SC-400 Data Classification 3 — Questions and Answers
Question 1: An administrator is reviewing Content Explorer in Microsoft Purview. What specific permission is required to view the actual content of items (not just metadata) in Content Explorer?
- Content Explorer List Viewer
- Content Explorer Content Viewer (Correct answer)
- Compliance Administrator
- Information Protection Admin
Correct answer: Content Explorer Content Viewer
The Content Explorer Content Viewer role allows users to view the actual content of sampled items, while List Viewer only shows metadata and item counts.
Question 2: A trainable classifier has been created and is in 'Need test items' status. What is the next required step?
- Publish the classifier to production
- Provide test content for the classifier to evaluate (Correct answer)
- Configure auto-labeling policies
- Upload a keyword dictionary
Correct answer: Provide test content for the classifier to evaluate
After initial training, the classifier requires test content items to evaluate its accuracy before it can be published for use.
Question 3: Which data classification feature in Microsoft Purview allows administrators to see an overview of how many items contain sensitive information across all Microsoft 365 locations?
- Activity Explorer
- Content Explorer (Correct answer)
- Data map
- Compliance Manager
Correct answer: Content Explorer
Content Explorer provides a visual summary of items containing sensitive information types or sensitivity labels across SharePoint, OneDrive, and Exchange.
Question 4: When creating an EDM sensitive information type, what format must the sensitive data table be uploaded in?
- JSON
- XML
- CSV or TSV (Correct answer)
- Excel XLSX
Correct answer: CSV or TSV
EDM data must be uploaded as a CSV or TSV (tab-separated values) file containing the sensitive data to be matched exactly.
Question 5: A sensitivity label has been configured with auto-labeling for emails. A user sends an email containing a credit card number. What happens if the label policy has 'enforce' mode enabled?
- The user is prompted to manually apply a label
- The label is automatically applied without user notification (Correct answer)
- The email is blocked until the user applies a label
- The email is quarantined for admin review
Correct answer: The label is automatically applied without user notification
In enforce mode, auto-labeling policies automatically apply the configured sensitivity label to matching content without requiring user action.
Question 6: Which Activity Explorer event type indicates that a sensitivity label was changed from a higher classification to a lower one?
- Label applied
- Label downgraded (Correct answer)
- Label removed
- Label changed
Correct answer: Label downgraded
Activity Explorer logs 'Label downgraded' events when a sensitivity label is changed to one with lower classification, which may require justification.
Question 7: An organization has 50 sensitivity labels. They want to limit which labels appear for users in specific departments. What should the administrator configure?
- Sensitivity label scopes
- Label priority ordering
- Label publishing policies scoped to specific users or groups (Correct answer)
- Label conditions
Correct answer: Label publishing policies scoped to specific users or groups
Label publishing policies allow administrators to publish specific sensitivity labels only to selected users or groups, limiting label visibility by department.
An administrator is reviewing Content Explorer in Microsoft Purview.
What specific permission is required to view the actual content of items (not just metadata) in Content Explorer?