SC-400 Data Loss Prevention & Threat Protection 5 — Questions and Answers
Question 1: Microsoft Purview Insider Risk Management uses which type of signals to detect potential data theft by a departing employee?
- Only email content scanned by DLP policies
- Behavioral signals such as file downloads, USB transfers, and HR departure indicators (Correct answer)
- Only signals from Microsoft Defender for Endpoint
- Manual reports submitted by managers through the compliance portal
Correct answer: Behavioral signals such as file downloads, USB transfers, and HR departure indicators
Insider Risk Management correlates behavioral signals (file activity, HR data, network events) to identify risky patterns like data exfiltration by departing employees.
Question 2: What role is required to create and manage Insider Risk Management policies in Microsoft Purview?
- Global Administrator only
- Insider Risk Management or Insider Risk Management Admin role (Correct answer)
- Security Administrator with DLP permissions
- Compliance Administrator with eDiscovery access
Correct answer: Insider Risk Management or Insider Risk Management Admin role
The Insider Risk Management and Insider Risk Management Admin roles are specifically scoped for creating and managing insider risk policies.
Question 3: An organization wants to apply DLP policies to Power BI reports shared within the organization. Which license is required?
- Microsoft 365 E3
- Microsoft 365 E5 Compliance or standalone Microsoft Purview DLP add-on (Correct answer)
- Power BI Premium only
- Microsoft Defender for Cloud Apps Plan 1
Correct answer: Microsoft 365 E5 Compliance or standalone Microsoft Purview DLP add-on
DLP for Power BI requires Microsoft 365 E5 Compliance or an equivalent standalone add-on license, as it extends beyond the standard E3 DLP coverage.
Question 4: A compliance team needs to investigate whether any sensitive files were uploaded to personal cloud storage (e.g., personal Dropbox) from corporate devices. Which Microsoft solution provides this visibility?
- Microsoft Defender for Office 365 Threat Explorer
- Microsoft Defender for Cloud Apps with conditional access app control
- Microsoft Purview Activity Explorer filtered by endpoint DLP (Correct answer)
- Microsoft Entra ID Sign-in logs
Correct answer: Microsoft Purview Activity Explorer filtered by endpoint DLP
Endpoint DLP logs file activity including uploads to cloud services, and Activity Explorer lets compliance teams filter and review these events.
Question 5: What is the function of 'Adaptive Protection' in Microsoft Purview?
- It automatically generates new sensitive information types based on detected data patterns
- It dynamically adjusts DLP policy strictness based on a user's insider risk level (Correct answer)
- It applies sensitivity labels to content automatically based on ML classifiers
- It blocks all external sharing for users flagged as high risk by Entra ID Protection
Correct answer: It dynamically adjusts DLP policy strictness based on a user's insider risk level
Adaptive Protection integrates Insider Risk Management risk levels with DLP policies, applying stricter controls to users classified as elevated risk.
Question 6: A DLP alert is triggered but the compliance admin needs more context about what the user was doing before and after the incident. Which tool provides a timeline of user activity?
- Content Explorer
- Activity Explorer (Correct answer)
- Microsoft Secure Score dashboard
- Microsoft Defender Incidents queue
Correct answer: Activity Explorer
Activity Explorer provides a chronological timeline of DLP-matched events and user file activities, giving context around an incident.
Question 7: Which Microsoft Purview Communication Compliance policy template is best suited to detect potential regulatory violations in broker communications under FINRA Rule 3110?
- Offensive language template
- Regulatory compliance template (Correct answer)
- Conflict of interest template
- Data exfiltration template
Correct answer: Regulatory compliance template
The regulatory compliance template in Communication Compliance is designed to detect language patterns that may violate financial regulatory requirements like FINRA.
Microsoft Purview Insider Risk Management uses which type of signals to detect potential data theft by a departing employee?