You have a Microsoft 365 subscription that contains 100 users and a Microsoft 365 group named Group1.
All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online.
A sensitivity label named Label1 is published as the default label for Group1.
You add two sublabels named Sublabel1 and Sublabel2 to Label1.
You need to ensure that the settings in Sublabel1 are applied by default to Group1.
What should you do?
A. Change the order of Sublabel1.
B. Modify the policy of Label1.
C. Delete the policy of Label1 and publish Sublabel1.
D. Duplicate all the settings from Sublabel1 to Label1.
Show Answer
Correct Answer: B
Explanation: Sublabels aren't automatically inherited as the default when a parent sensitivity label is already published. To have Sublabel1 applied by default, update the sensitivity label policy so that it assigns Sublabel1 as the default label for the targeted users or scope. Changing sublabel order has no effect on defaults, deleting the policy is unnecessary, and copying settings into the parent label would not make the sublabel the default.
Question 126
You have a Microsoft 365 subscription.
You create a new trainable classifier.
You need to train the classifier.
Which source can you use to train the classifier?
A. a Microsoft SharePoint Online site
B. an on-premises Microsoft SharePoint Server site
C. an NFS file share
D. an Azure Files share
Show Answer
Correct Answer: A
Explanation: Trainable classifiers in Microsoft Purview are trained using seed content stored in Microsoft 365 locations. A SharePoint Online site can be used to upload and organize seed files for training. On-premises SharePoint Server, NFS file shares, and Azure Files shares are not supported as direct training sources for trainable classifiers.
Question 127
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You need to delegate the following tasks:
• Configure role group assignments for communication compliance.
• Update and view the status of communication compliance alerts.
Which users can perform each task? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Configure the role group assignments: User2 only
Update and view the status of alert: User1 only
Explanation: Communication Compliance Admins manage communication compliance configuration, including role group assignments. Communication Compliance Analysts investigate, update, and remediate alerts. Viewers have read-only capabilities and cannot update alerts.
Question 128
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.
You create an information barrier segment named Segment1.
You need to add Segment1 to Site1.
What should you do first?
A. Run the Set-SPOSite cmdlet.
B. Run the Set-SPOTenant cmdlet.
C. Create an information barrier policy.
D. Modify the permissions of Site1.
Show Answer
Correct Answer: B
Explanation: To add an information barrier segment to a SharePoint Online site, the site is updated with Set-SPOSite. However, before that can work, Information Barriers must be enabled for SharePoint and OneDrive at the tenant level by running Set-SPOTenant with InformationBarriersSuspension set to false. Creating an information barrier policy governs communication between segments, but it is not a prerequisite for assigning a segment to a site. Therefore, the first step is to enable the tenant capability.
Sources:
https://learn.microsoft.com/en-us/purview/information-barriers-teams
Question 129
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains a user named User1 and the groups shown in the following table.
You have the Compliance Manager improvement action shown in the following exhibit.
Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Group1 and Group2 only
0/27
Explanation: Improvement actions can be assigned to supported groups (Microsoft 365 and Security), not directly to individual users. Because the testing source is Manual, enabling SSPR alone does not automatically award Compliance Manager points; points remain 0/27 until manually tested and updated.
Question 130
HOTSPOT
-
You have a Microsoft 365 E5 subscription that uses Microsoft Teams and contains the users shown in the following table.
You have the retention policies shown in the following table.
The users perform the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
Yes
Explanation: A 7-year Teams channel message retention policy applies to all teams and takes precedence over the shorter 5-year policy for Team1 because the longest retention period is retained. Teams chat between User2 and User1 is retained based on the applicable user retention, allowing the message to be retained for up to 7 years. A user-deleted Teams message under retention is preserved in the SubstrateHolds folder until the retention period expires.
Question 131
HOTSPOT
-
Your network contains an on-premises Active Directory domain named contoso.com. The domain contains the groups shown in the following table.
The domain is synced to an Azure AD tenant that contains the groups shown in the following table.
You create a sensitivity label named Label1.
You need to publish Label1.
To which groups can you publish Label1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: On-premises Active Directory groups: Group1 and Group4 only
Azure AD groups: Group13 and Group14 only
Explanation: Sensitivity label policies can target mail-enabled groups. For on-premises synced groups, only the email-enabled security/distribution groups qualify. In Azure AD, Microsoft 365 groups and mail-enabled security groups qualify; plain security groups (assigned or dynamic) do not.
Question 132
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You need to prevent users in the finance department from sharing files with users in the research department.
Which type of policy should you configure?
A. communication compliance
B. information barrier
C. Conditional Access
D. insider risk management
Show Answer
Correct Answer: B
Explanation: Information barriers are designed to prevent specific groups of users from communicating and sharing content with each other across Microsoft 365 services such as Teams, SharePoint, and OneDrive. Creating separate segments for the finance and research departments and applying an information barrier policy blocks file sharing and communication between those groups. Communication compliance monitors communications, Conditional Access controls sign-in and access conditions, and insider risk management detects and investigates risky user behavior.
Question 133
DRAG DROP
-
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2.
You need to implement insider risk management. The solution must meet the following requirements:
• Ensure that User1 can create insider risk management policies.
• Ensure that User2 can use content captured by using insider risk management policies.
• Follow the principle of least privilege.
To which role group should you add each user? To answer, drag the appropriate role groups to the correct users. Each role group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Explanation: Admins can create and manage insider risk management policies. Investigators can access and use captured content/evidence for investigations, while Analysts cannot view file content. This satisfies least privilege.
Question 134
You have a Microsoft 365 subscription.
You need to be notified by email whenever an administrator starts an eDiscovery search.
What should you do from the Microsoft Purview compliance portal?
A. From Records management create event type.
B. From eDiscovery, create an eDiscovery case.
C. From Content search, create a new search.
D. From Policies, create an alert policy.
Show Answer
Correct Answer: D
Explanation: To receive email notifications when an administrator starts an eDiscovery search, you configure an alert policy in the Microsoft Purview compliance portal. Alert policies can trigger notifications for specific audited activities, including when an eDiscovery search is started or exported. The other options do not provide activity-based email alerting.
$19
Get all 318 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.