Microsoft Certified:Information Security Administrator Associate
Domain 3Objective 1
Implement and Manage Microsoft Purview Insider Risk Management SC-401 Practice Questions (Page 3)
Part of the Manage risks, alerts, and activities domain, which accounts for 30–35% of the SC-401 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 4–8 from this objective — we provide 52 practice questions to prepare you well beyond it. (estimate)
52questions here
11free pages
13concepts
30–35%of the exam
Questions 11–15
- 11
An insider risk alert has been escalated to a case. The investigation reveals that the user's activity was actually a result of a malware infection, not intentional data exfiltration. What should you do with the case?
Select an answer first - 12
A legal team needs to collect forensic evidence for a specific insider risk case involving a user who allegedly copied sensitive files to a USB drive. They want to capture device activity and file access logs for that user. What should the admin configure in Insider Risk Management?
Select an answer first - 13
Which risk levels can be used in Adaptive Protection?
Select an answer first - 14
Your organization has a policy to send a warning notice to users when they trigger an insider risk alert. However, you want to avoid sending notices for low-risk alerts to reduce unnecessary user anxiety. What is the best way to achieve this?
Select an answer first - 15
Your organization wants to automatically send a reminder to users when they trigger an insider risk alert, reminding them of the acceptable use policy. Which feature should you configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-401” is a trademark of its owner, used for identification only.