SC-400 Data Loss Prevention & Threat Protection 2 — Questions and Answers
Question 1: A compliance administrator needs to prevent users from sharing files containing credit card numbers via Microsoft Teams chat. Which DLP policy location should be configured?
- Exchange email
- SharePoint sites
- Teams chat and channel messages (Correct answer)
- OneDrive accounts
Correct answer: Teams chat and channel messages
Teams chat and channel messages is the correct DLP location to intercept content shared directly within Microsoft Teams conversations.
Question 2: When configuring a DLP policy, what does setting a rule action to 'Block with override' allow end users to do?
- Permanently bypass the DLP policy for all future actions
- Send the content after providing a business justification (Correct answer)
- Request admin approval before the content is sent
- Encrypt the content automatically before sending
Correct answer: Send the content after providing a business justification
Block with override allows users to proceed with the action after entering a business justification, which is logged for compliance review.
Question 3: An organization wants DLP policies to apply to endpoints (Windows 10/11 devices). What must be enabled first?
- Microsoft Defender for Cloud Apps
- Microsoft Purview Information Protection scanner
- Microsoft Purview compliance portal device onboarding (Correct answer)
- Azure Information Protection unified labeling client
Correct answer: Microsoft Purview compliance portal device onboarding
Devices must be onboarded into Microsoft Purview compliance portal before endpoint DLP policies can be applied to them.
Question 4: Which DLP condition allows a policy to detect when a document contains both a Social Security Number AND a keyword like 'confidential'?
- Simple content match
- Content contains sensitive info type with high confidence
- Content matches all conditions using AND logic (Correct answer)
- Content matches any condition using OR logic
Correct answer: Content matches all conditions using AND logic
Combining multiple conditions with AND logic requires all specified conditions to be true simultaneously for the rule to trigger.
Question 5: A DLP policy is in simulation mode. What is the primary purpose of this mode?
- To encrypt matching content without notifying users
- To test policy impact without enforcing actions or blocking users (Correct answer)
- To apply policy only to external recipients
- To generate alerts but still allow all user actions permanently
Correct answer: To test policy impact without enforcing actions or blocking users
Simulation mode (test mode) lets administrators evaluate policy matches and impact reports before enabling enforcement.
Question 6: Which Microsoft Purview feature allows you to see exactly which DLP rule matched a specific email and why it was blocked?
- Content explorer
- Activity explorer
- DLP policy reports (Correct answer)
- Alert dashboard
Correct answer: DLP policy reports
DLP policy reports provide match counts and details, while the alert dashboard and activity explorer show events; reports aggregate rule-level match data.
Question 7: An endpoint DLP policy is configured to block copying sensitive data to USB drives. A user plugs in a USB drive and tries to copy a file with credit card numbers. What happens if the device is offline?
- The policy is not enforced because the device cannot contact the cloud
- The policy is enforced because endpoint DLP policies are cached locally on the device (Correct answer)
- The file is encrypted automatically before copying
- The user receives no notification and the copy succeeds silently
Correct answer: The policy is enforced because endpoint DLP policies are cached locally on the device
Endpoint DLP policies are cached on the device and enforced locally, so they remain active even when the device is offline.
A compliance administrator needs to prevent users from sharing files containing credit card numbers via Microsoft Teams chat.
Which DLP policy location should be configured?