You have a Microsoft 365 E5 subscription.
Your company has two departments named department1 and department2.
You configure an information barrier (IB) policy that prevents communication between the users in department1 and department2.
You discover that a user named User1 in department1 can still communicate with the users in department2. You validate that the policy works properly for all other users.
You need to ensure that User1 cannot communicate with the department2 users.
What should you modify?
A. the group assignments of User1
B. the user account attributes of User1
C. the IB policy
D. the IB segments
Show Answer
Correct Answer: B
Explanation: Information Barriers determine segment membership from user account attributes (such as Department, Country, etc.) synchronized to Microsoft Entra ID. If the policy works for all other users but not for a single user, the most likely cause is that the user's attributes do not place them into the expected segment. Modifying the user's account attributes so User1 is correctly included in the department1 segment will cause the existing IB policy to apply. Group assignments are not how IB segment membership is determined in the standard attribute-based configuration, and there is no indication the policy or segments themselves are incorrect since they work for everyone else.
Question 42
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You have the data loss prevention (DLP) policies shown in the following table.
From Insider risk management, you configure a priority user group named PriGroup1 that contains User3 as a member.
You have the insider risk policies shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
No
No
Explanation: Policy1 applies because User3 is in Group1 and DLP1 is High. Policy2 is triggered by a Medium-severity DLP rule, which doesn't trigger the data leaks indicator. Policy3 targets a priority user, but DLP3 is also Medium severity, so it doesn't generate the insider risk alert.
Question 43
You have a Microsoft 365 E5 tenant that has a retention label named Label1.
You need to create an auto-labeling policy that will apply Label1.
To which location can Label1 be applied?
A. Microsoft Entra security groups
B. Exchange email
C. Microsoft Defender for Cloud Apps
D. Teams channel messages
Show Answer
Correct Answer: B
Explanation: Auto-labeling policies for Microsoft Purview retention labels can apply labels to supported Exchange Online mailbox items (user and shared mailboxes), as well as SharePoint and OneDrive content. They do not target Microsoft Entra security groups, Microsoft Defender for Cloud Apps as a location, or Teams channel messages for retention label auto-labeling.
Question 44
You have a Microsoft 365 E5 subscription. Microsoft Priva Privacy Risk Management licenses are assigned to all users.
You need to review and delete all the personal data that relates to a former employee. The solution must minimize administrative effort.
What should you do first?
A. Create a retention policy.
B. Create an eDiscovery (Standard) case.
C. Purchase a Microsoft Priva Subject Rights Requests license.
D. From Data matching, add a personal data schema for the data profile.
Show Answer
Correct Answer: C
Explanation: To review and delete all personal data related to an individual across Microsoft 365 with minimal administrative effort, the appropriate capability is Microsoft Priva Subject Rights Requests (SRR). SRR is designed to locate, review, export, and delete personal data associated with a data subject. Because the scenario states only Priva Privacy Risk Management licenses are assigned, the required first step is to obtain the separate Subject Rights Requests add-on license. Retention policies and eDiscovery (Standard) are not purpose-built for fulfilling privacy data deletion requests, and creating a personal data schema is only needed for custom data matching scenarios, not as the first step here.
Question 45
DRAG DROP
-
You have a Microsoft 365 E5 subscription that has data loss prevention (DLP) implemented.
You need to create a custom sensitive info type. The solution must meet the following requirements:
• Match product serial numbers that contain a 10-character alphanumeric string.
• Ensure that the abbreviation of SN appears within six characters of each product serial number.
• Exclude a test serial number of 1111111111 from a match.
Which pattern settings should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Match product serial numbers that contain a 10-character alphanumeric string: Primary element
Ensure that the abbreviation of SN appears within six characters of each product serial number: Character proximity
Exclude a test serial number of 1111111111 from a match: Additional checks
Explanation: The primary element defines the main regex/pattern to detect. Character proximity enforces the maximum distance between the primary match and a supporting term such as 'SN'. Additional checks allow exclusions, such as ignoring a known test serial number.
Question 46
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains four Microsoft SharePoint Online sites named Site1, Site2, Site3, and Site4.
You have the retention policies shown in the following table.
You have the documents shown in the following table.
User1 moves Doc3 to Site4.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: When multiple retention policies apply to the same content, the longest retention period takes precedence. After Doc3 is moved to Site4 (which has no listed retention policy), it no longer matches the Site3 location policy for future location-based application.
Question 47
You have a Microsoft 365 E5 subscription.
You need to apply data loss prevention (DLP) policies to the following:
• Microsoft Exchange Online mailboxes
• Microsoft SharePoint Online sites
• Microsoft Power BI workspaces
• Microsoft OneDrive accounts
• On-premises repositories
What is the minimum number of DLP policies required to achieve the goal?
A. 1
B. 2
C. 3
D. 4
E. 5
Show Answer
Correct Answer: B
Explanation: The minimum is two DLP policies. One policy can target Exchange Online, SharePoint Online, OneDrive accounts, and on-premises repositories together. Power BI workspaces must be configured in a separate DLP policy because selecting the Power BI/Fabric location cannot be combined with the other workload locations in the same policy.
Question 48
You have a Microsoft 365 E5 subscription.
You create a data loss prevention (DLP) policy and select Use Notifications to inform your users and help educate them on the proper use of sensitive info.
Which apps will show the policy tip?
A. Outlook on the web only
B. Outlook Win32 only
C. Outlook for iOS and Android only
D. Outlook on the web and Outlook Win32 only
E. Outlook Win32 and Outlook for iOS and Android only
F. Outlook on the web, Outlook Win32, and Outlook for iOS and Android
Show Answer
Correct Answer: D
Explanation: DLP policy tips (user notifications) are supported in Outlook on the web and Outlook for Windows (Win32), but not in Outlook for iOS or Android. Therefore, the policy tip will appear in Outlook on the web and Outlook Win32 only.
Question 49
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You plan to create a custom trainable classifier by uploading 1,000 machine-generated files as seed content.
The files have sequential names and are uploaded in one-minute intervals as shown in the following table.
Which files were processed first and last when you created the custom trainable classifier? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: For custom trainable classifiers, positive seed content is limited to the first 500 uploaded samples, processed in upload/creation time order. Thus processing starts with the earliest file and ends with the 500th file.
Question 50
You have a Microsoft 365 tenant that is opt-in for trainable classifiers.
You need to ensure that a user named User1 can create custom trainable classifiers. The solution must use the principle of least privilege.
Which role should you assign to User1?
A. Global Administrator
B. Security Operator
C. Security Administrator
D. Compliance Administrator
Show Answer
Correct Answer: D
Explanation: Because the tenant has already been opted in for trainable classifiers, the Global Administrator action has already been completed. Creating and training custom trainable classifiers requires the Compliance Administrator role. Applying the principle of least privilege, Compliance Administrator is sufficient, whereas Global Administrator grants unnecessary permissions. Security Administrator and Security Operator do not have the required compliance permissions.
$19
Get all 318 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.