Quickly grab our SC-401 product now and kickstart your exam preparation today!
| Name: | Administering Information Security in Microsoft 365 |
| Exam Code: | SC-401 |
| Certification: | Microsoft 365 Certified |
| Vendor: | Microsoft |
| Total Questions: | 225 |
| Last Updated: | Aug 13, 2026 |
You need to meet the retention requirement for the users' Microsoft 365 data. What is the minimum number of retention policies required to achieve the goal?
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named
Site1.
You need to deploy a Microsoft Purview insider risk management solution that will generate an alert
when users share sensitive information on Site1 with external recipients.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct answer is worth one point.
You have a Microsoft 365 subscription. You have a user named User1 Several users have full access to the mailbox of User1. Some email messages sent to User 1 appeal to have been read and deleted before the user viewed them When you search the audit log in the Microsoft Purview portal to identify who signed in to the mailbox of User l. the results are blank. You need to ensure that you can view future sign-ins to the mailbox of User1. Solution: You run the Set-AuditConfig -Workload Exchange command. Does that meet the goal?
Note: This question is part of a series of questions that present the same scenario. Each question in
the series contains a unique solution that might meet the stated goals. Some question sets might
have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these
questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1.
Some email messages sent to User1 appear to have been read and deleted before the user viewed
them.
When you search the audit log in the Microsoft Purview portal to identify who signed in to the
mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1.
Solution: You run the Set-AdminAuditLogConfig -AdminAuditLogEnabled $true -
AdminAuditLogCmdlets *Mailbox* command.
Does that meet the goal?
You have a Microsoft 365 E5 tenant that contains a user named User1. User1 is assigned the Compliance Administrator role. User1 cannot view the regular expression in the IP Address sensitive info type. You need to ensure that User! can view the regular expression. What should you do?