SC-400 Information Protection & Governance 3 — Questions and Answers
Question 1: A DLP policy is configured with a 'Block with override' action. What does this mean for end users?
- Users cannot override the block under any circumstances
- Users can bypass the block by providing a business justification (Correct answer)
- The policy only audits and does not block
- Admins are notified but users see no restriction
Correct answer: Users can bypass the block by providing a business justification
Block with override allows users to justify and bypass the DLP restriction while creating an audit trail of the override.
Question 2: Which Microsoft Purview feature allows an organization to classify data in SharePoint Online, OneDrive, and Exchange using trainable classifiers?
- Sensitive information types
- Trainable classifiers in content explorer (Correct answer)
- Keyword queries in eDiscovery
- Azure Cognitive Services
Correct answer: Trainable classifiers in content explorer
Trainable classifiers use machine learning to identify content categories and can be applied via auto-labeling and DLP policies.
Question 3: An admin notices that a sensitivity label policy is not applying default labels to new documents created in Teams. What is the most likely cause?
- Teams does not support sensitivity labels
- The label policy was not published to the user or group (Correct answer)
- Default labels require AIP client installation
- Sensitivity labels only apply to email, not Teams
Correct answer: The label policy was not published to the user or group
Label policies must be published to specific users or groups; if the Teams user is not in scope, no default label will be applied.
Question 4: What is a 'sublabel' in Microsoft Purview sensitivity labeling?
- A label that applies only to sublevel SharePoint sites
- A child label nested under a parent label for more granular classification (Correct answer)
- A label applied automatically by machine learning
- A label visible only to compliance administrators
Correct answer: A child label nested under a parent label for more granular classification
Sublabels are nested under parent labels, allowing organizations to create hierarchical classification schemes (e.g., Confidential > Finance).
Question 5: An organization uses Microsoft Purview to protect sensitive PDFs shared externally. Which feature ensures that recipients outside the tenant can open protected PDFs without an Azure AD account?
- Guest access in SharePoint
- One-time passcode (OTP) via Azure RMS (Correct answer)
- B2B collaboration with Entra ID
- Public link sharing in OneDrive
Correct answer: One-time passcode (OTP) via Azure RMS
Azure RMS supports one-time passcode authentication, allowing external recipients without Azure AD accounts to access protected documents.
Question 6: A DLP policy needs to detect U.S. Social Security Numbers only when they appear with corroborating keywords like 'SSN' or 'Social Security'. What feature supports this requirement?
- Exact Data Match (EDM)
- Keyword dictionaries
- Sensitive information types with supporting elements (Correct answer)
- Trainable classifiers
Correct answer: Sensitive information types with supporting elements
Sensitive information types can include primary patterns plus supporting elements (keywords, confidence levels) to improve detection accuracy.
Question 7: Which Microsoft Purview tool provides a visual map showing where sensitive data resides across Microsoft 365 workloads?
- Compliance Manager
- Content Explorer (Correct answer)
- Activity Explorer
- Audit log search
Correct answer: Content Explorer
Content Explorer displays a breakdown of items containing sensitive information types or labels across Exchange, SharePoint, and OneDrive.
A DLP policy is configured with a 'Block with override' action.
What does this mean for end users?