SC-400 — Frequently Asked Questions
Community-vetted answers to 60 common questions about this exam.
Questions from real practice questions
Each Q&A comes from a specific community question — follow the link for its full analysis.
What Tool Reviews DLP Policy Matches in Microsoft 365?
Content explorer shows sensitive content found by classification, not DLP rule match events. Activity explorer is the tool that records DLP policy matches across workloads.
Yes. Activity explorer includes endpoint DLP matches from Windows 10/11 and recent macOS devices, plus Exchange, SharePoint, OneDrive, Teams, and on-premises sources.
When Does Sensitivity Label Content Expiry Apply to an Already Labeled Document?
No. Expiry is embedded when the label is applied, so Doc1 keeps its original 21-day period and access ends January 24.
Editing or saving labeled content does not re-stamp the label's expiration metadata; only re-applying the label would recalculate it.
Retraining Trainable Classifiers in Microsoft Purview
Classifier2 is published. Microsoft Purview does not support retraining published custom classifiers to maintain policy stability.
You must remove the existing classifier and create a new one with additional training samples to improve accuracy.
Manage Microsoft 365 Alert Status
Yes. If an alert has been marked as Resolved, an administrator can change its status back to Active or Investigating to continue the review process.
The four valid statuses are Active (default), Investigating, Resolved, and Dismissed.
Enforcing Sensitivity Labels for Microsoft 365 Groups
Sensitivity label policies do not support dynamic groups as a target scope. You must use auto-labeling policies to target users in dynamic groups.
No, the legacy AIP unified labeling client is deprecated. Modern solutions use built-in Office apps and auto-labeling agents.
Does Set-Mailbox AuditEnabled Meet Delegate Sign-In Audit Goal?
Mailbox auditing is on by default, but the MailboxLogin action for delegates must be explicitly added with Set-Mailbox -AuditDelegate @{Add='MailboxLogin'} to record their sign-ins.
Run Set-Mailbox -Identity User1 -AuditDelegate @{Add='MailboxLogin'} to add MailboxLogin to the delegate audit set.
How Many Alerts for SharePoint File Uploads in Purview?
The alert policy condition filters on .docx file names, so an .xlsx upload does not match the policy and is not counted as an alert.
Microsoft Purview alert aggregation adds matching events that occur within one minute to an existing alert instead of creating a separate alert for each upload.
Activate ISO/IEC 27001:2013 Template in Compliance Manager
It is inactive because the specific assessments have not been added to your workspace yet. You must click 'Add recommended assessments' to enable it.
No. The ISO/IEC 27001:2013 template is included in E3. Only specific premium templates like HIPAA require E5 licensing.
How Do You Define an Information Barrier Segment in Microsoft Purview?
Segments in the Purview compliance portal are defined by attribute-based user group filters. A Microsoft 365 group or distribution list can only be one of the filter criteria, not the segment definition itself.
In the Microsoft Purview compliance portal under Information barriers > Segments: name the segment first, then the next screen prompts you to add a User Group Filter such as Department eq 'Marketing'.
Which Locations Can Be Configured for a Subject Rights Request?
Teams chats are searched through Exchange Online, and Teams files are searched through SharePoint Online, so the Priva wizard only exposes Exchange and SharePoint as location toggles.
Yes. Exchange Online covers Exchange mailboxes and individual or group Teams chats, which is why Teams does not appear as its own configurable search location.
What to Create First for Insider Risk Management Project Policy?
Priority user groups are native to Insider Risk Management and can be selected directly in policy scoping, whereas Entra security groups would add administrative steps and may not support the same risk indicators.
Yes, but selecting users manually in each policy increases admin effort and risk of over-scoping. A priority user group centralizes the project team for reuse and minimizes impact.
How to Add an Information Barrier Segment to SharePoint Site1
Set-SPOSite performs the association, but Microsoft requires an information barrier policy to link the segment to the site first.
It is a tenant-level prerequisite, but the immediate step after creating a segment is to create an information barrier policy that includes it.
Viewing Regex in Built-in Sensitive Info Types
Built-in types are predefined by Microsoft to ensure stability. The regex is hidden to prevent accidental changes that could break detection accuracy.
No. This role allows managing policies but cannot modify the core definition of Microsoft's pre-built sensitive info types directly.
How to auto-delete credit card content after 12 months in Microsoft 365?
Sensitivity labels classify, encrypt, and mark content but do not set a retention or deletion period; only retention labels can automatically delete items 12 months after creation.
No. Microsoft 365 includes a built-in credit card SIT, and using it minimizes administrative effort; you only need a retention label and an auto-labeling policy for it.
How to make Sublabel1 the default sensitivity label for Group1?
Label order controls priority or display, not the default label applied by a scoped policy. The policy must explicitly select Sublabel1 as the default for Group1.
No. Deleting the existing policy would unpublish Label1 from Group1 and disrupt other settings; modify the current policy instead.
Modifying a Preservation-Locked Retention Policy RP1
The lock prevents removing locations to protect the retention scope; you can only add new locations. This is why option E as 'remove locations' is a trap.
Yes, extending the retention period is explicitly allowed. The lock only blocks shortening, not lengthening.
Which Components Require Approval for Emails with Two Customer Identifiers?
A mail flow rule can inspect sensitive information types, but unified DLP policy natively supports instance-count conditions and approval routing without a separate transport rule.
The DLP rule uses the sensitive information type with a minimum instance count of 2, so a single 13-digit identifier does not trigger the approval action.
Which two components meet SharePoint Project1 retention requirements?
Adaptive scopes help target retention policies to sites, but they do not provide event-based retention triggers; the Project1 milestone requires an event type in a file plan.
No. Sensitivity labels classify and protect content but cannot enforce a 10-year retention period followed by event-driven deletion; that requires retention labels from a file plan.
Obtaining Export Key for Microsoft Purview Content Search Download
The export key provides an additional layer of encryption for the downloaded data package, ensuring that even if the download link is intercepted, the data remains unreadable without the key.
The export key is displayed when you complete the export job configuration. You should save it securely as it is needed to decrypt the final .zip file containing the search results.
What to Create First to Review GDPR Compliance in Compliance Manager?
Templates are the prebuilt regulatory frameworks Microsoft provides, including GDPR. An assessment is what binds that GDPR template to your Microsoft 365 E5 tenant and produces the compliance score and improvement actions.
No. An alert policy only notifies you after a score changes; it performs no evaluation. It also depends on an assessment already existing, so it cannot be the first thing you create.
Retain Audit Logs for 10 Years in Microsoft 365 E5
No. The admin needs appropriate permissions (like Compliance Administrator), but the 10-year license is only required on the user accounts whose logs are being retained.
It provides advanced search capabilities and extends retention up to 1 year, but it does not support the 10-year retention period which requires the separate add-on license.
Assign eDiscovery Permissions in Purview
eDiscovery roles are managed as role groups specifically within the Purview compliance portal to ensure proper segregation of compliance duties.
You should assign the 'eDiscovery Manager' role group, which grants permissions to create and manage eDiscovery cases and view results.
Granting Least Privilege Audit Log Search Access
No, the Security Reader role allows viewing security alerts and reports but does not provide permissions to search the audit log.
Historically, audit logging was managed through Exchange Online. While Purview is now the central hub, the Exchange-based roles remain valid for granting these specific permissions.
KQL Query for Content Search Recipients
In KQL for Purview, listing values in parentheses (A B) implicitly means A OR B. Repeating the field with OR is less efficient and can sometimes cause syntax issues.
Yes, but you must use standard wildcard syntax like *. The options provided with #1-2 are invalid KQL syntax.
Microsoft Purview Activity Explorer for DLP and Label Reports
No, Content Search finds specific items based on criteria. It does not provide an activity log or trend report of label changes across the tenant.
Activity Explorer is available in Microsoft 365 E5 and G5 tenants, as well as standalone Purview plans, providing comprehensive audit and activity insights.
eDiscovery Case Mailbox Search Permissions
No. eDiscovery uses dedicated roles (eDiscovery Manager/Administrator) that grant search access independently of mailbox permissions like Full Access.
Yes. eDiscovery provides search-only access. It does not grant the ability to send messages or modify items unless specifically configured in Premium features.
First Step for Insider Risk Management Policy in Microsoft Purview
Office indicators define what sensitive data to look for, but they do not identify which users are at risk. You need HR data to filter policies by employment status.
Yes, the HR data connector provides a unified view of employee status across Microsoft 365 workloads, allowing insider risk policies to apply to SharePoint, Exchange, and Teams.
Microsoft Purview Insider Risk Management Device Onboarding
The HR connector provides employee context (like termination date) but does not provide the technical telemetry of file actions needed to detect the suspicious behavior.
No, Communication Compliance monitors messages (email, chat). It cannot detect local file operations like copying to a USB drive or printing from a workstation.
Sensitivity Label File Support in Microsoft Purview
Standard text files lack the container structure required to embed sensitivity metadata tags in most Office clients. Policies may apply to them via other means, but not standard labeling.
Yes, the legacy binary .doc format is not supported for client-side labeling. You must convert files to .docx to apply labels in modern Office applications.
Minimize Effort for Former Employee Data Deletion
eDiscovery requires manual case setup and content search, increasing administrative effort. Priva SRR automates data discovery and response.
Base Priva features may be included, but Subject Rights Requests is often a premium add-on or separate entitlement requiring explicit assignment/purchase.
← Back to Microsoft SC-400 information protection study guide