Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Microsoft logo

Microsoft Certified:Information Security Administrator Associate

Domain 3Objective 2

Manage Information Security Alerts and Activities SC-401 Practice Questions (Page 7)

Part of the Manage risks, alerts, and activities domain, which accounts for 30–35% of the SC-401 exam. Microsoft does not publish an official question count, but from its 100-minute exam (~40–65 total, ~12–23 in this domain), expect 4–8 from this objective — we provide 38 practice questions to prepare you well beyond it. (estimate)

38questions here
8free pages
9concepts
30–35%of the exam

Questions 31–35

  1. 31expert · hard

    An organization is required to retain audit logs for all user activities in Exchange Online and SharePoint Online for 5 years to meet regulatory requirements. The organization currently has Microsoft Purview Audit (Standard) enabled for all users. The security administrator needs to configure the audit log retention to meet this requirement. What is the most appropriate action?

    Select an answer first
  2. 32application · medium

    A user at Contoso is suspected of copying sensitive customer data to a personal OneDrive account. You need to determine whether the user accessed the sensitive files and then uploaded them to OneDrive. Which tool should you use to analyze the sequence of activities?

    Select an answer first
  3. 33application · medium

    During an investigation of a potential data breach, the legal team requests a copy of all emails and documents related to a specific project that may have been accessed by an unauthorized user. The security administrator needs to locate and preserve this information for the investigation. What is the most appropriate tool to use?

    Select an answer first
  4. 34application · medium

    The security team at Contoso receives a DLP alert in the Purview portal about a user sending sensitive data via email. The team wants to investigate the alert and also see related alerts from Defender for Cloud Apps in the same place. What should they do?

    Select an answer first
  5. 35application · medium

    A security operations center (SOC) analyst receives an alert in Microsoft Defender XDR that was generated by a Microsoft Purview DLP policy. The alert indicates that a user attempted to share a sensitive document externally. The analyst needs to investigate and respond to the alert within the Defender XDR console. What is the most appropriate action?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Microsoft. “SC-401” is a trademark of its owner, used for identification only.