HOTSPOT
-
You have a Microsoft 365 E5 subscription that uses Microsoft Purview Audit (Premium) with the 10-Year Audit Log Retention add-on license.
The subscription contains the audit retention policies shown in the following table.
From the SharePoint Online admin center, User1 performs the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
Yes
Explanation: Only activities explicitly matched by an audit retention policy use that policy. For 'Created site collection', the higher-priority matching policy (priority 40) retains for 3 years. 'Renamed site' matches the 6-month policy. 'Archives a site' has no matching activity-specific policy, so it is not retained for 1 year.
Question 12
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You have a file named Customer.csv that contains a list of 1,000 customer names.
You plan to use Customer.csv to classify documents stored in a Microsoft SharePoint Online library.
What should you create in the Microsoft Purview compliance portal, and which type of element should you select? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Create: A sensitive info type
Element: Keyword dictionary
Explanation: To classify SharePoint documents based on a list of customer names from a CSV, create a custom Sensitive Information Type that uses a Keyword Dictionary. A keyword dictionary is designed to match large lists of exact terms such as customer names. Trainable classifiers learn document patterns rather than matching a supplied list.
Question 13
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You create a sensitive information type (SIT) named SIT1.
You plan to create the communication compliance polices shown in the following table.
To which policies can you add SIT1 as a condition?
A. Policy1 only
B. Policy3 only
C. Policy1 and Policy2 only
D. Policy1 and Policy3 only
E. Policy1, Policy 2, and Policy3
Show Answer
Correct Answer: A
Explanation: Sensitive information types can be used as conditions in Communication Compliance policies based on the 'Detect inappropriate text' template. Other templates typically use trainable classifiers, classifiers, or different condition types rather than custom sensitive information types. Therefore, SIT1 can be added only to the policy created from that template (Policy1).
Question 14
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You have a Privacy Risk Management policy named Policy1 based on the Data transfers template as shown in the Privacy Risk Management policy exhibit. (Select the Privacy Risk Management policy tab and scroll to review the entire policy.)
User1 sends the following email messages that contain credit card information:
• Message1: Sent to User2.
• Message2: Sent to User3.
• Message3: Sent to User4.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Message1: Yes
Message2: No
Message3: Yes
Explanation: The policy applies to the monitored user, requires the sender to be in Group1 and the recipient to be in Group2, and matches credit card data. User1 is in Group1. User2 and User4 are in Group2, while User3 is not.
Question 15
You have a Microsoft 365 subscription that contains a user named User1.
User1 plans to export a history of Microsoft Purview communication compliance policy changes.
You need to add User1 to a role group in Microsoft Purview. The solution must follow the principle of least privilege.
To which role group should you add User1?
A. Communication Compliance Investigators
B. Communication Compliance Viewers
C. Communication Compliance Analysts
D. Communication Compliance Administrators
Show Answer
Correct Answer: B
Explanation: To export a history of Microsoft Purview communication compliance policy changes, the user only needs read/view access to communication compliance information. The Communication Compliance Viewers role group provides permissions to view settings, reports, and related information without granting administrative or investigative capabilities, satisfying the principle of least privilege.
Question 16
HOTSPOT
-
You have a Microsoft 365 E5 tenant that contains a published sensitivity label named Sensitivity1.
You plan to create a Microsoft Entra group named Group1 and assign Sensitivity1 to Group1.
How should you configure Group1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Setting: EnableMIPLabels
Type: Microsoft 365
Explanation: Sensitivity labels for groups require Microsoft Entra support for MIP labels to be enabled and can only be assigned to Microsoft 365 groups, not security, mail-enabled security, or distribution groups.
Question 17
HOTSPOT
-
You have a Microsoft E5 subscription that contains two users named User1 and User2.
You have a Microsoft SharePoint site named Site1. Site1 stores files that contain IP addresses as shown in the following table.
User1 is assigned the SharePoint admin role for Site1. User2 is a member of Site1.
You create the data loss prevention (DLP) policy shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: The DLP policy blocks access to SharePoint content containing at least two detected IP addresses. File1.txt (3 IPs) is blocked for regular users, but site/admin access is not restricted by this DLP block. File2.docx (1 IP) does not meet the threshold and remains accessible.
Question 18
HOTSPOT
-
You have a Microsoft 365 subscription.
You identify the following data loss prevention (DLP) requirements:
• Send notifications to users if they attempt to send attachments that contain an EU Social Security Number (SSN) or Equivalent ID.
• Prevent any email messages that contain credit card numbers from being sent outside your organization.
• Block the external sharing of Microsoft OneDrive content that contains EU passport numbers.
• Send administrators email alerts if any rule matches occur.
What is the minimum number of DLP policies and rules you must create to meet the requirements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Policies: 2
Rules: 3
Explanation: A single DLP policy can target Exchange email and include separate rules for EU SSN notifications and credit card blocking. A second policy is needed for OneDrive to block external sharing of EU passport numbers. Admin alerts are configured as actions within the matching rules, not as a separate rule.
Question 19
You have a Microsoft 365 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2.
You plan to use policies to meet the following requirements:
• Add a watermark of Confidential to a document if the document contains the words Project1 or Project2.
• Retain a document for seven years if the document contains credit card information.
• Add a watermark of Internal Use Only to all the documents stored on Site2.
• Add a watermark of Confidential to all the documents stored on Site1.
You need to recommend the minimum number of sensitive info types required.
How many sensitive info types should you recommend?
A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: B
Explanation: You need two sensitive information types: one custom sensitive information type that detects the keywords 'Project1' or 'Project2' to drive the Confidential watermark, and the built-in Credit Card Number sensitive information type to retain documents containing credit card information for seven years. The site-wide watermark requirements for Site1 and Site2 can be implemented using location-based labeling/policies and do not require additional sensitive information types.
Question 20
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2. The subscription has a data loss prevention (DLP) policy named Policy1.
User2 sends an outbound message that generates a false positive for Policy1.
You need to ensure that User1 can download the message that generated the alert. The solution must follow the principle of least privilege.
To which role group should you add User1?
A. Data Investigator
B. Global Reader
C. eDiscovery Manager
D. Security Operator
Show Answer
Correct Answer: A
Explanation: The Data Investigator role includes the ability to preview and export mailbox and SharePoint/OneDrive content returned from searches, which enables downloading the message for investigation. eDiscovery Manager also has export capabilities but includes broader case management and hold permissions. Following the principle of least privilege, Data Investigator is the more appropriate role.
$19
Get all 318 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.