Free Microsoft SC-401 Actual Exam Questions - Question 9 Discussion

Question No. 9Drag & Drop

DRAG DROP You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies. You need to identify the following: ● Rules that are applied without triggering a policy alert ● The top 10 files that have matched DLP policies ● Alerts that are miscategorized Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. SC-401 practice exam questions

Options
ADLP policy matches
BFalse positive and override
CIncident reports
Drag an item to a target. Click × to remove.
Answer Area
Rules that are applied without triggering a policy alert
Drop item here
The top 10 files that have matched DLP policies
Drop item here
Alerts that are miscategorized
Drop item here
US
AI
Arjun I.
2026-02-18

Policy Matches shows rules applied silently, so fits no alert requirement.

0
RW
Ravi W.
2026-02-16

For rules without alerts, "Policy Matches" works since it shows matches ignored by alerts. The top 10 files need "File Matches" because it focuses on file-level hits. Miscategorized alerts fit "Alerts" report better.

0
RN
Rayan N.
2026-02-11

Policy Matches for no alerts, File Matches for top 10 files, Alerts for miscategorized.

0
FU
Farhan U.
2026-02-09

No alerts in a rule means that report checks inactive rules, so maybe “Policy Matches” for that?

0
FU
Farhan U.
2026-01-30

The report for files matching DLP policies should highlight top 10 files, so “File Matches” fits best.

0
RN
Rayan N.
2026-01-15

This one’s tricky without the image, but sounds like DLP reports stuff?

0