Microsoft Certified:Information Security Administrator Associate
Domain 3Objective 1
Implement and Manage Microsoft Purview Insider Risk Management SC-401 Practice Questions (Page 2)
Part of the Manage risks, alerts, and activities domain, which accounts for 30–35% of the SC-401 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 4–8 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
13concepts
30–35%of the exam
Questions 6–10
- 6
An insider risk case has been opened for a user who is suspected of data exfiltration. The investigation is complete and the user has been cleared. What should you do with the case?
Select an answer first - 7
You have enabled the Microsoft Defender for Endpoint integration in Insider Risk Management. Which policy indicators should you enable to detect users copying sensitive files to USB drives?
Select an answer first - 8
Your organization wants to minimize false positives in Insider Risk Management alerts. Which setting should you adjust?
Select an answer first - 9
A company is concerned about employees who repeatedly violate security policies by sharing sensitive data. They want to detect these violations and create a policy that focuses on this behavior. Which policy template should they use?
Select an answer first - 10
Which policy template is most appropriate for detecting repeated attempts to access sensitive information without authorization?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-401” is a trademark of its owner, used for identification only.