SC-400 Communication Compliance 5 — Questions and Answers
Question 1: A compliance administrator wants to monitor third-party collaboration platforms like Zoom chat in Communication Compliance. What is the prerequisite for ingesting this data?
- Purchase a Zoom compliance license directly from Zoom
- Configure a third-party data connector in Microsoft Purview to import Zoom data (Correct answer)
- Deploy a Microsoft agent on all endpoints running Zoom
- Enable Zoom native integration through Microsoft Teams admin center
Correct answer: Configure a third-party data connector in Microsoft Purview to import Zoom data
Third-party platform data like Zoom chat must be imported into Microsoft 365 using a data connector configured in the Microsoft Purview compliance portal before it can be monitored.
Question 2: A Communication Compliance policy uses the 'Threat' built-in classifier. What type of language is this classifier designed to detect?
- Language indicating potential market manipulation or insider trading
- Language that threatens physical violence or harm to individuals (Correct answer)
- Language involving profanity or offensive workplace conduct
- Language suggesting regulatory non-compliance in financial reporting
Correct answer: Language that threatens physical violence or harm to individuals
The 'Threat' classifier in Communication Compliance is designed to identify messages containing language that threatens physical violence or harm to individuals or property.
Question 3: When a Communication Compliance policy generates more alerts than reviewers can handle, what is the recommended approach to prioritize review efforts?
- Increase the number of reviewers assigned to the policy
- Use alert filters and sorting by risk score to prioritize high-severity items (Correct answer)
- Delete low-priority alerts without reviewing them
- Pause the policy until the backlog is cleared
Correct answer: Use alert filters and sorting by risk score to prioritize high-severity items
Communication Compliance provides filters and risk scoring to help reviewers prioritize high-severity or high-risk alerts when alert volume is high.
Question 4: A company is configuring Communication Compliance and wants to ensure the policy captures all communication types supported by the service. Which combination of channels is currently supported?
- Email, Teams, Yammer, and Skype for Business only
- Email, Teams, Yammer, and third-party connectors (Correct answer)
- Email and Teams only, with Yammer planned for future release
- Email, Teams, SharePoint sites, and OneDrive files
Correct answer: Email, Teams, Yammer, and third-party connectors
Communication Compliance supports supervision of email, Microsoft Teams, Yammer (in Native Mode), and third-party data imported via connectors.
Question 5: An administrator sets up a Communication Compliance policy for a healthcare organization and wants to detect discussions of patient information in non-secure channels. Which condition is MOST appropriate?
- Keyword condition with medical terminology
- Sensitive information type condition for health information (Correct answer)
- Profanity classifier
- Threat classifier
Correct answer: Sensitive information type condition for health information
The sensitive information type condition can detect patterns like US medical record numbers, health insurance information, or other PHI patterns to identify patient data sharing.
Question 6: A reviewer in Communication Compliance selects the 'Escalate' remediation action. To which Microsoft Purview solution is the case escalated by default?
- Microsoft Purview Insider Risk Management
- Microsoft Purview eDiscovery (Premium) (Correct answer)
- Microsoft Purview Data Loss Prevention incidents
- Microsoft Purview Audit
Correct answer: Microsoft Purview eDiscovery (Premium)
The 'Escalate' action in Communication Compliance creates a case in Microsoft Purview eDiscovery (Premium) for deeper legal investigation.
Question 7: A company wants to implement Communication Compliance but needs to ensure that policy configuration and alert review are handled by separate teams to enforce separation of duties. How should role assignments be structured?
- Assign all staff to the Compliance Administrator role to provide equal access
- Assign policy administrators to 'Communication Compliance Admins' and reviewers to 'Communication Compliance Analysts' or 'Investigators' (Correct answer)
- Use a single custom role group with granular permissions for both teams
- Assign reviewers to the Global Administrator role for maximum access
Correct answer: Assign policy administrators to 'Communication Compliance Admins' and reviewers to 'Communication Compliance Analysts' or 'Investigators'
Using separate role groups — Admins for policy management and Analysts/Investigators for alert review — enforces separation of duties in the Communication Compliance workflow.
A compliance administrator wants to monitor third-party collaboration platforms like Zoom chat in Communication Compliance.
What is the prerequisite for ingesting this data?