HOTSPOT
-
You have a Microsoft 365 tenant.
You need to create a new sensitive info type for items that contain the following:
• An employee ID number that consists of the hire date of the employee followed by a three digit number
• The words “Employee”, “ID”, or “Identification” within 300 characters of the employee ID number
What should you use for the primary and secondary elements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Primary element: Functions
Secondary element: A keyword list
Explanation: Use a function as the primary element to detect a date-based number pattern reliably, and a keyword list as the secondary element to require the presence of terms like "Employee", "ID", or "Identification" within the specified proximity.
Question 115
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
You create a sensitivity label that has the following settings:
• Name: Sensitivity1
• Define the scope for this label: Items
• Choose protection settings for files and emails: Mark the content of files
• Add custom headers, footers, and watermarks to files and emails that have this label applied
You make Sensitivity available to User1.
User1 performs the following actions:
• Creates a new email
• Adds a file named File1.docx as an attachment to the email
• Applies Sensitivity1 to the email
• Sends the email to User2
How will the email and the attachment be marked? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Email:
Marked with a header, a footer, and a watermark
Attachment:
Not marked
Explanation: The sensitivity label is applied only to the email item. When a label that adds headers, footers, and watermarks is applied to an email, the email itself is marked according to the label configuration. Attachments do not automatically inherit the label or its markings unless the label is applied directly to the file, so the attached document remains unmarked.
Question 116
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
The subscription contains the information barrier segments shown in the following table.
The subscription contains the Microsoft SharePoint Online sites shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1 can access Site1: Yes
User2 can access Site2: No
User3 can access Site2: Yes
Explanation: Information barriers allow access only when a user matches the site segment and is permitted. User1 belongs to Finance and Site1 is associated with Segment1 (Finance). User2 belongs to IT and does not match Site2’s Marketing segment. User3 belongs to Marketing and matches Site2’s segment, so access is allowed if shared, even without prior membership.
Question 117
DRAG DROP
-
You have a Microsoft 365 E5 subscription.
You need to prevent the sharing of sensitive information in Microsoft Teams.
Which entities can you protect by applying a data loss prevention (DLP) policy to each resource? To answer, drag the appropriate activities to the correct entity. Each activity may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User accounts:
1:1/n chats and private channels only
Microsoft 365 groups:
General chats only
Security groups or distribution lists:
1:1/n chats and private channels only
Explanation: In Microsoft Teams DLP, the scope depends on the entity type. Policies scoped to user accounts or security groups/distribution lists can protect 1:1, group chats, and private channel messages, but not standard (general) channel messages. Policies scoped to Microsoft 365 groups apply to standard (general) channel messages only, not private channels or 1:1 chats.
Question 118
You have a Microsoft 365 E5 subscription.
You plan to implement information barriers (IBs).
You need to create an IB segment named Segment1.
What should you use to define Segment1?
A. a user group filter
B. a distribution list group
C. a Microsoft 365 group
D. an administrative unit
Show Answer
Correct Answer: A
Explanation: Information Barriers segments are defined by user attributes using a user group filter (for example, Department, JobTitle, or custom attributes). Segments are not based directly on distribution lists, Microsoft 365 groups, or administrative units.
Question 119
You have a Microsoft 365 subscription linked to a Microsoft Entra tenant that contains a user named User1.
You need to grant User1 permission to search Microsoft 365 audit logs. The solution must use the principle of least privilege.
Which role should you assign to User1?
A. the Reviewer role in the Microsoft Purview compliance portal
B. the View-Only Audit Logs role in the Exchange admin center
C. the Compliance Management role in the Exchange admin center
D. the Security Reader role in the Microsoft Entra admin center
Show Answer
Correct Answer: B
Explanation: To search Microsoft 365 audit logs with least privilege, the user must have permissions specifically scoped to audit log viewing. The View-Only Audit Logs role grants read-only access to search and export audit logs without broader compliance or administrative permissions. Other roles either do not grant audit log search capability or provide excessive privileges.
Question 120
You have a Microsoft 365 subscription.
The Global Administrator role is assigned to your user account.
You have a user named Admin1.
You create an eDiscovery case named Case1.
You need to ensure that Admin1 can view the results of Case1.
What should you do first?
A. From the Microsoft Entra admin center, assign a role group to Admin1.
B. From the Microsoft Purview compliance portal, assign a role group to Admin1.
C. From the Microsoft 365 admin center, assign a role to Admin1.
Show Answer
Correct Answer: B
Explanation: Viewing eDiscovery case results requires eDiscovery permissions, which are managed through role groups in the Microsoft Purview compliance portal (such as eDiscovery Manager). These permissions are not assigned via the Microsoft 365 admin center or Entra roles. Therefore, the first step is to assign Admin1 to the appropriate role group in the Purview compliance portal.
Question 121
You have a Microsoft 365 E5 subscription that contains two users named User1 and Admin1. Admin1 manages audit retention policies for the subscription.
You need to ensure that the audit logs of User1 will be retained for 10 years.
What should you do first?
A. Assign a Microsoft Purview Audit (Premium) add-on license to User1.
B. Assign a 10-year audit log retention add-on license to Admin1.
C. Assign a Microsoft Purview Audit (Premium) add-on license to Admin1.
D. Assign a 10-year audit log retention add-on license to User1.
Show Answer
Correct Answer: D
Explanation: To retain audit logs for a specific user for up to 10 years, Microsoft requires assigning the 10-year audit log retention add-on license to the user whose activities are being retained. Admin1 only manages policies; the license must be applied to User1 before creating or applying a 10-year audit log retention policy.
Question 122
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
On January 1, you create the sensitivity label shown in the following table.
On January 2, you publish Label1 to User1.
On January 3, User1 creates a Microsoft Word document named Doc and applies Label to the document.
On January 4, User2 edits Doc1.
On January 15, you increase the content expiry period for Label1 to 28 days.
When will access to Doc1 expire for User2?
A. January 23
B. January 24
C. January 25
D. January 31
Show Answer
Correct Answer: B
Explanation: Sensitivity label settings, including content expiry, are stamped on the document at the time the label is applied. Doc1 was labeled on January 3 when Label1 had a 21‑day expiry. Later changes to the label (on January 15) do not retroactively affect already labeled content. Therefore, access for User2 expires 21 days after January 3, which is January 24.
Question 124
You have a Microsoft 365 subscription that contains 100 users and a Microsoft 365 group named Group1.
All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online.
A sensitivity label named Label1 is published as the default label for Group1.
You add two sublabels named Sublabel1 and Sublabel2 to Label1.
You need to ensure that the settings in Sublabel1 are applied by default to Group1.
What should you do?
A. Change the order of Sublabel1.
B. Modify the policy of Label1.
C. Delete the policy of Label1 and publish Sublabel1.
D. Duplicate all the settings from Sublabel1 to Label1.
Show Answer
Correct Answer: B
Explanation: For Microsoft 365 groups, the default sensitivity label (including sublabels) is controlled by the label policy, not by label order or label inheritance. Even though Label1 is already the default for Group1, sublabels are not automatically applied unless explicitly configured. To ensure Sublabel1 is applied by default, you must modify the existing label policy for Label1 and set Sublabel1 as the default label for the group. The other options do not change which label is applied by default.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.