SC-400 Data Classification 5 — Questions and Answers
Question 1: An administrator notices that a sensitivity label applied via auto-labeling is being overridden by users with a lower-priority label. What setting prevents users from manually lowering the label applied by an auto-labeling policy?
- Set the label as mandatory
- Configure the policy to prevent label downgrade without justification (Correct answer)
- Enable 'Lock label applied by policy'
- Set the auto-label as the default label
Correct answer: Configure the policy to prevent label downgrade without justification
Configuring the label publishing policy to require justification for label downgrading helps prevent unauthorized reduction of sensitivity classification.
Question 2: Which Microsoft Purview feature enables administrators to understand what types of sensitive data exist in their environment before configuring policies?
- DLP policy simulation
- Data classification dashboard in Content Explorer (Correct answer)
- Compliance score in Compliance Manager
- Secure Score
Correct answer: Data classification dashboard in Content Explorer
The data classification dashboard and Content Explorer provide visibility into the volume and types of sensitive information across Microsoft 365 before policies are enforced.
Question 3: A sensitivity label is scoped to 'Files & emails' and 'Groups & sites.' What additional configuration is needed for the label to apply protection to SharePoint sites?
- Enable co-authoring for encrypted files
- Configure group and site settings within the label (Correct answer)
- Create a separate retention label
- Enable SharePoint integration in the admin center
Correct answer: Configure group and site settings within the label
When a sensitivity label is scoped to Groups & sites, you must configure the specific site and group settings (privacy, external sharing, etc.) within the label definition.
Question 4: When testing a custom sensitive information type using the 'Test' function in Microsoft Purview, what is the minimum recommended sample size for reliable results?
- 5 positive and 5 negative examples
- 20 positive and 20 negative examples
- 10 positive and 10 negative examples (Correct answer)
- 50 positive and 50 negative examples
Correct answer: 10 positive and 10 negative examples
Microsoft recommends at least 10 positive (true positive) and 10 negative (true negative) samples when testing a custom sensitive information type to validate accuracy.
Question 5: An organization wants to classify email attachments containing financial data in Exchange Online using auto-labeling. Which condition type should be configured in the auto-labeling policy?
- Label conditions based on content type
- Sensitive information types detected in attachment content (Correct answer)
- Sender domain rules
- Message classification headers
Correct answer: Sensitive information types detected in attachment content
Auto-labeling policies for Exchange can be configured to detect sensitive information types within email body and attachment content to trigger label application.
Question 6: What is the maximum number of custom sensitive information types that can be created per Microsoft 365 tenant?
- 100
- 500 (Correct answer)
- 50
- 1000
Correct answer: 500
Each Microsoft 365 tenant can have up to 500 custom sensitive information types in addition to the built-in types provided by Microsoft.
Question 7: A compliance team wants to identify which users are most frequently applying or changing sensitivity labels on documents. Which tool provides this user-level activity data?
- Content Explorer filtered by user
- Activity Explorer filtered by user (Correct answer)
- Microsoft Defender for Cloud Apps activity log
- Azure AD sign-in logs
Correct answer: Activity Explorer filtered by user
Activity Explorer can be filtered by user to show all label-related activities performed by specific individuals, including label applied, changed, and removed events.
An administrator notices that a sensitivity label applied via auto-labeling is being overridden by users with a lower-priority label.
What setting prevents users from manually lowering the label applied by an auto-labeling policy?