SC-400 Information Protection & Governance 5 — Questions and Answers
Question 1: Which Microsoft Purview capability allows an organization to apply sensitivity labels to on-premises files in Windows Server file shares?
- Microsoft Purview Information Protection scanner (Correct answer)
- Microsoft Defender for Identity
- Azure File Sync with labeling
- On-premises DLP connector
Correct answer: Microsoft Purview Information Protection scanner
The Microsoft Purview Information Protection scanner (formerly AIP scanner) can discover, classify, and label files in on-premises repositories.
Question 2: A DLP policy is set to 'Audit only' mode. What is the impact on users and data?
- Users are blocked from sharing sensitive content but not notified
- No restrictions are applied, but matching events are logged for review (Correct answer)
- Policy tips are shown to users but sharing is still blocked
- Sensitive content is quarantined for admin review
Correct answer: No restrictions are applied, but matching events are logged for review
Audit-only mode logs policy matches without restricting user actions, allowing admins to assess impact before enforcing restrictions.
Question 3: An admin wants to prevent sensitivity labels from being removed by users once applied. Which label setting supports this?
- Mandatory labeling with justification required for downgrade (Correct answer)
- Encryption with 'Do Not Forward' restriction
- Content marking with dynamic watermarks
- Auto-labeling with highest confidence threshold
Correct answer: Mandatory labeling with justification required for downgrade
Requiring justification for label downgrade or removal forces users to explain why they are reducing protection, creating an audit trail and deterrent.
Question 4: Which sensitive information type would best detect European Union passport numbers across multiple EU member states?
- A single custom regex for all EU passports
- EU Passport Number built-in sensitive information type (Correct answer)
- Keyword dictionary containing 'passport'
- Trainable classifier for travel documents
Correct answer: EU Passport Number built-in sensitive information type
Microsoft Purview includes built-in sensitive information types for EU Passport Numbers that handle the varying formats across member states.
Question 5: A sensitivity label policy must apply different default labels for users in the Finance department versus general employees. How should this be configured?
- Create two separate label policies scoped to different groups (Correct answer)
- Use a single policy with conditional access rules
- Configure group-based encryption in Azure RMS
- Apply department-specific retention policies instead
Correct answer: Create two separate label policies scoped to different groups
Creating separate label policies for different user groups allows distinct default labels, mandatory settings, and published label sets per group.
Question 6: An organization needs to ensure that emails classified as 'Confidential' cannot be forwarded by recipients. Which sensitivity label encryption option achieves this?
- Apply watermark to email body
- Assign 'Do Not Forward' permission in the encryption settings (Correct answer)
- Block all external recipients with DLP policy
- Enable S/MIME signing for the label
Correct answer: Assign 'Do Not Forward' permission in the encryption settings
The 'Do Not Forward' permission in Azure RMS encryption prevents recipients from forwarding, printing, or copying the email content.
Question 7: Which Microsoft Purview feature allows organizations to discover and classify sensitive data stored in multi-cloud environments such as AWS S3 and Azure Blob Storage?
- Microsoft Purview Data Map (Correct answer)
- Microsoft Defender for Cloud
- Microsoft Purview Compliance Manager
- Azure Policy with sensitivity tags
Correct answer: Microsoft Purview Data Map
Microsoft Purview Data Map scans and classifies data assets across hybrid and multi-cloud environments including AWS S3 and Azure storage.
Which Microsoft Purview capability allows an organization to apply sensitivity labels to on-premises files in Windows Server file shares?