HOTSPOT
-
You have two Microsoft 365 subscriptions named Contoso and Fabrikam. The subscriptions contain the users shown in the following table.
You have a sensitivity label named Sensitiviy1 as shown in the exhibit. (Click the Exhibit tab.)
You have the files shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Auto-applied labels are automatically re-applied, so the encryption cannot effectively be removed by the user. A Co-Owner can remove protection from content they own. Reviewer permission allows viewing but not printing.
Question 115
HOTSPOT
-
You have a Microsoft 365 tenant.
You need to create a new sensitive info type for items that contain the following:
• An employee ID number that consists of the hire date of the employee followed by a three digit number
• The words “Employee”, “ID”, or “Identification” within 300 characters of the employee ID number
What should you use for the primary and secondary elements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Primary element: A regular expression
Secondary element: A keyword list
Explanation: Use a regular expression to detect the employee ID pattern (hire date followed by three digits). Use a keyword list for the supporting terms ('Employee', 'ID', 'Identification') within the specified proximity.
Question 116
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
You create a sensitivity label that has the following settings:
• Name: Sensitivity1
• Define the scope for this label: Items
• Choose protection settings for files and emails: Mark the content of files
• Add custom headers, footers, and watermarks to files and emails that have this label applied
You make Sensitivity available to User1.
User1 performs the following actions:
• Creates a new email
• Adds a file named File1.docx as an attachment to the email
• Applies Sensitivity1 to the email
• Sends the email to User2
How will the email and the attachment be marked? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Email: Marked with a header and footer only
Attachment: Not marked
Explanation: Sensitivity label content markings apply to the item the label is applied to. Emails support headers and footers but not watermarks. Applying the label to the email does not automatically mark an attached Word document; the document would need the label applied directly.
Question 117
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
The subscription contains the information barrier segments shown in the following table.
The subscription contains the Microsoft SharePoint Online sites shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: A SharePoint site with an information barrier segment is restricted to users in the matching segment who also have appropriate site permissions. Site1 is assigned to the Finance segment and User1 is in Finance and a site member. Site2 is assigned to the Marketing segment; User2 is not in Marketing, and User3 is not a site member.
Question 118
DRAG DROP
-
You have a Microsoft 365 E5 subscription.
You need to prevent the sharing of sensitive information in Microsoft Teams.
Which entities can you protect by applying a data loss prevention (DLP) policy to each resource? To answer, drag the appropriate activities to the correct entity. Each activity may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User accounts: 1:1/n chats and private channels only
Microsoft 365 groups: 1:1/n chats and general chats only
Security groups or distribution lists: 1:1/n chats and private channels only
Explanation: Teams DLP scope depends on the entity selected. User accounts cover 1:1/group chats and private channels. Microsoft 365 groups cover team (standard/shared) channel messages plus chats. Security groups/distribution lists behave like collections of users, so they cover chats and private channels.
Question 119
You have a Microsoft 365 E5 subscription.
You plan to implement information barriers (IBs).
You need to create an IB segment named Segment1.
What should you use to define Segment1?
A. a user group filter
B. a distribution list group
C. a Microsoft 365 group
D. an administrative unit
Show Answer
Correct Answer: A
Explanation: Information Barriers segments are defined using user group filters based on user attributes (such as Department, Country, or other supported Entra ID attributes). Distribution lists, Microsoft 365 groups, and administrative units are not used to define IB segments themselves, though group membership may be referenced within filter criteria in some scenarios.
Question 120
You have a Microsoft 365 subscription linked to a Microsoft Entra tenant that contains a user named User1.
You need to grant User1 permission to search Microsoft 365 audit logs. The solution must use the principle of least privilege.
Which role should you assign to User1?
A. the Reviewer role in the Microsoft Purview compliance portal
B. the View-Only Audit Logs role in the Exchange admin center
C. the Compliance Management role in the Exchange admin center
D. the Security Reader role in the Microsoft Entra admin center
Show Answer
Correct Answer: B
Explanation: The least-privilege role that allows searching Microsoft 365 audit logs is the View-Only Audit Logs role. Although current Microsoft documentation also describes assigning this permission through the Microsoft Purview Audit Reader role group, among the provided options the correct match is the View-Only Audit Logs role in Exchange Online role-based access control. Reviewer, Compliance Management, and Security Reader do not specifically grant audit log search permissions.
Question 121
You have a Microsoft 365 subscription.
The Global Administrator role is assigned to your user account.
You have a user named Admin1.
You create an eDiscovery case named Case1.
You need to ensure that Admin1 can view the results of Case1.
What should you do first?
A. From the Microsoft Entra admin center, assign a role group to Admin1.
B. From the Microsoft Purview compliance portal, assign a role group to Admin1.
C. From the Microsoft 365 admin center, assign a role to Admin1.
Show Answer
Correct Answer: B
Explanation: To view eDiscovery case content and results, a user must be assigned an appropriate eDiscovery role group (such as eDiscovery Manager or eDiscovery Administrator) in the Microsoft Purview compliance portal. Microsoft Entra roles or Microsoft 365 admin center roles alone do not grant eDiscovery case permissions. The first step is to assign the required role group in the Purview compliance portal.
Question 122
You have a Microsoft 365 E5 subscription that contains two users named User1 and Admin1. Admin1 manages audit retention policies for the subscription.
You need to ensure that the audit logs of User1 will be retained for 10 years.
What should you do first?
A. Assign a Microsoft Purview Audit (Premium) add-on license to User1.
B. Assign a 10-year audit log retention add-on license to Admin1.
C. Assign a Microsoft Purview Audit (Premium) add-on license to Admin1.
D. Assign a 10-year audit log retention add-on license to User1.
Show Answer
Correct Answer: D
Explanation: Microsoft 365 E5 includes Microsoft Purview Audit (Premium), but retaining audit logs for 10 years requires a separate 10-year audit log retention add-on license assigned to the specific user whose audit data will be retained. After licensing the user, a 10-year audit log retention policy can be configured. Therefore, the first step is to assign the 10-year audit log retention add-on license to User1.
Question 123
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
On January 1, you create the sensitivity label shown in the following table.
On January 2, you publish Label1 to User1.
On January 3, User1 creates a Microsoft Word document named Doc and applies Label to the document.
On January 4, User2 edits Doc1.
On January 15, you increase the content expiry period for Label1 to 28 days.
When will access to Doc1 expire for User2?
A. January 23
B. January 24
C. January 25
D. January 31
Show Answer
Correct Answer: B
Explanation: The document was labeled on January 3 with the sensitivity label's original content expiry setting of 21 days. Protection and label settings are embedded when the label is applied, so increasing the label's expiry period on January 15 does not retroactively update already-labeled documents. Therefore, access expires 21 days after January 3, which is January 24.
$19
Get all 318 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.