HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1 and a sensitivity label named Label1.
The external sharing settings for Site1 are configured as shown in the Site1 exhibit. (Click the Site1 tab.)
The external sharing settings for Label1 are configured as shown in the Label1 exhibit. (Click the Label1 tab.)
Label1 is applied to Site1.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: The sensitivity label overrides the site's external sharing setting and allows 'Anyone' sharing. 'Anyone' links do not require invitations or sign-in. Conditional Access for labeled sites is not enabled, so managed devices are not required.
Question 105
You have a Microsoft 365 E5 subscription.
You need to ensure that any message or document containing a credit card number is deleted automatically 12 months after it was created. The solution must minimize administrative effort.
Which two components should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. a sensitivity label
B. an auto-labeling policy for a sensitivity label
C. a retention label
D. an auto-labeling policy for a retention label
E. a sensitive information type (SIT)
Show Answer
Correct Answer: C, D
Explanation: Use a retention label configured to delete items 12 months after creation. Then create an auto-labeling policy for the retention label that applies the label to messages and documents containing credit card numbers by using the built-in Sensitive Information Type for credit card numbers. Because Microsoft 365 already includes a built-in credit card SIT, creating a new SIT is unnecessary and would increase administrative effort.
Question 106
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You need to identify resumes that are stored in the subscription by using a built-in trainable classifier.
Solution: You create a retention policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: A retention policy governs how content is retained or deleted; it does not identify resumes using a built-in trainable classifier. To identify resumes, you would create and use the built-in trainable classifier (e.g., in Microsoft Purview) and then apply it in policies such as auto-labeling or other compliance solutions. Therefore, creating only a retention policy does not meet the goal.
Question 107
You have a Microsoft 365 E5 tenant that contains a user named User1. User1 is assigned the Compliance Administrator role.
User1 cannot view the regular expression in the IP Address sensitive info type.
You need to ensure that User1 can view the regular expression.
What should you do?
A. Assign User1 the Global Reader role.
B. Assign User1 to the Reviewer role group.
C. Instruct User to use the Test function on the sensitive info type.
D. Create a copy of the IP Address sensitive info type and instruct User1 to edit the copy.
Show Answer
Correct Answer: D
Explanation: Built-in Microsoft Purview sensitive information types expose their underlying regular expressions only when working with an editable copy. A Compliance Administrator cannot view or edit the regex of the built-in IP Address sensitive info type directly. Creating a copy of the built-in sensitive info type and opening the copy for editing allows the regular expression to be viewed. The Global Reader role and Reviewer role do not provide this capability, and the Test function does not reveal the regex.
Question 108
DRAG DROP
-
You have a Microsoft 365 E5 subscription.
You need to label Microsoft Exchange Online emails that match the following conditions:
• Contain employment offers
• Contain offensive language
• Contain medical terms and conditions
The solution must minimize administrative effort.
Which type of data classification should you use for each condition? To answer, drag the appropriate data classification types to the correct conditions. Each data classification type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Contain employment offers: Trainable classifier
Contain offensive language: Trainable classifier
Contain medical terms and conditions: Sensitive info type
Explanation: Use built-in trainable classifiers for employment agreements/offers and profanity (offensive language). Use the built-in Sensitive Information Type 'All medical terms and conditions' for medical content. Exact Data Match (EDM) is for matching against your own structured datasets and is not appropriate here.
Question 109
HOTSPOT
-
You have a Microsoft SharePoint Online site named Site1 that contains the users shown in following table.
You create the retention labels shown in the following table.
You publish the retention labels to Site1.
Site1 contains the files shown in following table.
Which files can User1 delete on May 15, 2023, and which files can User2 delete on August 15, 2024? To answer, drag the appropriate files to the correct users. Each file may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: May 15, 2023: File1 and File2
August 15, 2024: File1 and File2
Explanation: Retention labels alone do not block deletion unless the item is declared a record or a regulatory record. Deleting a retained item is allowed; the service preserves a copy to satisfy retention. The label transition after the retention period affects retention behavior, not the user's ability to delete before or after.
Question 110
DRAG DROP
-
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You plan to deploy a Defender for Cloud Apps file policy that will be triggered when the following conditions are met:
• A file is shared externally.
• A file is labeled as internal only.
Which filter should you use for each condition? To answer, drag the appropriate filters to the correct conditions. Each filter may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: When a file is shared externally: Access level
When a file is labelled as Internal only: Sensitivity label
Explanation: Use the Access level filter to detect externally shared files, and the Sensitivity label filter to match files labeled 'Internal only'.
Question 111
HOTSPOT
-
You plan to provide a user named User1 with the ability to view data loss prevention (DLP) reports.
You need to identify the following:
• Which role you should assign to User1
• Which tool you should use to assign the role
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Role: Security Reader
Tool: Microsoft Purview compliance portal
Explanation: Viewing DLP reports requires read access to security/compliance information. The least-privilege built-in role is Security Reader, and compliance role assignments for Microsoft Purview features are managed in the Microsoft Purview compliance portal.
Question 112
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You need to delegate the following tasks:
• Create and manage data loss prevention (DLP) policies.
• Review classified content by using Content explorer.
The solution must use the principle of least privilege.
Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Create and manage DLP policies: User1
Review classified content using Content explorer: User3
Explanation: Information Protection Administrator has permissions to create and manage DLP policies. Information Protection Investigator can access Content explorer to review classified content, while Information Protection Analyst cannot access Content explorer.
Question 113
You have a Microsoft 365 tenant that has data loss prevention (DLP) policies.
You need to review DLP policy matches for the tenant.
What should you use?
A. Content explorer
B. Activity explorer
C. Compliance Manager
D. records management events
Show Answer
Correct Answer: B
Explanation: Activity explorer is the correct tool for reviewing DLP policy matches and DLP-related events across Microsoft 365 workloads. It provides visibility into DLP policy match events and other compliance activities. Content explorer is used to inspect and locate sensitive content, not to review DLP policy match events. Compliance Manager assesses compliance posture, and records management events are for records lifecycle activities.
$19
Get all 318 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.