Administering Information Security in Microsoft 365
Last Update Mar 20, 2026
Total Questions : 203
To help you prepare for the SC-401 Microsoft exam, we are offering free SC-401 Microsoft exam questions. All you need to do is sign up, provide your details, and prepare with the free SC-401 practice questions. Once you have done that, you will have access to the entire pool of Administering Information Security in Microsoft 365 SC-401 test questions which will help you better prepare for the exam. Additionally, you can also find a range of Administering Information Security in Microsoft 365 resources online to help you better understand the topics covered on the exam, such as Administering Information Security in Microsoft 365 SC-401 video tutorials, blogs, study guides, and more. Additionally, you can also practice with realistic Microsoft SC-401 exam simulations and get feedback on your progress. Finally, you can also share your progress with friends and family and get encouragement and support from them.
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription.
You have a user named User1. Several users have full access to the mailbox of User1.
Some email messages sent to User1 appear to have been read and deleted before the user viewed them.
When you search the audit log in the Microsoft Purview portal to identify who signed in to the mailbox of User1, the results are blank.
You need to ensure that you can view future sign-ins to the mailbox of User1.
Solution: You run the Set-Mailbox -Identity " User1 " -AuditEnabled $true command.
Does that meet the goal?
You have a Microsoft 365 £5 subscription.
You are implementing insider risk management.
You need to create an insider risk management notice template and format the message body of the notice template.
How should you configure the template? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.

You have a Microsoft 365 E5 subscription that contains the adaptive scopes shown in the following table.

You create the retention policies shown in the following table.

Which retention policies support a preservation lock?
You need to provide a user with the ability to view data loss prevention (DIP) alerts in the Microsoft Purview portal. The solution must use the principle of least privilege.
Which role should you assign to the user?