SC-400 Sensitivity Labels 2 — Questions and Answers
Question 1: A company wants to apply sensitivity labels automatically to emails containing credit card numbers. Which feature should the compliance administrator configure?
- Manual labeling policy
- Auto-labeling policy with sensitive info types (Correct answer)
- Default label policy
- Recommended labeling policy
Correct answer: Auto-labeling policy with sensitive info types
Auto-labeling policies use sensitive information types or trainable classifiers to automatically apply sensitivity labels to content without user intervention.
Question 2: When configuring a sensitivity label to encrypt content, which permission level allows recipients to view but not edit or print a document?
- Co-Author
- Co-Owner
- Viewer (Correct answer)
- Reviewer
Correct answer: Viewer
The Viewer permission level in Microsoft Purview sensitivity label encryption settings allows users only to open and view content without editing, copying, or printing.
Question 3: A sensitivity label policy has a default label set to 'General'. A user applies the 'Confidential' label to a document. What happens when the user tries to downgrade to 'Public'?
- The label changes silently
- The user must provide a justification (Correct answer)
- The action is blocked entirely
- An admin alert is triggered automatically
Correct answer: The user must provide a justification
When label downgrade protection is enabled, users must provide a business justification before they can apply a lower-priority sensitivity label.
Question 4: Which sensitivity label scope must be enabled to protect content in Microsoft Teams channels and SharePoint sites?
- Files & emails
- Schematized data assets
- Groups & sites (Correct answer)
- Azure Purview assets
Correct answer: Groups & sites
The 'Groups & sites' scope must be enabled on a sensitivity label to control settings for Microsoft Teams, Microsoft 365 Groups, and SharePoint sites.
Question 5: An organization needs sensitivity labels to appear in Office for the web but not in the Office desktop apps for a specific user group. How is this achieved?
- Create separate labels for web and desktop
- Publish a label policy scoped to specific users with app-specific settings (Correct answer)
- Use endpoint DLP to block desktop app labeling
- Configure conditional access to restrict desktop apps
Correct answer: Publish a label policy scoped to specific users with app-specific settings
Label policies can be scoped to specific users or groups and configured with different settings, allowing targeted publishing of labels to particular audiences.
Question 6: A sensitivity label is configured with 'Let users assign permissions' using the Prompt users in Word, Excel, and PowerPoint option. What encryption standard is used?
- S/MIME
- Azure Rights Management Service (RMS) (Correct answer)
- TLS 1.3
- PGP encryption
Correct answer: Azure Rights Management Service (RMS)
When users assign permissions through sensitivity labels, Azure Rights Management Service (Azure RMS) applies the encryption using the permissions the user specifies.
Question 7: Which report in Microsoft Purview compliance portal shows how sensitivity labels are being applied across your organization's content over time?
- Activity explorer (Correct answer)
- Content explorer
- DLP reports
- Audit log search
Correct answer: Activity explorer
Activity explorer shows labeling activities such as label applied, label changed, and label removed events across users and content over time.
A company wants to apply sensitivity labels automatically to emails containing credit card numbers.
Which feature should the compliance administrator configure?