Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam SC-900 All Questions

View all questions & answers for the SC-900 exam

Exam SC-900 topic 1 question 99 discussion

Actual exam question from Microsoft's SC-900
Question #: 99
Topic #: 1
[All SC-900 Questions]

HOTSPOT -
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: No -
Advanced Audit helps organizations to conduct forensic and compliance investigations by increasing audit log retention.

Box 2: No -

Box 3: Yes -
Reference:
https://docs.microsoft.com/en-us/microsoft-365/compliance/advanced-audit?view=o365-worldwide

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
JohnnyBas
Highly Voted 2 years, 6 months ago
NNY is correct
upvoted 11 times
...
zellck
Most Recent 1 year, 5 months ago
NNY https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-premium?view=o365-worldwide#send Investigators can use the Send event to identify email sent from a compromised account. The audit record for a Send event contains information about the message, such as when the message was sent, the InternetMessage ID, the subject line, and if the message contained attachments. This auditing information can help investigators identify information about email messages sent from a compromised account or sent by an attacker. Additionally, investigators can use a Microsoft 365 eDiscovery tool to search for the message (by using the subject line or message ID) to identify the recipients the message was sent to and the actual contents of the sent message.
upvoted 1 times
zellck
1 year, 5 months ago
https://learn.microsoft.com/en-us/microsoft-365/compliance/audit-premium?view=o365-worldwide#searchqueryinitiatedexchange Investigators can use the SearchQueryInitiatedExchange event to determine if an attacker who may have compromised an account looked for or tried to access sensitive information in the mailbox. The audit record for a SearchQueryInitiatedExchange event contains information such as the actual text of the search query. The audit record also indicates the Outlook environment the search was performed in. By looking at the search queries that an attacker may have performed, an investigator can better understand the intent of the email data that was searched for.
upvoted 1 times
...
...
JA2018
2 years, 8 months ago
Shouldn't the answer to part 2 be "Yes"?
upvoted 2 times
Randy8
2 years, 8 months ago
No, "The actual content of the message is not displayed." https://docs.microsoft.com/en-ca/learn/modules/describe-ediscovery-capabilities-of-microsoft-365/5b-describe-purpose-value-advanced-auditing
upvoted 3 times
jaaake
1 year, 3 months ago
I am confused about this "Content Explorer Content viewer: Membership in this role group allows you to view the contents of each item in the list. The data classification content viewer role has been pre-assigned to this role group." There is also an alert on that page "Important: These permissions supercede permissions that are locally assigned to the items, which allows viewing of the content."
upvoted 1 times
...
jaaake
1 year, 3 months ago
In other words, without viewing the content how can you express an audit opinion?
upvoted 1 times
...
...
...
JA2018
2 years, 8 months ago
https://docs.microsoft.com/en-us/microsoft-365/compliance/advanced-audit?view=o365-worldwide
upvoted 1 times
...
JA2018
2 years, 8 months ago
Send The Send event is also a mailbox auditing action and is triggered when a user performs one of the following actions: Sends an email message Replies to an email message Forwards an email message Investigators can use the Send event to identify email sent from a compromised account. The audit record for a Send event contains information about the message, such as when the message was sent, the InternetMessage ID, the subject line, and if the message contained attachments. This auditing information can help investigators identify information about email messages sent from a compromised account or sent by an attacker. Additionally, investigators can use a Microsoft 365 eDiscovery tool to search for the message (by using the subject line or message ID) to identify the recipients the message was sent to and the actual contents of the sent message.
upvoted 4 times
...
[Removed]
2 years, 11 months ago
Correct
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...