SC-400 Audit and Monitoring 4 — Questions and Answers
Question 1: A company must demonstrate that no admin has accessed a sensitive SharePoint site in the past 6 months. Which audit feature best supports this?
- Communication Compliance reports
- Audit log search filtered by site URL and admin accounts (Correct answer)
- Insider Risk Management activity explorer
- Microsoft Secure Score
Correct answer: Audit log search filtered by site URL and admin accounts
Audit log search can be filtered by specific SharePoint site URLs and user accounts to produce a report of all access events.
Question 2: What does the RecordType field in a Microsoft 365 audit log entry indicate?
- The sensitivity label applied to the file
- The Microsoft 365 service or feature that generated the event (Correct answer)
- The retention policy applied to the record
- The geographic region where the activity occurred
Correct answer: The Microsoft 365 service or feature that generated the event
The RecordType field identifies which Microsoft 365 workload or feature produced the audit event, such as SharePoint, Exchange, or Azure AD.
Question 3: Which Microsoft 365 feature enables administrators to receive daily email digests of high-risk activities detected by default alert policies?
- Audit log search scheduled export
- Default alert policies with email notification configured (Correct answer)
- Microsoft Defender for Cloud Apps
- Microsoft Secure Score recommendations
Correct answer: Default alert policies with email notification configured
Default alert policies in Microsoft Purview can be configured to send email notifications to admins when triggered by predefined high-risk activities.
Question 4: An insider risk investigator needs to correlate audit data with user behavior analytics. Which Microsoft Purview solution provides this integration natively?
- Audit (Standard)
- Insider Risk Management (Correct answer)
- eDiscovery Premium
- Compliance Manager
Correct answer: Insider Risk Management
Microsoft Purview Insider Risk Management natively ingests audit signals and applies machine learning to identify risky user behavior patterns.
Question 5: When using Search-UnifiedAuditLog in PowerShell, what is the maximum number of records returned per call?
- 100
- 1000
- 5000
- 50000 (Correct answer)
Correct answer: 50000
Search-UnifiedAuditLog returns up to 5,000 results per call; pagination using the SessionId and SessionCommand parameters is needed for larger result sets.
Question 6: A forensic investigator needs to determine which mail folders a compromised account accessed during a breach. Which Audit (Premium) event provides this data?
- Send
- MailItemsAccessed (Correct answer)
- UpdateInboxRules
- MessageBind
Correct answer: MailItemsAccessed
MailItemsAccessed is an Audit Premium event that records which mail items and folders were accessed, enabling forensic reconstruction of attacker activity.
Question 7: Which tool can be used to automate recurring audit log searches and export results to SharePoint or OneDrive for compliance reporting?
- Microsoft Purview Content Search
- Power Automate with Office 365 Management Activity API (Correct answer)
- Microsoft Sentinel KQL queries only
- Azure Logic Apps with manual trigger only
Correct answer: Power Automate with Office 365 Management Activity API
Power Automate can use the Office 365 Management Activity API connector to schedule recurring audit data pulls and store results in SharePoint or OneDrive.
A company must demonstrate that no admin has accessed a sensitive SharePoint site in the past 6 months.
Which audit feature best supports this?