SIMULATION
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
Microsoft 365 Password: **********
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You need to retain Microsoft SharePoint files that contain the word Falcon for two years from the date they were created, and then delete them.
To complete this task, sign in to the appropriate admin center.
Show Answer
Correct Answer: Microsoft Purview compliance portal
Create a retention label
Auto-apply the label to SharePoint content using a keyword condition (Falcon)
Explanation: To retain and then delete SharePoint files containing a specific word, you must use Microsoft Purview. Create a retention label set to retain items for 2 years from creation and delete afterward. Then create an auto-apply retention label policy scoped to SharePoint locations and configure the condition to apply when content contains the keyword "Falcon".
Question 62
You have a Microsoft 365 E5 subscription that contains multiple data loss prevention (DLP) policies.
You need to identify which DLP rules include conditions that can trigger the DLP policies.
Which report should you use from the Microsoft Purview compliance portal?
A. DLP policy matches
B. False positives and overrides
C. DLP incidents
D. Third-party DLP policy matches
Show Answer
Correct Answer: A
Explanation: The DLP policy matches report shows which DLP rules have matched content and triggered policy actions. It provides visibility into the specific conditions and rules responsible for activating DLP policies, making it the correct report for identifying trigger conditions.
Question 64
SIMULATION
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
Microsoft 365 Password: **********
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You need to provide users with the ability to manually classify files that contain product information that are stored in SharePoint Online sites. The solution must meet the following requirements:
• The users must be able to apply a classification of Product1 to the files.
• Any authenticated user must be able to open files classified as Product1.
• Files classified as Product1 must be encrypted.
To complete this task, sign in to the appropriate admin center.
Show Answer
Correct Answer: Create and publish a sensitivity label named Product1
Scope: Items > Files only
Enable Control access (encryption)
Assign permissions: Any authenticated users – View
Explanation: A sensitivity label allows manual classification of files in SharePoint Online. Enabling control access encrypts the files. Assigning Any authenticated users with View permission ensures all signed-in users can open the files while maintaining least privilege.
Question 65
You have a Microsoft 365 E5 subscription that uses Privacy risk management.
You need to recommend which type of policy can evaluate the external sharing of personal data on Microsoft SharePoint Online sites.
Which policy type should you recommend?
A. Data overexposure
B. Data transfers
C. Data theft by departing users
D. Data minimization
E. Security policy violations
Show Answer
Correct Answer: B
Explanation: In Microsoft Priva Privacy Risk Management, Data transfers policies are specifically designed to evaluate when personal data is shared externally from the organization, including external sharing from SharePoint Online and OneDrive (for example, sharing links with external users or moving files outside the tenant). Data overexposure focuses on excessive internal access, not external sharing.
Question 66
HOTSPOT
-
You have a Microsoft 365 E5 tenant that contains two users named User1 and User2 and a Microsoft SharePoint Online site named Site1 as shown in the following exhibit.
For Site1, the users are assigned the roles shown in the following table.
You publish a retention label named Retention1 to Site1.
To which files can the users apply Retention1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: User1:
File1.docx, File2.docx, and File3.docx
User2:
File1.docx and File2.docx only
Explanation: Site owners can apply retention labels to all files regardless of DLP status. Members can apply retention labels only to files they can edit. The DLP blocked file (File3.docx) restricts member actions, so User2 cannot label it, while DLP warnings do not prevent labeling.
Question 67
SIMULATION
-
Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and click on the username below.
To enter your password, place your cursor in the Enter password box and click on the password below.
Microsoft 365 Username:
Microsoft 365 Password: **********
If the Microsoft 365 portal does not load successfully in the browser, press CTRL-K to reload the portal in a new browser tab.
The following information is for technical support purposes only:
Lab Instance: 12345678
-
You discover that all users can apply the Confidential - Finance label.
You need to ensure that the Confidential - Finance label is available only to the members of the Finance Team group.
To complete this task, sign in to the appropriate admin center.
Show Answer
Correct Answer: Microsoft Purview compliance portal
Information protection > Label policies
Edit the policy that publishes "Confidential - Finance"
Remove All users and assign only the Finance Team group
Explanation: Sensitivity labels are made available to users through label policies in Microsoft Purview. To restrict a label to a specific group, you must edit the publishing label policy and scope it only to the Finance Team group. Assigning a sensitivity label to a Microsoft 365 group does not control which users can apply the label.
Question 68
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You need to implement a compliance solution that meets the following requirements:
• Captures clips of key security-related user activities, such as the exfiltration of sensitive company data.
• Integrates data loss prevention (DLP) capabilities with insider risk management.
What should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: Forensic evidence in Insider Risk Management captures activity clips (screen, app, file actions) for investigations. Adaptive Protection integrates DLP signals with insider risk to dynamically apply protections based on user risk level.
Question 69
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the administrators shown in the following table.
On August 1, 2023, you apply the communication compliance policies shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
Show Answer
Correct Answer: Yes
Yes
No
Explanation: Communication compliance policies scan every 24 hours from creation time.
Policy1 (11:00 AM Aug 1) has results after 11:00 AM Aug 2 → reviewable at 3:00 PM.
Policy3 (5:45 PM Aug 1) has results after 5:45 PM Aug 2 → reviewable at 9:00 PM.
Policy2 (2:30 PM Aug 1) first scans at 2:30 PM Aug 2 → not reviewable at 2:00 PM.
Question 70
You have a Microsoft 365 E3 subscription.
You plan to assess compliance with ISO/IEC 27001:2013.
From Compliance Manager, you discover that the ISO/IEC 27001:2013 regulatory template for Microsoft 365 is inactive.
What should you do?
A. Purchase a Microsoft 365 E5 subscription.
B. Add a data connector.
C. Add recommended assessments.
D. Create a trainable classifier.
Show Answer
Correct Answer: A
Explanation: The ISO/IEC 27001:2013 regulatory template in Compliance Manager is a premium regulatory template. Microsoft 365 E3 does not include premium regulatory templates, so the template remains inactive. Upgrading to Microsoft 365 E5 provides access to these regulatory templates, allowing you to assess compliance. Other options do not activate an inactive regulatory template.
Question 71
HOTSPOT -
You have a Microsoft 365 subscription that contains a sensitivity label named Contoso Confidential.
You publish Contoso Confidential to all users.
Contoso Confidential is configured as shown in the Configuration exhibit. (Click the Configuration tab.)
The Encryption settings of Contoso Confidential are configured as shown in the Encryption exhibit. (Click the Encryption tab.)
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: 1) Offline access is allowed for 7 days, so a disabled account is not immediately blocked from opening already downloaded content.
2) Permissions are granted to "Authenticated users", which includes guest (B2B) users.
3) No auto-labeling policy is configured for SharePoint Online files.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.