exam questions

Exam SC-401 All Questions

View all questions & answers for the SC-401 exam

Exam SC-401 topic 3 question 19 discussion

Actual exam question from Microsoft's SC-401
Question #: 19
Topic #: 3
[All SC-401 Questions]

You have Microsoft 365 E5 subscription.
You create two alert policies named Policy1 and Policy2 that will be triggered at the times shown in the following table.

How many alerts will be added to the Microsoft Purview portal?

  • A. 2
  • B. 3
  • C. 4
  • D. 5
  • E. 6
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PsiCzar
Highly Voted 1 month, 3 weeks ago
Selected Answer: C
Answer is incorrect, it should be C. 4, based on https://learn.microsoft.com/en-us/purview/compliance-manager-alert-policies "When multiple events that match the conditions of an alert policy occur within one minute, they're added to an existing alert by a process called alert aggregation." So: Policy 1: has 3 alerts in less than a minute, so 1 alert is generated, then a further 2 alerts separated by more than a minute each, consolidated that's 3 alerts Policy 2: has 2 alerts all within the same minute, so that is 1 alert
upvoted 6 times
Jdr379
1 month ago
I concur that it's C.
upvoted 1 times
...
...
Jdr379
Most Recent 1 month ago
Selected Answer: C
Answer is C. Microsoft 365 E5: 1-minute aggregation interval Same aggregation logic: When multiple events that match the conditions of an alert policy occur with a short period of time, they're added to an existing alert by a process called alert aggregation
upvoted 1 times
...
4d76265
1 month, 3 weeks ago
Selected Answer: C
PsiCzar's answer is the best here with MS reference.
upvoted 1 times
...
CuentaRM10
1 month, 3 weeks ago
Selected Answer: C
Sorry, it should be C To prevent alert overload, policy matches on the same item in the same location are grouped if they occur within a one-minute window. https://learn.microsoft.com/en-us/training/modules/purview-data-loss-prevention-alerts/configure-data-loss-prevention-alert-generation
upvoted 1 times
...
CuentaRM10
1 month, 3 weeks ago
Selected Answer: A
It should be Answer A. All matches that are detected within a span of 60 minutes will be grouped into one single alert to reduce excessive notifications https://learn.microsoft.com/en-us/purview/compliance-manager-alert-policies#default-score-change-policy
upvoted 1 times
...
papillor
1 month, 3 weeks ago
Selected Answer: A
Correction Good answer is A !! Only 2 alerts ! I misclicked.
upvoted 1 times
...
papillor
1 month, 3 weeks ago
Selected Answer: B
When the same alert is generated multiple times within a short period (by default 5 minutes), Microsoft Purview consolidates these occurrences into a single alert in the portal.
upvoted 1 times
...
jeff1988
2 months, 1 week ago
Selected Answer: E
Each alert policy triggers independently based on the specified times. Here are the times again: Policy1: 10:00:00, 10:00:04, 10:01:01, 10:04:45 (4 alerts) Policy2: 10:00:03, 10:00:31 (2 alerts) Since each trigger time results in a separate alert, we count all the times: Policy1: 4 alerts Policy2: 2 alerts Adding them together, we get 6 alerts. Therefore, the correct answer is E. 6.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...