You have a Microsoft 365 E5 subscription.
You need to ensure that any message or document containing a credit card number is deleted automatically 12 months after it was created. The solution must minimize administrative effort.
Which two components should you create? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. a sensitivity label
B. an auto-labeling policy for a sensitivity label
C. a retention label
D. an auto-labeling policy for a retention label
E. a sensitive information type (SIT)
Show Answer
Correct Answer: C, D
Explanation: To automatically delete content after a fixed period, you must use retention, not sensitivity. A retention label defines the retention period (12 months from creation with delete action). To minimize administrative effort and ensure it applies to any message or document containing a credit card number, you use an auto-labeling policy for the retention label, which can leverage the built-in Credit Card sensitive information type. There is no need to create a new SIT or use sensitivity labels.
Question 105
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 E5 subscription.
You need to identify resumes that are stored in the subscription by using a built-in trainable classifier.
Solution: You create a retention policy.
Does this meet the goal?
A. Yes
B. No
Show Answer
Correct Answer: B
Explanation: A retention policy is used to retain or delete content based on conditions; it does not identify or classify content. Built-in trainable classifiers are created and used within Microsoft Purview for classification, not via retention policies.
Question 106
You have a Microsoft 365 E5 tenant that contains a user named User1. User1 is assigned the Compliance Administrator role.
User1 cannot view the regular expression in the IP Address sensitive info type.
You need to ensure that User1 can view the regular expression.
What should you do?
A. Assign User1 the Global Reader role.
B. Assign User1 to the Reviewer role group.
C. Instruct User to use the Test function on the sensitive info type.
D. Create a copy of the IP Address sensitive info type and instruct User1 to edit the copy.
Show Answer
Correct Answer: D
Explanation: Built-in sensitive information types (SITs) like IP Address do not expose their underlying regular expressions for viewing. Even Compliance Administrators cannot see the regex unless they are editing a custom SIT. By creating a copy of the built-in IP Address sensitive info type, User1 can open the edit screen of the custom copy, where the regular expression is visible. Other roles or the Test function do not reveal the regex.
Question 107
DRAG DROP
-
You have a Microsoft 365 E5 subscription.
You need to label Microsoft Exchange Online emails that match the following conditions:
• Contain employment offers
• Contain offensive language
• Contain medical terms and conditions
The solution must minimize administrative effort.
Which type of data classification should you use for each condition? To answer, drag the appropriate data classification types to the correct conditions. Each data classification type may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Contain employment offers:
Trainable classifier
Contain offensive language:
Trainable classifier
Contain medical terms and conditions:
Sensitive info type
Explanation: To minimize administrative effort, use built-in Microsoft Purview capabilities. Employment offers are best detected with the preconfigured Trainable classifier (Employment agreement). Offensive language is covered by the Profanity trainable classifier. Medical terms and conditions are already defined in the built-in Sensitive info type "All medical terms and conditions," requiring no training.
Question 108
HOTSPOT
-
You have a Microsoft SharePoint Online site named Site1 that contains the users shown in following table.
You create the retention labels shown in the following table.
You publish the retention labels to Site1.
Site1 contains the files shown in following table.
Which files can User1 delete on May 15, 2023, and which files can User2 delete on August 15, 2024? To answer, drag the appropriate files to the correct users. Each file may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: May 15, 2023:
No files
Aug 15, 2024:
File1 only
Explanation: Retention labels prevent deletion during the active retention period (items are not records, but deletion is blocked). File1 has Retention1 (2 years from Aug 1, 2022), so it is protected until Aug 1, 2024 and can be deleted after that date. File2 has Retention2 (1 year from Aug 1, 2022), which then changes to Retention1, extending retention until Aug 1, 2025. Therefore, on May 15, 2023 neither file can be deleted, and on Aug 15, 2024 only File1 is deletable.
Question 109
DRAG DROP
-
You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps.
You plan to deploy a Defender for Cloud Apps file policy that will be triggered when the following conditions are met:
• A file is shared externally.
• A file is labeled as internal only.
Which filter should you use for each condition? To answer, drag the appropriate filters to the correct conditions. Each filter may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: When a file is shared externally:
Access level
When a file is labelled as Internal only:
Sensitivity label
Explanation: Access level filters files by sharing scope (public, external, internal, private). Sensitivity label filters files based on Microsoft Purview sensitivity labels such as Internal only.
Question 110
HOTSPOT
-
You plan to provide a user named User1 with the ability to view data loss prevention (DLP) reports.
You need to identify the following:
• Which role you should assign to User1
• Which tool you should use to assign the role
What should you identify? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Security Reader
Microsoft Purview compliance portal
Explanation: Viewing DLP reports requires read-only security/compliance permissions. The Security Reader role provides access to DLP reports without administrative rights, and compliance-related roles are assigned and managed in the Microsoft Purview compliance portal under Permissions.
Question 111
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You need to delegate the following tasks:
• Create and manage data loss prevention (DLP) policies.
• Review classified content by using Content explorer.
The solution must use the principle of least privilege.
Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Create and manage DLP policies: User1
Review classified content by using Content explorer: User3
Explanation: Information Protection Administrator has permissions to create and manage DLP policies. Content explorer access requires Information Protection Investigator; Analysts do not have Content explorer permissions.
Question 112
You have a Microsoft 365 tenant that has data loss prevention (DLP) policies.
You need to review DLP policy matches for the tenant.
What should you use?
A. Content explorer
B. Activity explorer
C. Compliance Manager
D. records management events
Show Answer
Correct Answer: B
Explanation: To review DLP policy matches, you need visibility into DLP events where content matched a DLP rule. In Microsoft Purview, **Activity explorer** collects and displays DLP policy match events from Exchange, SharePoint, OneDrive, Teams, endpoints, and other workloads, allowing you to filter and review these matches over time. Content explorer focuses on where sensitive data exists, not on DLP policy match events.
Question 113
HOTSPOT
-
You have two Microsoft 365 subscriptions named Contoso and Fabrikam. The subscriptions contain the users shown in the following table.
You have a sensitivity label named Sensitiviy1 as shown in the exhibit. (Click the Exhibit tab.)
You have the files shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Sensitivity1 assigns Co-Owner permissions to contoso.com and Reviewer permissions to fabrikam.com.
User1 (Contoso) is a Co-Owner and can remove encryption from File1, even if it was auto-labeled.
User2 (Contoso) is a Co-Owner and can remove encryption from File3.
User3 (Fabrikam) is a Reviewer on File2 and Reviewer permissions do not include Print rights.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.