Microsoft SC-401 Information Security Administrator 1-10

表示モード
画像位置
文字位置
理解度の自動記録
STATUS FILTER

Choose confidence levels to display

Loading...
Q1SC-401
Show answer
Correct answer: D. Sensitivity labels

Microsoft 365 Copilot generates answers based on the Microsoft 365 data that each user has permission to access.
Therefore, to keep the R&D documents in Channel1 out of the answers shown to unauthorized users, a sensitivity label that can apply protection to the files themselves is effective.
Sensitivity labels let you configure content classification, encryption, and access control so that only authorized users can open and use a file.
Copilot recognizes sensitivity labels and preserves the protection of labeled data.
DLP controls sharing and transmission, Insider Risk Management detects internal risk, and Information Barriers separate users from one another, so sensitivity labels are the best fit for this requirement.
Learn about sensitivity labels
Restrict access to content by using sensitivity labels to apply encryption

Q2SC-401
Show answer
Correct answer: B. Copy and extract content (EXTRACT)

For Copilot to summarize a file encrypted with a sensitivity label, it is not enough for the user simply to have access to the target file.
When encryption is applied, the user needs the EXTRACT (copy and extract content) usage right in order for Copilot to return the data.
With only the VIEW permission, the user can open and read the file outside of Copilot, but Copilot cannot summarize it.
EXPORT is for saving in another format, DOCEDIT is for editing, and VIEW is for viewing, so none of these are the central permission that meets the summarization requirement.
Therefore, assign Copy and extract content (EXTRACT) to Label1.
Learn about sensitivity labels
Security and compliance considerations for Microsoft 365 Copilot

Q3SC-401
Show answer
Correct answer: C. SharePoint admin center

To use sensitivity labels on Office files stored in SharePoint Online and OneDrive, you must enable the information protection setting on the SharePoint side.
This setting is configured not in the Microsoft Purview portal but as the option to enable sensitivity labels for Office files under Settings in the SharePoint admin center.
Once enabled, recognizing and applying labels and processing encrypted files is supported for files across both services.
The Microsoft Entra admin center focuses on identity and access management, and the Microsoft 365 admin center on tenant-wide administration, so neither is where this requirement is configured.
Therefore, the tool you should use is the SharePoint admin center.
Enable sensitivity labels for files in SharePoint and OneDrive

Q4SC-401
Show answer
Correct answer: B. Set-OMEConfiguration

To add branding elements such as a company logo to encrypted email, you modify the branding settings of Microsoft Purview Message Encryption.
To update an existing encrypted-message configuration, you can use Set-OMEConfiguration to set the logo, disclaimer text, body text, background color, and so on.
New-OMEConfiguration is used to create a new template, but that adds more effort than modifying an existing configuration and works against minimizing administrative work.
Set-IRMConfiguration configures Information Rights Management, and Set-RMSTemplate relates to RMS templates, so neither is suited to adding a logo.
Therefore, Set-OMEConfiguration is best for customizing encrypted email that includes a company logo.
Add your organization’s brand to encrypted messages
Set-OMEConfiguration

Q5SC-401
Show answer
Correct answer: C. A sensitivity label

To control revocation and expiration of encrypted email sent to external recipients, you configure the encryption settings in a Microsoft Purview sensitivity label.
Sensitivity labels can apply encryption to email and files and let you set access permissions, offline access expiration, and usage rights per user or group.
Revocation and expiration management of encrypted email is a content protection setting rather than a branding or delivery control.
A custom branding template changes what is displayed, a mail flow rule performs condition-based processing, and a Conditional Access policy controls sign-in and app usage.
Therefore, what you should configure first is a sensitivity label that includes encryption settings.
Restrict access to content by using sensitivity labels to apply encryption
Learn about sensitivity labels

Q6SC-401
Show answer
Correct answer: A. A trainable classifier

A resume is unstructured data that contains elements such as a name, work experience, education, and accomplishments, yet varies in wording and format from document to document.
To identify such documents, a trainable classifier that learns content and structure to classify is better suited than a keyword dictionary or a function.
In Microsoft Purview, you can use a trainable classifier as the condition for automatically applying a sensitivity label.
The pre-trained classifiers include one that identifies resumes, and it can be used with English-language documents.
An EDM classifier is intended for matching known, exact data, so it is not suited to classifying documents like resumes.
Therefore, to minimize administrative work, use a trainable classifier.
Learn about trainable classifiers
Automatically apply a sensitivity label to Microsoft 365 data

Q7SC-401
Show answer
Correct answer: B. One DLP policy that contains two DLP rules

With Microsoft Purview endpoint DLP, you can detect operations in which a file containing sensitive information is copied to a USB removable device on a Windows device and apply controls such as audit, warn, and block.
Here, for the same target data and the same device operation, you need to allow the copy with auditing for Group1 and block it for all other users.
Therefore, within a single DLP policy, you configure a separate audit rule for Group1 and a block rule for the other users.
A single rule cannot appropriately branch between auditing and blocking per user under the same conditions.
Therefore, what you should create is one DLP policy that contains two DLP rules.
Learn about endpoint data loss prevention
Create and deploy a data loss prevention policy

Q8SC-401
Show answer
Correct answer: D. Publish the label in the Microsoft Purview portal, E. Create the label in the Microsoft Purview portal

To enable users to apply retention labels to individual documents in a SharePoint library, you must first create the retention label in the Microsoft Purview portal and then publish it to the target users or SharePoint sites.
A retention label defines things such as how long content is retained, deletion after retention, and declaring content as a record.
A label is not shown to users just by being created; it becomes available in SharePoint only after it is published as a label policy.
A file policy in Microsoft Defender for Cloud Apps or site settings in the SharePoint admin center are not the primary steps for making retention labels available to users.
Therefore, you need to create and publish the retention label in the Microsoft Purview portal.
Publish retention labels and apply them in apps
Learn about retention policies and retention labels

Q9SC-401
Show answer
Correct answer: D. A retention label

Microsoft Purview Data Lifecycle Management controls how long content such as SharePoint Online content is retained and when it is deleted after the retention period.
The foundation of this control is the retention label.
A retention label lets you define behaviors such as the retention period, the basis for when retention starts, and deletion or review after retention.
After creating a retention label, you publish it so users can apply it manually, or you apply it to content that matches conditions with an auto-apply policy.
A sensitivity label policy is for information protection, a DLP policy is for preventing information leakage, and an auto-labeling policy is for automatically applying existing labels.
Therefore, what you should create first is a retention label.
Publish retention labels and apply them in apps
Learn about retention policies and retention labels

Q10SC-401
Show answer
Correct answer: B. 2

In a Microsoft Purview retention policy, you can specify locations such as Exchange email, SharePoint sites, and Microsoft 365 Groups together in a single retention policy.
On the other hand, when you select Teams-related retention locations such as Teams chats or Teams channel messages, there is a constraint that other locations cannot be selected in the same retention policy.
Therefore, you need one retention policy for Exchange email, SharePoint sites, and Microsoft 365 Groups, and another for Teams chats and Teams channel messages.
Because Teams message retention is treated as a Teams-only location, you cannot combine everything into a single static retention policy.
Therefore, the minimum number of retention policies required is 2.
Create and configure retention policies
Learn about retention for Microsoft Teams