SC-401 · Question #1
Case Study 1 - Contoso, Ltd Overview Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg. Existing Environment…
The correct answer is B. Admin1 and Admin4 only. Permissions required to create and manage sensitivity labels: "Another option is to add users to the Compliance Data Administrator, Compliance Administrator, or Security Administrator role group." https://learn.microsoft.com/en-us/purview/get-started-with-sensitivity-labels
Question
Case Study 1 - Contoso, Ltd Overview Contoso, Ltd. is a consulting company that has a main office in Montreal and three branch offices in Seattle, Boston, and Johannesburg. Existing Environment Microsoft 365 Environment Contoso has a Microsoft 365 E5 tenant. The tenant contains the administrative user accounts shown in the following table. Users store data in the following locations:
- SharePoint sites
- OneDrive accounts
- Exchange email
- Exchange public folders
- Teams chats
- Teams channel messages
When users in the research department create documents, they must add a 10-digit project code to each document. Project codes that start with the digits 999 are confidential. SharePoint Online Environment Contoso has four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4. Site2 contains the files shown in the following table. Two users named User1 and User2 are assigned roles for Site2 as shown in the following table. Site3 stores documents related to the company's projects. The documents are organized in a folder hierarchy based on the project. Site4 has the following two retention policies applied:
- Name: Site4RetentionPolicy1
Locations to apply the policy: Site4 Delete items older than: 2 years Delete content based on: When items were created
- Name: Site4RetentionPolicy2
Locations to apply the policy: Site4 Retain items for a specific period: 4 years Start the retention period based on: When items were created At the end of the retention period: Do nothing Problem Statements Management at Contoso is concerned about data leaks. On several occasions, confidential research department documents were leaked. Requirements Planned Changes Contoso plans to create the following data loss prevention (DLP) policy:
- Name: DLPpolicy1
Locations to apply the policy: Site2 Conditions:
Content contains any of these sensitive info types: SWIFT Code
- Instance count: 2 to any
Actions: Restrict access to the content Technical Requirements Contoso must meet the following technical requirements:
- All administrative users must be able to review DLP reports.
- Whenever possible, the principle of least privilege must be used.
- For all users, all Microsoft 365 data must be retained for at least
one year.
- Confidential documents must be detected and protected by using
Microsoft 365.
- Site1 documents that include credit card numbers must be labeled
automatically.
- All administrative users must be able to create Microsoft 365
sensitivity labels.
- After a project is complete, the documents in Site3 that relate to
the project must be retained for 10 years. You need to meet the technical requirements for the creation of the sensitivity labels. To which user or users must you assign the Sensitivity Label Administrator role?
Exhibits
Options
- AAdmin1 only
- BAdmin1 and Admin4 only
- CAdmin1 and Admin5 only
- DAdmin1, Admin2, and Admin3 only
- EAdmin1, Admin2, Admin4, and Admin5 only
How the community answered
(20 responses)- A20% (4)
- B65% (13)
- C10% (2)
- E5% (1)
Explanation
Permissions required to create and manage sensitivity labels: "Another option is to add users to the Compliance Data Administrator, Compliance Administrator, or Security Administrator role group." https://learn.microsoft.com/en-us/purview/get-started-with-sensitivity-labels
Topics
Community Discussion
No community discussion yet for this question.

