HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the data loss prevention (DLP) policies shown in the following table.
You have a custom employee information form named Templatel.docx.
You plan to create a sensitive info type named Sensitive1 that will use the document fingerprint from Template1.docx.
What should you use to create Sensitive1, and in which DLP policies can you use Sensitive1? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: The Microsoft Purview compliance portal
DLP1, DLP2, and DLP3
Explanation: Document fingerprint–based sensitive information types are created in the Microsoft Purview compliance portal. Once created, they can be used in DLP policies for Exchange Online email, SharePoint Online sites, and Microsoft Teams chats and channel messages.
Question 73
HOTSPOT
-
You have a Microsoft 365 subscription that has Enable Security defaults set to No in Azure AD.
You have a custom compliance manager template named Regulation1.
You have the assessments shown in the following table.
Assessment1 has the improvement actions shown in the following table.
Assessment2 has the improvement actions shown in the following table.
You perform the following actions:
• For Assessment2, change the Test status of Establish a threat intelligence program to Implemented.
• Enable multi-factor authentication (MFA) for all users.
• Configure a privileged access policy.
For each of the following statements, select Yes if the statement is true. Otherwise select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: 1) Establishing a threat intelligence program is an operational (non-technical) action and was marked Implemented only in Assessment2, so it won’t appear as Implemented in Assessment1.
2) Assessment1 gains points only from enabling MFA for admins and non-admins: 27 + 27 = 54.
3) In Assessment2, only the technical action (configure a privileged access policy, +15) is automatically tested; the operational action (+9) doesn’t add points yet, so the increase is not 78.
Question 74
DRAG DROP
-
You have a Microsoft 365 E5 subscription and use Microsoft Purview.
The subscription contains the following users:
• User1: Must be able to investigate policy matches, but unable to view the file content related to the match.
• User2: Must be able to investigate policy matches and view the file content related to the match.
• User3: Must be able to create, update, and delete Microsoft Priva Privacy Risk Management policies.
You need to add each user to a role group. The solution must follow the principle of least privilege.
To which role group should you add each user? To answer, drag the appropriate role groups to the correct users. Each group may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Explanation: Analysts can investigate policy matches without viewing file content. Investigators can investigate matches and view related file content. Administrators have full permissions, including creating, updating, and deleting Microsoft Priva Privacy Risk Management policies.
Question 75
HOTSPOT
-
You have a Microsoft 365 E5 tenant that contains the objects shown in the following table.
You need to restore a Microsoft Word document that was deleted from the Sales channel by User1.
From where can the document be restored, and how long will the document be retained? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Microsoft SharePoint Online
93 days
Explanation: Files shared in a Microsoft Teams channel are stored in the connected SharePoint Online site (Documents library for the channel). Deleted files can be restored from the SharePoint recycle bin, where they are retained for up to 93 days.
Question 76
You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Project1.
You need to recommend a record management solution that meets the following requirements:
• Retains files in Project1 for a minimum of 10 years
• Once Project1 is complete, retains files for an additional five years before the files are deleted
Which two components should you include in the recommendation? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. a data loss prevention (DLP) policy
B. an adaptive scope
C. an event type
D. a file plan
E. a sensitivity label
Show Answer
Correct Answer: C, D
Explanation: The requirement to retain content for a set period and then start an additional retention period once the project is completed requires event-based retention, which is provided by an event type. A file plan is needed to define and manage retention labels that specify the 10-year retention and the additional five-year retention before deletion. DLP policies, adaptive scopes, and sensitivity labels do not control record retention lifecycles in this way.
Question 77
You create a label that encrypts email data.
Users report that they cannot use the label in Outlook on the web to protection the email messages they send.
You need to ensure that the users can use the new label to protect their email.
What should you do?
A. Create a label policy.
B. Create a new sensitive information type.
C. Modify the priority order of label policies.
D. Wait six hours and ask the users to try again.
Show Answer
Correct Answer: A
Explanation: Sensitivity labels are not available to users until they are published through a label policy. Creating and assigning a label policy makes the new encryption label visible and usable in Outlook on the web and other apps.
Question 79
HOTSPOT
-
You have a Microsoft 365 E5 subscription.
You are evaluating Data Protection Baseline compliance by using Compliance Manager.
You need to identify improvement actions that meet the following requirements:
• Provide data loss prevention (DLP) policy recommendations.
• Provide Data Protection Baseline recommendations.
Which filter should you use for each requirement? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Explanation: In Compliance Manager, DLP guidance is surfaced under Solutions, while Data Protection Baseline guidance aligns to regulatory frameworks and is filtered under Regulations.
Question 80
HOTSPOT
-
You have a Microsoft 365 E5 subscription that contains the groups shown in the following table.
The subscription contains the users shown in the following table.
You create the mail flow rules shown in the following table.
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: No
Yes
No
Explanation: Rule2 triggers only when the sender address is [email protected], not when the sender is merely a member of Dist1. Rule1 encrypts messages only when the recipient is a member of Group1. User3 is not in Group1, User1 is in Group1, and sending to the Group1 address itself does not encrypt delivery to members.
Question 81
HOTSPOT
-
You have a Microsoft 365 E5 subscription that uses Microsoft Exchange Online and Teams.
You need to ensure that when a user sends a message containing a cloud attachment, a retention label is applied to the cloud attachment by using auto-labeling policy.
How should you configure the retention label to start the retention period, and to which locations should you apply the auto-labeling policy? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Show Answer
Correct Answer: Start the retention period based on when the items were:
Labeled
Locations:
Microsoft 365 Group mailboxes & sites, OneDrive accounts, and SharePoint classic and communication sites only
Explanation: Auto-labeling applies the retention label when content matches conditions, so the retention period should start when the item is labeled. Cloud attachments in Teams are stored in SharePoint team sites (channel files) and OneDrive (chat files), so the policy must target SharePoint and OneDrive locations associated with Microsoft 365 Groups.
Question 82
You plan to implement inside 365 E5 subscription.
You plan to implement insider risk management for users that manage sensitive data associated with a project.
You need to create a protection policy for the users. The solution must meet the following requirements:
• Minimize the impact on users who are NOT part of the project.
• Minimize administrative effort.
What should you do first?
A. From the Microsoft Entra admin center, create a security group.
B. From the Microsoft Purview compliance portal, create an insider risk management policy.
C. From the Microsoft Purview compliance portal, create a priority user group.
D. From the Microsoft Entra admin center, create a risky users policy.
Show Answer
Correct Answer: C
Explanation: To protect only users involved in a sensitive project while minimizing impact on others and reducing admin effort, you should first define a Priority user group in Insider Risk Management. Priority user groups are specifically designed to scope insider risk policies to targeted users (such as project teams handling sensitive data). Creating this group first allows subsequent insider risk policies to be applied narrowly without affecting unrelated users, and avoids managing multiple broad policies or exclusions.
$19
Get all 316 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.