Microsoft Certified:Information Security Administrator Associate
Domain 3Objective 2
Manage Information Security Alerts and Activities SC-401 Practice Questions (Page 5)
Part of the Manage risks, alerts, and activities domain, which accounts for 30–35% of the SC-401 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 4–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)
38questions here
8free pages
9concepts
30–35%of the exam
Questions 21–25
- 21
Where in the Microsoft Purview portal would you go to view and respond to data loss prevention (DLP) alerts?
Select an answer first - 22
A security administrator is investigating a potential insider risk case where an employee is suspected of downloading a large number of files from a shared drive and sending them to a personal email account. The administrator needs to gather evidence of the user's activities, including the file names and the exact times of the actions. What is the most effective way to investigate this case?
Select an answer first - 23
When responding to a file policy alert in Defender for Cloud Apps, which of the following is a possible action?
Select an answer first - 24
Where can Microsoft Purview alerts be managed alongside other security alerts in the Microsoft Defender portal?
Select an answer first - 25
Which Microsoft Purview tool is used to search and view audit logs for user and system activities?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-401” is a trademark of its owner, used for identification only.