HOTSPOT
-
You have a Microsoft 365 E5 subscription that uses Microsoft Purview Audit (Premium) with the 10-Year Audit Log Retention add-on license.
The subscription contains the audit retention policies shown in the following table.
From the SharePoint Online admin center, User1 performs the actions shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Action1: No
Action2: Yes
Action3: Yes
Explanation: Action1 (Archive site): No audit retention policy matches the Archive site activity, so it is not retained for one year.
Action2 (Create site collection): Multiple policies match; the higher-priority policy (RP3) applies, retaining logs for 3 years.
Action3 (Rename site): RP4 explicitly matches Rename site and retains logs for 6 months.
Question 11
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You have a file named Customer.csv that contains a list of 1,000 customer names.
You plan to use Customer.csv to classify documents stored in a Microsoft SharePoint Online library.
What should you create in the Microsoft Purview compliance portal, and which type of element should you select? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Create: A sensitive info type
Element: Keyword dictionary
Explanation: To classify documents based on a fixed list of customer names from a CSV file, create a custom Sensitive Information Type and use a keyword dictionary to store and match the names. Trainable classifiers are for pattern-based or example-driven content, not exact list matching.
Question 12
You have a Microsoft 365 E5 subscription that uses Microsoft Purview.
You create a sensitive information type (SIT) named SIT1.
You plan to create the communication compliance polices shown in the following table.
To which policies can you add SIT1 as a condition?
A. Policy1 only
B. Policy3 only
C. Policy1 and Policy2 only
D. Policy1 and Policy3 only
E. Policy1, Policy 2, and Policy3
Show Answer
Correct Answer: A
Explanation: In Communication Compliance, custom sensitive information types can only be used as conditions when the policy is based on the **Detect inappropriate text** template. Other templates (such as those using trainable classifiers or image-based detection) do not support SIT conditions. Therefore, SIT1 can be added only to Policy1.
Question 13
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You have a Privacy Risk Management policy named Policy1 based on the Data transfers template as shown in the Privacy Risk Management policy exhibit. (Select the Privacy Risk Management policy tab and scroll to review the entire policy.)
User1 sends the following email messages that contain credit card information:
• Message1: Sent to User2.
• Message2: Sent to User3.
• Message3: Sent to User4.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Message1: No
Message2: No
Message3: Yes
Explanation: The policy triggers only when the sender is in Group1 and the recipient is in Group2. User1 (sender) is in Group1. User2 and User3 do not satisfy the recipient Group2 condition as required for the policy match in this configuration, while User4 is in Group2, so only Message3 meets all conditions and triggers an alert.
Question 14
You have a Microsoft 365 subscription that contains a user named User1.
User1 plans to export a history of Microsoft Purview communication compliance policy changes.
You need to add User1 to a role group in Microsoft Purview. The solution must follow the principle of least privilege.
To which role group should you add User1?
A. Communication Compliance Investigators
B. Communication Compliance Viewers
C. Communication Compliance Analysts
D. Communication Compliance Administrators
Show Answer
Correct Answer: B
Explanation: Exporting a history of communication compliance policy changes is a read-only activity. The Communication Compliance Viewers role provides view and export access to policies, alerts, and audit history without granting investigative, analytical, or administrative permissions, satisfying least-privilege requirements.
Question 15
HOTSPOT
-
You have a Microsoft 365 E5 tenant that contains a published sensitivity label named Sensitivity1.
You plan to create a Microsoft Entra group named Group1 and assign Sensitivity1 to Group1.
How should you configure Group1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Setting:
EnableMIPLabels
Type:
Microsoft 365
Explanation: Sensitivity labels for containers (Microsoft Purview Information Protection) can only be applied to Microsoft 365 groups. Enabling the EnableMIPLabels setting allows sensitivity labels to be assigned to the group.
Question 16
HOTSPOT
-
You have a Microsoft E5 subscription that contains two users named User1 and User2.
You have a Microsoft SharePoint site named Site1. Site1 stores files that contain IP addresses as shown in the following table.
User1 is assigned the SharePoint admin role for Site1. User2 is a member of Site1.
You create the data loss prevention (DLP) policy shown in the following exhibit.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1 can view the contents of File1.txt: Yes
User2 can view the contents of File1.txt: No
User2 can view the contents of File2.docx: Yes
Explanation: The DLP policy blocks access when content contains at least two IP address instances. File1.txt has three IP addresses, so access is blocked for members. Site admins can still view blocked content. File2.docx has only one IP address, so it does not trigger the policy and remains accessible.
Question 17
HOTSPOT
-
You have a Microsoft 365 subscription.
You identify the following data loss prevention (DLP) requirements:
• Send notifications to users if they attempt to send attachments that contain an EU Social Security Number (SSN) or Equivalent ID.
• Prevent any email messages that contain credit card numbers from being sent outside your organization.
• Block the external sharing of Microsoft OneDrive content that contains EU passport numbers.
• Send administrators email alerts if any rule matches occur.
What is the minimum number of DLP policies and rules you must create to meet the requirements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Policies: 2
Rules: 3
Explanation: One policy can cover Exchange email with two separate rules: (1) notify users for EU SSN/Equivalent ID attachments and (2) block emails with credit card numbers sent externally. A second policy is required for OneDrive to block external sharing of files containing EU passport numbers. Admin alerting is configured on the existing rules and does not require an additional rule.
Question 18
You have a Microsoft 365 subscription that contains two Microsoft SharePoint Online sites named Site1 and Site2.
You plan to use policies to meet the following requirements:
• Add a watermark of Confidential to a document if the document contains the words Project1 or Project2.
• Retain a document for seven years if the document contains credit card information.
• Add a watermark of Internal Use Only to all the documents stored on Site2.
• Add a watermark of Confidential to all the documents stored on Site1.
You need to recommend the minimum number of sensitive info types required.
How many sensitive info types should you recommend?
A. 1
B. 2
C. 3
D. 4
Show Answer
Correct Answer: B
Explanation: Only two sensitive info types are needed. One custom sensitive info type can detect the keywords "Project1" or "Project2" to apply the Confidential watermark. The second is the built-in Credit Card Information sensitive info type to trigger seven-year retention. The site-wide watermark requirements for Site1 and Site2 are based on location and can be handled with default or auto-labeling policies, not sensitive info types.
Question 19
You have a Microsoft 365 E5 subscription that contains two users named User1 and User2. The subscription has a data loss prevention (DLP) policy named Policy1.
User2 sends an outbound message that generates a false positive for Policy1.
You need to ensure that User1 can download the message that generated the alert. The solution must follow the principle of least privilege.
To which role group should you add User1?
A. Data Investigator
B. Global Reader
C. eDiscovery Manager
D. Security Operator
Show Answer
Correct Answer: A
Explanation: To download the message that triggered a DLP alert, the user must be able to review and export content associated with DLP incidents. The Data Investigator role in Microsoft Purview includes permissions to investigate DLP alerts and export mailbox or site content returned from DLP-related investigations. It provides the required capability without broader case management or hold permissions, which aligns with the principle of least privilege. eDiscovery Manager has broader permissions than necessary.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.