone do the start and end times correspond to?
- The administrator's local time zone
- UTC (Coordinated Universal Time) (Correct answer)
- The tenant's registered country time zone
- Pacific Standard Time (PST)
Correct answer: UTC (Coordinated Universal Time)
All audit log timestamps in Microsoft Purview use UTC, so search date/time parameters must be specified in UTC.
Question 6: An organization wants to monitor for bulk email deletion events in Exchange Online. Which audit record activity type should they filter for?
- FolderBind
- HardDelete (Correct answer)
- SoftDelete
- MoveToDeletedItems
Correct answer: HardDelete
HardDelete in Exchange audit logs records permanent deletion of messages, which is critical to monitor for data destruction or exfiltration scenarios.
Question 7: Which role is required to search and view the audit log in the Microsoft Purview compliance portal?
- Global Reader
- View-Only Audit Logs or Audit Logs role in Exchange Online (Correct answer)
- SharePoint Administrator
- Security Operator
Correct answer: View-Only Audit Logs or Audit Logs role in Exchange Online
Users must be assigned the View-Only Audit Logs or Audit Logs role in Exchange Online permissions to access audit log search.
A compliance officer needs audit log data retained for 5 years to meet regulatory requirements.
Which Microsoft Purview Audit (Premium) feature supports this?