HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You have the data loss prevention (DLP) policies shown in the following table.
From Insider risk management, you configure a priority user group named PriGroup1 that contains User3 as a member.
You have the insider risk policies shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
Yes
Explanation: Policy1 targets Group1 and is triggered by DLP1 (High). User3 is in Group1, so an alert is generated.
Policy2 targets Group2 with DLP2 (Medium). Insider risk data leak policies only generate alerts from DLP rules configured as High severity, so no alert.
Policy3 targets priority users in PriGroup1. User3 is a priority user and DLP3 is linked to the policy, so the activity triggers an alert.
Question 42
You have a Microsoft 365 E5 tenant that has a retention label named Label1.
You need to create an auto-labeling policy that will apply Label1.
To which location can Label1 be applied?
A. Microsoft Entra security groups
B. Exchange email
C. Microsoft Defender for Cloud Apps
D. Teams channel messages
Show Answer
Correct Answer: B
Explanation: Auto-labeling policies for retention labels can apply to supported content locations such as Exchange email, SharePoint sites, and OneDrive accounts. Among the options given, only Exchange email is a valid location where an auto-labeling policy can apply a retention label. The other options (Entra security groups, Defender for Cloud Apps, and Teams channel messages) are not supported locations for retention auto-labeling.
Question 43
You have a Microsoft 365 E5 subscription. Microsoft Priva Privacy Risk Management licenses are assigned to all users.
You need to review and delete all the personal data that relates to a former employee. The solution must minimize administrative effort.
What should you do first?
A. Create a retention policy.
B. Create an eDiscovery (Standard) case.
C. Purchase a Microsoft Priva Subject Rights Requests license.
D. From Data matching, add a personal data schema for the data profile.
Show Answer
Correct Answer: C
Explanation: To efficiently review and delete all personal data for a former employee, Microsoft Priva Subject Rights Requests (SRR) is the purpose-built solution that automates data discovery, review, and deletion across Microsoft 365. Because SRR is an add-on and not included with E5 or Priva Privacy Risk Management, the first required step is to purchase the SRR license. Other options (retention policies, eDiscovery, or data matching schemas) are either not designed for this scenario or require more administrative effort.
Question 44
DRAG DROP
-
You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented.
You need to create a custom sensitive info type. The solution must meet the following requirements:
• Match product serial numbers that contain a 10-character alphanumeric string.
• Ensure that the abbreviation of SN appears within six characters of each product serial number.
• Exclude a test serial number of 1111111111 from a match.
Which pattern settings should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Primary element
Supporting elements
Additional checks
Explanation: The serial number pattern itself is defined as the Primary element (10‑character alphanumeric string). The presence of the abbreviation "SN" near the serial number is enforced using Supporting elements. The exclusion of a known test value (1111111111) is handled by Additional checks, which allow explicit exceptions.
Question 45
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
You have the retention policies shown in the following table.
You have the documents shown in the following table.
User1 moves Doc3 to Site4.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Doc1: Yes
Doc2: No
Doc3: No
Explanation: SharePoint retention uses the longest applicable retention period per location.
- Doc1 (Site1): Policies 1 (2y) and 3 (6y) apply → retained 6 years.
- Doc2 (Site2): Policies 1 (2y), 2 (4y), and 3 (6y) apply → retained 6 years, not 4.
- Doc3: Although originally in Site3, after moving to Site4 (no policies), it is not retained for 4 years → statement is false.
Question 46
You have a Microsoft 365 E5 subscription.
You need to apply data loss prevention (DLP) policies to the following:
• Microsoft Exchange Online mailboxes
• Microsoft SharePoint Online sites
• Microsoft Power BI workspaces
• Microsoft OneDrive accounts
• On-premises repositories
What is the minimum number of DLP policies required to achieve the goal?
A. 1
B. 2
C. 3
D. 4
E. 5
Show Answer
Correct Answer: B
Explanation: In Microsoft Purview DLP, Exchange Online, SharePoint Online, OneDrive for Business, and on‑premises repositories can be included together in a single DLP policy. However, when Power BI (Fabric/Power BI workspaces) is selected, all other workload locations are unavailable and require a separate policy. Therefore, one policy covers Exchange, SharePoint, OneDrive, and on‑premises data, and a second policy is required for Power BI, for a total of two policies.
Question 47
You have a Microsoft 365 E5 subscription.
You create a data loss prevention (DLP) policy and select Use Notifications to inform your users and help educate them on the proper use of sensitive info.
Which apps will show the policy tip?
A. Outlook on the web only
B. Outlook Win32 only
C. Outlook for iOS and Android only
D. Outlook on the web and Outlook Win32 only
E. Outlook Win32 and Outlook for iOS and Android only
F. Outlook on the web, Outlook Win32, and Outlook for iOS and Android
Show Answer
Correct Answer: D
Explanation: DLP policy tips are supported in Outlook on the web and Outlook for Windows (Win32). They are not supported in Outlook mobile apps for iOS and Android. Therefore, the policy tip will appear only in Outlook on the web and Outlook Win32.
Question 48
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You plan to create a custom trainable classifier by uploading 1,000 machine-generated files as seed content.
The files have sequential names and are uploaded in one-minute intervals as shown in the following table.
Which files were processed first and last when you created the custom trainable classifier? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Custom trainable classifiers process up to the 2,000 most recently created seed files based on the file creation timestamp. With 1,000 files uploaded sequentially one minute apart, processing starts with the earliest created file and ends with the most recently created file.
Question 49
You have a Microsoft 365 tenant that is opt-in for trainable classifiers.
You need to ensure that a user named User1 can create custom trainable classifiers. The solution must use the principle of least privilege.
Which role should you assign to User1?
A. Global Administrator
B. Security Operator
C. Security Administrator
D. Compliance Administrator
Show Answer
Correct Answer: D
Explanation: The tenant is already opted in for trainable classifiers, which requires a Global Administrator. After opt-in, the least-privileged role that can create and train custom trainable classifiers is Compliance Administrator. Other roles listed either lack the required permissions or grant excessive privileges.
Question 50
HOTSPOT
-
You have a Microsoft 365 subscription.
You need to use PowerShell to enable multiple segment support for information barriers (IBs).
How should you complete the PowerShell command? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Multiple segment support for Information Barriers is enabled by setting the tenant policy configuration. The correct cmdlet is Set-PolicyConfig with the parameter -InformationBarrierMode set to 'MultiSegment'.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.