SC-400 Communication Compliance 3 — Questions and Answers
Question 1: A company wants to prevent reviewers from accessing the actual content of flagged messages in Communication Compliance unless escalated. Which feature can help maintain this separation?
- Communication Compliance Analysts role with limited remediation rights (Correct answer)
- Enabling message encryption for all captured content
- Configuring a two-stage review workflow with escalation
- Using a keyword-only policy with no message body capture
Correct answer: Communication Compliance Analysts role with limited remediation rights
The Communication Compliance Analysts role group allows members to view alert metadata and manage cases but restricts access to full message content, supporting separation of duties.
Question 2: An organization needs to capture Yammer messages in addition to email and Teams for compliance review. What must be configured for Yammer content to appear in Communication Compliance?
- Deploy the Yammer compliance connector in Microsoft 365
- Enable Yammer in Native Mode for the Microsoft 365 tenant (Correct answer)
- Install the Yammer compliance agent on all user devices
- Configure a DLP policy that forwards Yammer messages to compliance
Correct answer: Enable Yammer in Native Mode for the Microsoft 365 tenant
Yammer content is only available for Communication Compliance supervision when the Yammer network is in Native Mode for Microsoft 365.
Question 3: A reviewer uses the 'Tag as' feature in Communication Compliance. What is the purpose of tagging an alert?
- It automatically escalates the alert to legal counsel
- It classifies the alert for tracking, reporting, and workflow management (Correct answer)
- It removes the alert from the review queue permanently
- It sends a notification to the supervised user
Correct answer: It classifies the alert for tracking, reporting, and workflow management
Tagging alerts in Communication Compliance helps reviewers classify and organize items for tracking, reporting, and managing the review workflow.
Question 4: What happens to communications captured by a Communication Compliance policy when the policy is deleted?
- All captured communications are immediately deleted
- Previously captured communications remain accessible until their retention period expires (Correct answer)
- The communications are archived to Azure Blob Storage automatically
- The policy deletion is blocked if unresolved alerts exist
Correct answer: Previously captured communications remain accessible until their retention period expires
Deleting a Communication Compliance policy stops new captures, but previously captured and reviewed communications remain accessible based on their configured retention period.
Question 5: A financial services firm must demonstrate to auditors that all flagged communications were reviewed within 48 hours. Which Communication Compliance feature supports this audit requirement?
- Communication Compliance audit log reports
- Alert aging reports showing review timestamps (Correct answer)
- Sensitivity label audit reports
- DLP incident reports
Correct answer: Alert aging reports showing review timestamps
Communication Compliance provides reports including alert aging information with timestamps, allowing organizations to demonstrate timely review of flagged communications.
Question 6: An administrator configures a Communication Compliance policy and sets the message direction to 'Inbound.' What communications will this policy capture?
- Only messages sent by supervised users to external recipients
- Only messages received by supervised users from external senders (Correct answer)
- Messages sent between supervised users internally
- All messages regardless of direction
Correct answer: Only messages received by supervised users from external senders
Setting message direction to 'Inbound' captures communications received by supervised users from external senders, not messages they send.
Question 7: A compliance team wants to use Communication Compliance to detect potential collusion between traders at different firms. Which condition type is specifically designed to help identify this risk?
- Profanity condition
- Threat condition
- Regulatory collusion trainable classifier (Correct answer)
- Sensitive information type condition for financial data
Correct answer: Regulatory collusion trainable classifier
Microsoft Purview's 'Regulatory Collusion' trainable classifier is designed to detect language indicative of potential collusion, such as market manipulation discussions.
A company wants to prevent reviewers from accessing the actual content of flagged messages in Communication Compliance unless escalated.
Which feature can help maintain this separation?