Courseiva

CCNA Manage compliance by using Microsoft Purview Questions

47 questions · Manage compliance by using Microsoft Purview · All types, answers revealed

1
MCQeasy

A compliance officer needs to ensure that all documents in a SharePoint Online library are automatically labeled with a 'Confidential' sensitivity label if they contain at least one of a predefined list of sensitive information types such as credit card numbers or social security numbers. Users should be able to override the label with a business justification. Which Microsoft Purview feature should the officer configure?

A.Auto-labeling policy for SharePoint Online
B.Data Loss Prevention (DLP) policy
C.Retention label policy
D.Sensitivity label with manual classification
AnswerA

Auto-labeling policies in the Microsoft Purview compliance portal let you define conditions—such as sensitive info types, trainable classifiers, or custom keywords—that trigger automatic application of a sensitivity label to matching SharePoint Online documents. Once created, the policy runs continuously, and in enforcement mode it labels every existing and new file that meets the criteria, providing a scalable, centralized solution. You can also require users to justify lowering or removing the label, balancing automation with user oversight. This directly satisfies the need to ensure all relevant documents are classified automatically.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on the detection of sensitive information types (e.g., credit card numbers, SSNs). This policy supports user override with a business justification, meeting the compliance officer's requirement exactly. Manual classification (Option D) would not automate the labeling, and DLP policies (Option B) focus on preventing data loss, not applying sensitivity labels.

Exam trap

Microsoft often tests the distinction between auto-labeling policies (which apply sensitivity labels automatically) and DLP policies (which enforce actions like blocking or alerting), causing candidates to confuse the two because both can detect sensitive information types.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are designed to detect and block the sharing of sensitive data, not to automatically apply sensitivity labels to documents; they can trigger alerts or block actions but do not label content. Option C is wrong because retention label policies manage how long content is kept or deleted, not sensitivity classification; they are unrelated to labeling based on sensitive information types. Option D is wrong because a sensitivity label with manual classification requires users to manually apply the label, which does not satisfy the requirement for automatic labeling based on content detection.

2
Multi-Selecthard

Which THREE components are required to implement Microsoft Purview Data Lifecycle Management for Microsoft 365? (Choose three.)

Select 3 answers
A.Retention labels
B.Retention policies
C.Sensitivity labels
D.Data loss prevention policies
E.File plan
AnswersA, B, E

Retention labels are a required component because they apply retention and disposal rules to individual items, such as a single email or document, enabling granular control over the content lifecycle. Unlike policies that target entire locations, labels can be manually assigned by users or automatically applied based on conditions, and they are essential for record management and item-level compliance.

Why this answer

Options A, B, and E are correct because retention labels, retention policies, and a file plan are core components for Data Lifecycle Management. Option C is incorrect because sensitivity labels are part of Information Protection, not Data Lifecycle Management. Option D is incorrect because DLP is a separate solution.

3
MCQeasy

A compliance officer needs to prevent users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label
C.retention label
D.An information barrier policy
AnswerA

A Data Loss Prevention (DLP) policy in Microsoft Purview can inspect outbound email messages in real time for sensitive information types (e.g., credit card numbers, PII) and apply actions such as blocking delivery, redirecting the message, or allowing override with justification. While composing, the policy can display a policy tip to the user, providing immediate feedback that sharing such content is prohibited, which directly enforces the compliance officer's requirement to prevent email sharing.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information, such as credit card numbers, in transit (e.g., email) and enforce actions like blocking the message and displaying a policy tip to the user. DLP policies use sensitive information types (e.g., Credit Card Number) and rules to inspect content in Exchange Online, SharePoint, OneDrive, and Teams, allowing real-time blocking with user notification. This directly meets the compliance officer's requirement to prevent external sharing and provide immediate feedback.

Exam trap

Microsoft often tests the distinction between DLP policies and sensitivity labels, where candidates mistakenly think a sensitivity label alone can block email transmission, but labels require a DLP policy to enforce actions like blocking, while DLP policies can work independently of labels.

How to eliminate wrong answers

Option B (sensitivity label) is wrong because sensitivity labels classify and protect data at rest (e.g., encryption, visual markings) but do not natively block email transmission based on content inspection or provide policy tips in real-time; they require additional DLP policies to enforce actions on labeled content. Option C (retention label) is wrong because retention labels manage data lifecycle (retention and deletion) and have no capability to inspect email content for sensitive data or block messages. Option D (information barrier policy) is wrong because information barriers restrict communication between specific user groups (e.g., to prevent conflicts of interest) and do not scan for sensitive data like credit card numbers or block external sharing.

4
MCQmedium

A compliance officer needs to ensure that all documents in a Microsoft Teams channel are automatically retained for 3 years after creation and then permanently deleted. The retention policy should apply only to the specific channel, not the entire team. Which approach should the officer use?

A.Create a retention policy in Microsoft Purview and select the location 'Teams channel messages', then specify the channel name
B.Create a retention policy in Microsoft Purview and select the location 'Teams chats' for the entire team
C.Publish a retention label to the channel and configure auto-application rules based on creation date
D.Use Exchange Online PowerShell to create a retention policy for the channel mailbox
AnswerC

Correct. A retention label with auto-application rules can be published to the channel's SharePoint site, scoped to specific document libraries or folders, and configured to retain for 3 years then delete. This meets the requirement.

Why this answer

Documents in a Teams channel are stored in SharePoint. To automatically retain and then delete documents, you need a retention label with auto-application rules scoped to the channel's SharePoint site. This ensures documents are retained for 3 years from creation and then permanently deleted, without affecting other content.

Exam trap

The trap is that candidates may think 'Teams channel messages' covers documents, but it only covers chat messages. Documents in Teams channels are stored in SharePoint and require different retention settings, such as retention labels with auto-application rules scoped to the channel.

How to eliminate wrong answers

Option B is wrong because selecting 'Teams chats' applies the policy to 1:1 and group chats, not to channel messages; it also cannot be scoped to a single channel. Option C is wrong because retention labels are designed for user-applied or auto-classification scenarios, not for automatic retention and deletion of all channel messages based solely on creation date; they require manual application or complex auto-application rules that do not guarantee coverage of all existing and future messages. Option D is wrong because Exchange Online PowerShell can manage mailbox-level retention policies, but Teams channel messages are stored in a dedicated group mailbox and cannot be targeted to a specific channel using Exchange retention policies; the correct method is through Purview's Teams channel messages location.

5
Multi-Selecteasy

Which TWO Microsoft Purview solutions are primarily used for data classification?

Select 2 answers
A.Data Loss Prevention
B.Auto-labeling
C.Communication Compliance
D.Data Lifecycle Management
E.Sensitivity labels
AnswersB, E

Auto-labeling is a primary Purview solution used to classify data by automatically applying sensitivity labels to content. It evaluates files, emails, and other content against sensitive info types, patterns, and conditions, then assigns the appropriate label without manual intervention. This enables consistent, bulk classification across hybrid environments, and it can run in client-side or service-side (server-side) modes to label content before or after it is stored.

Why this answer

Auto-labeling applies labels based on sensitive info types. Sensitivity labels are the classification labels themselves. DLP is for protection.

Data Lifecycle Management is for retention. Communication Compliance is for monitoring.

6
MCQmedium

A compliance officer needs to automatically retain emails that contain personally identifiable information (PII) for 10 years and then permanently delete them. Which Microsoft Purview feature should be configured?

A.Auto-apply retention labels based on sensitive information types
B.Data Lifecycle Management retention policy
C.Data classification
D.eDiscovery
AnswerA

Auto-apply retention labels are content-aware and can be configured to trigger whenever a sensitive information type—such as a credit card number, passport number, or other PII—is detected in an email. Once the label is applied, its retention settings enforce the 10-year retention period and, at the end of that period, automatically dispose of the item. This satisfies the requirement to selectively retain emails based on content, not just location or folder.

Why this answer

Auto-apply retention labels based on sensitive information types allow you to automatically classify and retain emails containing PII for a specified period (10 years) and then permanently delete them. This feature uses sensitive information types (e.g., Social Security Number, Credit Card Number) to detect PII and applies a retention label that enforces the retention and deletion actions at the item level, which is required for targeted compliance scenarios.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management retention policies (which apply broadly to all content in a location) with auto-apply retention labels (which apply only to content matching specific sensitive information types), leading them to incorrectly select option B.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policy applies to all content in a location (e.g., entire mailbox or site) and cannot automatically target only emails containing specific sensitive information like PII; it lacks the auto-classification capability based on content inspection. Option C is wrong because Data classification is a discovery and labeling tool that identifies and categorizes data but does not itself enforce retention or deletion actions; it requires a retention label or policy to act on the classification. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for automated retention and deletion based on content type.

7
MCQmedium

A compliance officer needs to prevent users from sending emails that contain credit card numbers to external recipients. When a user attempts to send such an email, the action should be blocked and a policy tip should be displayed in Outlook telling them why the email was blocked. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP) policy
B.Retention label policy
C.Microsoft Purview Information Protection sensitivity label
D.Compliance Manager
AnswerA

DLP policies can identify, monitor, and protect sensitive data across Exchange Online, SharePoint, and OneDrive. They support policy tips and blocking actions.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to detect and block sensitive information, such as credit card numbers, from being sent to external recipients. When configured with a 'Block' action and a policy tip, it prevents the email from being sent and displays a customizable notification in Outlook explaining the reason. This directly meets the compliance officer's requirement to block the email and show a policy tip.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking based on content inspection), leading them to choose Option C because they think labeling alone can block emails.

How to eliminate wrong answers

Option B is wrong because a Retention label policy is used to retain or delete data based on compliance requirements, not to block the transmission of sensitive content in emails. Option C is wrong because a Microsoft Purview Information Protection sensitivity label applies classification and protection (e.g., encryption) to content, but it does not natively block outbound emails containing credit card numbers or display policy tips in Outlook. Option D is wrong because Compliance Manager is a risk assessment and compliance management tool that provides recommendations and tracks compliance posture, not a policy that enforces real-time blocking of sensitive data in email.

8
MCQeasy

A compliance officer needs to block users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy.
B.Sensitivity label with encryption.
C.Microsoft Defender for Office 365 Safe Attachments policy.
D.Communication compliance policy.
AnswerA

DLP policies can detect credit card numbers in Exchange Online emails and block them with user notifications via policy tips.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information types (e.g., credit card numbers via predefined rule patterns matching the Luhn algorithm) in transit and enforce actions such as blocking the email and displaying a policy tip to the sender. This meets the compliance officer's requirement to block external sharing of credit card data immediately with user notification.

Exam trap

The trap here is that candidates often confuse the real-time blocking and notification capability of DLP with sensitivity labels (which only apply protection after classification) or communication compliance (which is a review-based solution, not a real-time enforcement mechanism).

How to eliminate wrong answers

Option B is wrong because a sensitivity label with encryption can protect content by restricting access or applying encryption, but it does not actively scan outbound email content for credit card numbers or block messages in transit with a policy tip. Option C is wrong because Microsoft Defender for Office 365 Safe Attachments policy focuses on scanning email attachments for malware and malicious content, not on detecting sensitive data patterns like credit card numbers. Option D is wrong because a communication compliance policy is designed to monitor and review internal/external communications for policy violations (e.g., harassment, insider trading) and typically requires manual review, not real-time blocking with a policy tip based on sensitive data patterns.

9
MCQmedium

A compliance officer needs to discover and review documents in SharePoint Online that contain driver's license numbers, but the officer does not want to apply any protection actions automatically. Which Microsoft Purview solution should be used?

A.Data Lifecycle Management
B.Records Management
C.Data Classification
D.Information Protection
AnswerC

Data Classification includes Content Explorer, which enables browsing and reviewing items containing sensitive info without applying protection.

Why this answer

Data Classification in Microsoft Purview allows you to identify and label sensitive content, such as driver's license numbers, across SharePoint Online without automatically applying protection actions like encryption or access restrictions. This solution is ideal for discovery and review scenarios where the compliance officer needs to locate sensitive data but does not want to enforce automated policies.

Exam trap

Microsoft often tests the distinction between discovery-only solutions (Data Classification) and enforcement solutions (Information Protection), so the trap here is assuming that any sensitive data solution must automatically apply protection, leading candidates to choose Information Protection instead of Data Classification.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management focuses on retaining or deleting content based on age or compliance requirements, not on discovering or reviewing specific sensitive data types. Option B is wrong because Records Management is designed to mark content as records for legal or regulatory retention, not for scanning or classifying content for sensitive information like driver's license numbers. Option D is wrong because Information Protection applies automatic protection actions (e.g., encryption, access restrictions) via sensitivity labels, which the compliance officer explicitly does not want to apply.

10
MCQmedium

Your organization uses Microsoft Purview Information Protection. You need to ensure that when users manually apply a 'Confidential' label to a document in Word, the document is automatically marked with a footer 'CONFIDENTIAL' and encrypted. What must you configure?

A.Modify the sensitivity label policy to include the footer.
B.Create a DLP rule that applies the footer and encryption.
C.Set up auto-labeling to apply the footer and encryption.
D.Configure the sensitivity label's settings to include the footer and encryption.
AnswerD

Sensitivity labels can define markings and encryption.

Why this answer

D is correct because sensitivity labels include built-in settings for markings (like footers) and encryption, which are configured within the label's properties. Option A is incorrect because the sensitivity label policy determines which labels are published to users, but the actual marking and encryption settings are defined in the label itself, not in the policy. Option B is incorrect because DLP rules apply to data loss prevention scenarios, not to sensitivity label application; they cannot be used to apply footers or encryption when a user manually applies a label.

Option C is incorrect because auto-labeling is used for automatically applying labels based on conditions, not for manual labeling scenarios.

11
MCQhard

A compliance officer needs to ensure that all emails containing sensitive information (e.g., passport numbers) are automatically encrypted when sent to external recipients. The encryption should be enforced without requiring users to manually select an option. Which Microsoft Purview feature should they configure?

A.Data Loss Prevention (DLP) policy with encryption action
B.Sensitivity labels with auto-labeling
C.Message Encryption (OME) policies
D.Communication Compliance
AnswerA

Data Loss Prevention (DLP) policies in Microsoft Purview can directly apply an encryption action to outgoing email by leveraging Azure Rights Management. When a DLP policy detects a sensitive information type (e.g., credit card numbers or personally identifiable information) in the message body or attachments, it automatically wraps the message with the 'Encrypt' action, enforcing transport-level protection without user intervention. This policy-based approach is purpose-built for compliance scenarios where data exfiltration must be prevented at the email boundary.

Why this answer

A Data Loss Prevention (DLP) policy with encryption action is correct because it automatically detects sensitive information (e.g., passport numbers) using sensitive info types and enforces encryption via Microsoft Purview Message Encryption (OME) as a rule action. This ensures that when an email containing such data is sent to an external recipient, the email is automatically encrypted without requiring user intervention, meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse sensitivity labels with auto-labeling as the solution for automatic encryption, but auto-labeling only applies labels based on conditions and does not enforce encryption unless the label itself is configured for encryption and the DLP policy triggers the action.

How to eliminate wrong answers

Option B is wrong because sensitivity labels with auto-labeling can classify and protect content but do not directly enforce encryption on outbound emails based on content detection; they require a DLP policy to trigger the encryption action. Option C is wrong because Message Encryption (OME) policies define encryption rules but are typically configured within DLP policies or mail flow rules; standalone OME policies do not automatically detect sensitive data and enforce encryption without additional conditions. Option D is wrong because Communication Compliance is designed to detect and investigate policy violations (e.g., harassment, insider trading) and does not provide automatic encryption of emails based on sensitive content.

12
MCQmedium

A compliance officer needs to prevent users from sharing protected health information (PHI) with external users in Microsoft Teams chat messages. When a user attempts to send a message containing a known PHI data type (e.g., medical record numbers), the message should be blocked and the sender should see a policy tip. Which Microsoft Purview solution should the officer configure?

A.Communication compliance policy
B.Data Loss Prevention (DLP) policy for Teams
C.Sensitivity labels applied to Teams
D.Information barriers
AnswerB

A Data Loss Prevention (DLP) policy for Teams can enforce real-time protection on chat and channel messages by scanning content for sensitive information types, including protected health information (PHI). When a match is detected, the policy blocks the message and shows the sender a policy tip, with options to allow override based on policy configuration. This directly prevents users from sharing PHI, making it the appropriate solution.

Why this answer

A Data Loss Prevention (DLP) policy for Microsoft Teams can be configured to detect and block sensitive information types, such as medical record numbers (a PHI data type), in chat messages. When a match occurs, the policy can block the message and display a policy tip to the sender, meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse Communication compliance (which reviews sent messages) with DLP (which blocks messages in transit), leading them to select Option A despite the requirement for real-time blocking and policy tips.

How to eliminate wrong answers

Option A is wrong because Communication compliance policies are designed to detect and review inappropriate or policy-violating communications (e.g., harassment, insider trading) after they are sent, not to block messages in real-time or enforce data loss prevention rules. Option C is wrong because sensitivity labels applied to Teams control access and protection (e.g., encryption, visual markings) at the container or file level, not the content of individual chat messages. Option D is wrong because Information barriers are used to prevent specific groups of users from communicating with each other (e.g., to avoid conflicts of interest), not to scan message content for sensitive data types like PHI.

13
MCQeasy

A compliance officer needs to automatically detect documents in SharePoint Online that contain a custom pattern (e.g., employee ID in the format EMP-12345). The pattern will be used to apply a sensitivity label. Which Microsoft Purview feature should the officer use to define the pattern?

A.Sensitive information types
B.Data Loss Prevention (DLP) policies
C.Content search
D.Data classification reports
AnswerA

Sensitive information types define the detection logic itself, using built-in or custom regex patterns, keywords, and confidence thresholds to identify data like employee IDs. After you define a custom sensitive information type, it becomes a reusable condition that purge policies, auto-labeling, and DLP rules rely on. This is the correct answer because the compliance officer's requirement to 'automatically detect' a specific pattern starts with creating that type, not with a policy that merely consumes it.

Why this answer

Sensitive information types (SITs) in Microsoft Purview are specifically designed to define custom patterns, such as regular expressions for employee IDs like EMP-12345. Once defined, these SITs can be used in sensitivity labels to automatically classify and protect documents in SharePoint Online. This is the correct feature because it directly supports pattern-based detection for labeling.

Exam trap

The trap here is that candidates often confuse DLP policies with pattern definition, but DLP policies only consume pre-defined sensitive information types and cannot create them.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies enforce rules to prevent data exfiltration but do not define the pattern itself; they use existing sensitive information types. Option C is wrong because Content Search is a query tool for finding content based on keywords or metadata, not for defining reusable patterns for automatic labeling. Option D is wrong because Data classification reports provide visibility into classified data but do not allow creation of custom patterns.

14
MCQmedium

A compliance administrator needs to ensure that all documents in a SharePoint library are retained for exactly 7 years and then allow users to manually dispose of them sooner after a review. What should they configure in Microsoft Purview?

A.Create a retention label with a retention period of 7 years and enable disposition review
B.Create a retention label with a retention period of 7 years and no additional action
C.Create a sensitivity label that restricts access
D.Create a record label
AnswerA

A retention label with a 7-year period and disposition review is the correct choice because it retains the document for the full regulatory period, yet the disposition review step triggers a manual approval workflow at the end of the retention period. During that review, an authorized user can approve early disposal, satisfying the requirement that documents be manually dispose-able if approved, rather than being automatically deleted or locked indefinitely.

Why this answer

The requirement specifies a fixed 7-year retention period followed by user-initiated disposal after a review. A retention label with a retention period of 7 years and disposition review enabled allows content to be retained for exactly 7 years, after which a disposition review triggers a manual approval process for disposal. This matches the need for both mandatory retention and manual disposal after review.

Exam trap

The trap here is that candidates often confuse retention labels with record labels, assuming that any label with a retention period automatically supports manual disposal, but only retention labels with disposition review enabled provide the specific workflow for user-initiated disposal after review.

How to eliminate wrong answers

Option B is wrong because a retention label with no additional action will automatically delete the content after 7 years without any user review or manual disposal option, which violates the requirement to allow users to manually dispose of items sooner after a review. Option C is wrong because a sensitivity label is designed to classify and protect data through encryption or access restrictions, not to enforce retention or disposition workflows; it does not provide any retention period or disposal review capability. Option D is wrong because a record label marks content as a record (immutable) and typically prevents deletion or modification, which contradicts the requirement to allow manual disposal after review; records require a disposition review but are not designed for flexible user-initiated disposal.

15
Multi-Selectmedium

You are the Microsoft 365 Administrator for a multinational organization that must comply with various regulatory requirements, including GDPR, SOX, and internal data retention policies. You are deploying Microsoft Purview compliance solutions. Which four of the following actions are valid steps when managing compliance using Microsoft Purview? (Choose all that apply. There are four correct answers.)

Select 4 answers
.Create a DLP policy that prevents users from sharing credit card numbers via email with external recipients.
.Use a retention label to automatically delete documents containing trade secrets after 7 years.
.Configure a sensitivity label with sublabels that apply different markings (e.g., 'Confidential' and 'Highly Confidential') to the same document.
.Enable auditing in the Microsoft 365 compliance portal to track user activities such as file downloads and mailbox access.
.Assign a retention policy to a user's mailbox that deletes all emails immediately after they are sent.
.Apply a sensitivity label to a SharePoint site that blocks all external sharing of documents stored in that site.

Why this answer

Creating a DLP policy that prevents sharing credit card numbers via email with external recipients is a valid step because Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive information types (e.g., credit card numbers) and enforce actions such as blocking external sharing. This directly supports compliance with regulations like GDPR and SOX by preventing unauthorized data exfiltration.

Exam trap

Microsoft often tests the misconception that sensitivity labels can directly control external sharing of documents within a site, when in reality they control site-level settings (e.g., privacy) while external sharing is governed by SharePoint sharing policies.

16
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 7 years, and after that automatically delete them. During the retention period, users must not be able to edit or delete the documents. Which solution should they use?

A.Create a retention policy scoped to the site with 'Retain as records' action
B.Create a retention label with 'Retain as regulatory records' and publish it to the site, then use auto-apply based on site location
C.Create a sensitivity label with 'Retain as records' and apply it manually
D.Create a litigation hold for the site
AnswerB

A regulatory records label is the only way to make content both uneditable and undeletable; publishing the label to the site makes it available, and an auto-apply policy scoped by site location automatically assigns it to every document, eliminating reliance on manual user action. Once applied, the label blocks editing and deletion by users and even administrators, and the retention period cannot be shortened. This fully satisfies the compliance requirement for retaining all documents with record integrity.

Why this answer

A retention label with 'Retain as regulatory records' locks the document against editing or deletion during the retention period, and auto-applying the label based on site location ensures all documents in the Finance site inherit the 7-year retention and automatic deletion. This meets the compliance officer's requirement for immutable retention and automatic disposal without manual user intervention.

Exam trap

The trap here is confusing 'Retain as records' (which only prevents deletion after the retention period) with 'Retain as regulatory records' (which prevents editing and deletion during the entire retention period), leading candidates to incorrectly choose Option A.

How to eliminate wrong answers

Option A is wrong because a retention policy with 'Retain as records' action does not prevent users from editing or deleting documents during the retention period; it only prevents deletion after the retention period ends. Option C is wrong because a sensitivity label with 'Retain as records' is not a valid construct; sensitivity labels manage sensitivity and protection, not retention, and manual application does not guarantee all documents are covered. Option D is wrong because a litigation hold preserves documents indefinitely (until the hold is released) and does not enforce a specific 7-year retention period or automatic deletion; it also does not prevent editing, only deletion.

17
Multi-Selectmedium

A global administrator at Fabrikam Inc. plans to implement Microsoft Purview to manage compliance for sensitive information. The solution must include the ability to discover, classify, and protect sensitive data across Microsoft 365 services. Which three of the following should the administrator configure? (Choose three.)

Select 3 answers
.Create a sensitive information type to detect custom data patterns, such as employee IDs.
.Enable auto-labeling policies in Microsoft Purview to automatically apply sensitivity labels to documents containing trade secrets.
.Configure a trainable classifier to identify and label content that matches specific organizational patterns, such as legal contracts.
.Set up a data loss prevention (DLP) policy to block external sharing of files labeled as 'Highly Confidential'.
.Deploy Microsoft Purview eDiscovery to automatically classify all content in Microsoft Teams chats.
.Enable Microsoft Purview Insider Risk Management to scan and label all historical email data.

Why this answer

Creating a sensitive information type is correct because it allows the administrator to define custom patterns (e.g., employee IDs) that Microsoft Purview can use to discover and classify sensitive data across Microsoft 365 services. This is a foundational step for building compliance policies tailored to the organization's specific data.

Exam trap

The trap here is that candidates often confuse the roles of DLP, eDiscovery, and Insider Risk Management as classification tools, when in fact they are enforcement, search, and risk detection tools respectively, not designed for automatic discovery and labeling of sensitive data.

18
MCQhard

A compliance officer needs to preserve all communications (email and Teams messages) for employees in the legal department for a minimum of 7 years. Additionally, any deletion (by users or system) must be blocked, and after the retention period, the items must be disposed of automatically. The solution must also ensure that the communications are marked as 'records' to prevent tampering. Which Microsoft Purview solution should the officer configure?

A.Litigation hold on the legal department's mailboxes and Teams
B.retention label configured with 'Mark items as a record' and a retention period of 7 years, then delete automatically
C.Preservation hold library in SharePoint Online
D.Data Loss Prevention (DLP) policy with retention action
AnswerB

A retention label configured with 'Mark items as a record' makes content immutable: after application, users and administrators cannot edit or delete the item until the retention period expires. Setting the retention period to 7 years and selecting 'delete automatically' ensures the communication is preserved for the full regulatory period and then automatically purged. This is the only option that combines record immutability, a fixed 7-year timeframe, and automatic deletion, which matches the compliance officer's exact requirement.

Why this answer

A retention label with 'Mark items as a record' enforces immutability (prevents tampering) and, when configured with a 7-year retention period followed by automatic deletion, meets the compliance officer's requirements for preservation, blocking deletion, and automatic disposal. This label can be applied to both Exchange Online mailboxes (email) and Teams messages via auto-labeling policies, covering all communications for the legal department.

Exam trap

The trap here is that candidates often confuse Litigation Hold (which preserves indefinitely without automatic deletion) with a retention label that includes both a fixed retention period and record marking, failing to recognize that Litigation Hold does not meet the 'dispose automatically after 7 years' requirement.

How to eliminate wrong answers

Option A is wrong because a Litigation Hold preserves content indefinitely (or until manually removed) but does not enforce automatic deletion after a specific period, nor does it mark items as 'records' to prevent tampering. Option C is wrong because the Preservation Hold Library is a SharePoint Online feature that applies to document libraries, not to Exchange Online mailboxes or Teams messages, and it does not provide record marking or automatic deletion scheduling. Option D is wrong because a Data Loss Prevention (DLP) policy is designed to detect and prevent sensitive data leakage, not to enforce retention, record marking, or automatic disposal; it lacks the ability to block deletion or mark items as records.

19
MCQhard

A compliance officer needs to ensure that no user can permanently delete a document from a specific SharePoint Online site. The document must be kept for at least 5 years. Which Microsoft Purview solution should the officer configure?

A.A: Sensitivity label with a retention period of 5 years.
B.B: Retention policy for the site with retention period of 5 years and action set to 'Retain'.
C.C: DLP policy to prevent deletion of documents.
D.D: eDiscovery hold on the site.
AnswerB

A retention policy applied at the site level prevents permanent deletion of content during the retention period, meeting the requirement.

Why this answer

A retention policy with the 'Retain' action ensures that documents in the SharePoint site are preserved for the specified period and cannot be permanently deleted by users or system processes. This meets the compliance requirement of a 5-year minimum retention and prevents permanent deletion, as retained items are moved to the Preservation Hold library.

Exam trap

The trap here is that candidates often confuse retention policies with sensitivity labels or eDiscovery holds, assuming that any retention setting or legal hold prevents deletion, but only a retention policy with the 'Retain' action provides the specific immutable retention and deletion prevention required for a fixed period like 5 years.

How to eliminate wrong answers

Option A is wrong because a sensitivity label with a retention period of 5 years applies retention settings at the item level based on classification, but it does not prevent permanent deletion by users; sensitivity labels primarily enforce protection and classification, not immutable retention. Option C is wrong because a DLP policy prevents data loss by blocking sharing or exfiltration of sensitive data, not by preventing deletion of documents; DLP policies do not enforce retention or deletion prevention. Option D is wrong because an eDiscovery hold preserves content for legal or investigative purposes but is designed for temporary holds, not for a fixed 5-year retention period, and it does not prevent permanent deletion by users in the same way as a retention policy with 'Retain' action.

20
MCQmedium

A compliance officer needs to ensure that all outbound emails containing credit card numbers sent to external recipients are automatically encrypted without requiring user intervention. Which Microsoft Purview feature should be configured?

A.Data Loss Prevention (DLP) policy with a rule that encrypts the message when credit card numbers are detected.
B.Sensitivity label with auto-labeling based on credit card numbers.
C.Retention policy for Exchange Online.
D.eDiscovery case for content search.
AnswerA

DLP can detect sensitive info and enforce encryption using Rights Management, all without user action.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview can be configured with a rule that automatically detects credit card numbers (using a built-in sensitive info type) and applies encryption via Transport Layer Security (TLS) or Information Rights Management (IRM) to outbound emails sent to external recipients. This meets the compliance officer's requirement for automatic encryption without user intervention, as the DLP rule triggers encryption at the transport level in Exchange Online.

Exam trap

The trap here is that candidates often confuse auto-labeling with sensitivity labels (Option B) as a direct encryption mechanism, but auto-labeling does not automatically encrypt outbound emails at the transport layer—it only applies labels, and encryption requires additional configuration (e.g., via a DLP policy or a label's protection settings) that may not trigger without user action or client-side processing.

How to eliminate wrong answers

Option B is wrong because sensitivity labels with auto-labeling can classify and protect content based on credit card numbers, but they do not automatically encrypt outbound emails at the transport level; they apply protection at the item level (e.g., file or email) and require user interaction or client-side auto-labeling, which may not encrypt messages in transit to external recipients without manual steps. Option C is wrong because a retention policy for Exchange Online is used to retain or delete emails based on age or criteria, not to encrypt outbound messages; it does not provide real-time encryption triggered by content detection. Option D is wrong because an eDiscovery case for content search is used to search, hold, and export content for legal or investigative purposes, not to enforce encryption on outbound emails; it is a discovery tool, not a protection mechanism.

21
MCQmedium

A compliance officer needs to automatically retain documents in a SharePoint Online document library for 7 years and then automatically delete them. The retention must be applied based on when the document is created. Which Microsoft Purview feature should be configured?

A.Data Lifecycle Management
B.Records Management
C.eDiscovery
D.Communication Compliance
AnswerA

Data Lifecycle Management in Microsoft Purview is the solution specifically built to automate retention and deletion based on configured policies. It uses retention labels and policies to apply rules like 'retain for 7 years then delete' triggered by content age or events. This lets you meet compliance obligations without manual intervention, making it the correct choice for automatically retaining documents.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview allows you to create retention labels that automatically retain content for a specified period (e.g., 7 years) based on the date the document was created, and then trigger a disposal action such as deletion. This feature is designed specifically for managing the lifecycle of data in SharePoint Online, including automatic retention and deletion based on metadata like creation date.

Exam trap

The trap here is that candidates often confuse Records Management with Data Lifecycle Management, assuming that any retention policy must involve records, when in fact DLM handles automated retention and deletion without requiring the content to be declared a record.

How to eliminate wrong answers

Option B (Records Management) is wrong because Records Management is focused on declaring content as records (immutable, auditable) and applying retention that prevents deletion or modification, not on automatically deleting content after a set period. Option C (eDiscovery) is wrong because eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for automated retention and deletion policies. Option D (Communication Compliance) is wrong because Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, sensitive info) in Microsoft Teams, Exchange, and Yammer, not for managing document lifecycle retention or deletion.

22
Multi-Selecthard

A compliance officer needs to ensure that all documents containing a custom sensitive info type (Employee ID with pattern EMP-####) are automatically labeled with a retention label that retains the documents for 3 years. Which two Microsoft Purview components must be configured? (Choose two.)

Select 2 answers
A.sensitivity label
B.retention label
C.data loss prevention (DLP) policy
D.An auto-labeling policy for retention labels
AnswersB, D

A retention label defines the retention and deletion rules for content at a granular level, such as preserving documents for a specific number of days, years, or permanently. You can apply it manually to individual items or through auto-labeling policies, and it triggers a retention period that cannot be overridden by users. For the compliance officer's requirement to manage document retention, this is the direct and authoritative mechanism.

Why this answer

A retention label is required to specify the retention period (3 years) for the documents. An auto-labeling policy for retention labels is needed to automatically apply that retention label based on the detection of the custom sensitive info type (Employee ID pattern EMP-####). Together, these two components enable automatic classification and retention without manual user intervention.

Exam trap

The trap here is that candidates often confuse sensitivity labels with retention labels, or think a DLP policy can apply retention labels, but Microsoft Purview separates these functions: DLP controls data movement, while auto-labeling policies for retention labels handle automatic retention label assignment.

23
MCQmedium

A company must ensure that all outgoing emails containing credit card numbers are blocked from being sent to external recipients. When a user attempts to send such an email, it should be blocked immediately, and the user should see a policy tip explaining the rule. Which Microsoft Purview solution should the administrator configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels
C.Retention labels
D.Communication compliance
AnswerA

DLP policies can block emails containing sensitive info and display policy tips to users.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information, such as credit card numbers, in transit (email) and enforce real-time actions like blocking the message and displaying a policy tip to the user. DLP policies in Microsoft Purview can be configured with conditions that match credit card number patterns using built-in sensitive info types, and the action 'Block messages' with a policy tip notification is available for Exchange Online mail flow. This ensures immediate blocking and user notification without requiring any manual labeling or classification.

Exam trap

The trap here is that candidates often confuse sensitivity labels with DLP because both involve 'protection,' but sensitivity labels require manual or automatic classification and do not perform real-time content inspection or blocking of outbound emails based on sensitive data patterns.

How to eliminate wrong answers

Option B is wrong because sensitivity labels are used to classify and protect data at rest (e.g., documents and emails) by applying encryption or visual markings, but they do not natively detect credit card numbers in real-time during email transmission or enforce blocking with policy tips. Option C is wrong because retention labels are designed to manage data lifecycle and retention policies (e.g., how long to keep or delete data), not to inspect email content for sensitive information or block outbound messages. Option D is wrong because communication compliance is focused on monitoring and reviewing internal and external communications for policy violations (e.g., harassment or insider trading), but it does not provide real-time blocking of emails based on sensitive data patterns or display policy tips to users.

24
MCQmedium

A compliance officer needs to prevent users from sharing confidential documents with external users outside the organization. The policy should block sharing via email attachments or sharing links from SharePoint Online. Which Microsoft Purview solution should be configured?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Retention policies
D.Information barriers
AnswerB

DLP policies are the correct technical control because they can identify sensitive information in messages and files and automatically block specific actions such as sending an external email or creating an external sharing link in SharePoint and OneDrive. When a rule is triggered, DLP can block the activity outright, show a policy tip, or require a user to justify an override, giving compliance officers a real-time enforcement mechanism. DLP works across Exchange, SharePoint, OneDrive, Teams, and endpoints, making it the only option listed that explicitly prevents the sharing of sensitive content.

Why this answer

Data Loss Prevention (DLP) in Microsoft Purview is designed to identify, monitor, and automatically protect sensitive information across Exchange Online, SharePoint Online, and OneDrive for Business. By creating a DLP policy with a rule that blocks sharing of confidential documents via email attachments or sharing links to external users, the compliance officer can enforce the required restriction. DLP policies can inspect content for sensitive data types (e.g., credit card numbers, custom confidential labels) and apply actions such as blocking the sharing action or sending a notification.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which apply protection) with DLP policies (which enforce actions like blocking), leading them to choose Option A, but labels alone cannot block sharing; they require a DLP policy to enforce the block action.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data by applying encryption, markings, or access restrictions, but they do not natively block sharing actions based on external user detection; DLP policies are required to enforce such blocking rules. Option C is wrong because retention policies are designed to preserve or delete content after a specified period, not to prevent real-time sharing of documents with external users. Option D is wrong because information barriers restrict communication and collaboration between specific internal groups or users (e.g., to avoid conflicts of interest), but they do not block sharing with external users outside the organization.

25
MCQhard

A compliance officer needs to automatically detect and apply a sensitivity label to documents in SharePoint Online that contain a custom sensitive information type (e.g., employee ID pattern). The label must be applied automatically, and users must be prompted to provide a justification when attempting to remove the label. Which combination of configurations should the officer implement?

A.Create a sensitivity label with an auto-labeling policy that uses a custom sensitive info type, and configure the label's protection settings to require user justification to remove the label.
B.Create a retention label and publish it to the site via auto-labeling policy.
C.Use a Data Loss Prevention (DLP) policy to apply the label and configure the policy to block removal.
D.Deploy the Azure Information Protection scanner to scan SharePoint Online documents.
AnswerA

This allows automatic detection and application of the label, and the justification requirement prevents easy removal.

Why this answer

Microsoft Purview sensitivity labels support auto-labeling policies that can automatically apply a label based on custom sensitive information types (e.g., employee ID patterns). Additionally, the label's protection settings include an option to require user justification when removing the label, which meets the compliance officer's requirement for both automatic detection and removal justification.

Exam trap

The trap here is that candidates confuse retention labels (which handle lifecycle) with sensitivity labels (which handle classification and protection), or they mistakenly think DLP policies can enforce label removal justification, which is a sensitivity label property, not a DLP rule action.

How to eliminate wrong answers

Option B is wrong because retention labels are designed for data lifecycle management (retention and deletion), not for sensitivity classification or protection settings like requiring justification for removal. Option C is wrong because DLP policies can apply sensitivity labels via auto-labeling, but they cannot enforce a 'block removal' of a label; removal justification is a property of the sensitivity label itself, not a DLP action. Option D is wrong because the Azure Information Protection (AIP) scanner is used for on-premises file shares and on-premises SharePoint, not for SharePoint Online; SharePoint Online uses built-in auto-labeling policies in Purview.

26
Multi-Selectmedium

Which TWO Microsoft Purview solutions can be used to detect and prevent the unauthorized sharing of sensitive information in Microsoft Teams messages?

Select 2 answers
A.Communication Compliance
B.eDiscovery (Premium)
C.Sensitivity labels
D.Information Barriers
E.Data Loss Prevention (DLP)
AnswersA, E

Communication Compliance in Microsoft Purview is designed to detect policy violations by analyzing user communications in Teams, Exchange, and Yammer for inappropriate or risky content. It uses customizable policies to flag messages that contain sensitive information, offensive language, or violations of corporate standards, enabling admins to review and take action. While it does not block sharing in real time, it is specifically built for detection and investigation of policy breaches.

Why this answer

DLP policies can scan Teams messages for sensitive content and block sharing. Communication Compliance can monitor messages for policy violations and take action. Sensitivity labels are for classification, not detection.

Information Barriers restrict communication between groups. eDiscovery is for investigation after the fact.

27
MCQmedium

A compliance administrator needs to automatically apply a retention label to all documents in a SharePoint Online site that contain Social Security numbers. The label should retain the documents for 5 years and then automatically delete them. Which feature should they configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label with auto-labeling
C.retention label with auto-labeling
D.An information barrier policy
AnswerC

Retention labels, when combined with auto-labeling policies, can automatically apply based on sensitive info types and enforce retention and deletion actions.

Why this answer

Retention labels with auto-labeling are designed to automatically apply retention settings based on sensitive information types, such as Social Security numbers, and can enforce a retention period (5 years) followed by automatic deletion. This feature is part of Microsoft Purview's records management and uses trainable classifiers or sensitive info types to trigger the label assignment on SharePoint Online documents.

Exam trap

The trap here is that candidates confuse DLP policies (which detect and protect) with retention labels (which manage lifecycle), leading them to choose Option A because both involve sensitive data detection, but only retention labels can enforce deletion after a set period.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy detects and protects sensitive data but does not apply retention labels or manage lifecycle actions like retention and deletion; DLP policies block or warn, not retain. Option B is wrong because sensitivity labels with auto-labeling focus on classification and protection (encryption, markings) rather than retention and deletion schedules; they do not enforce a 5-year retention followed by automatic deletion. Option D is wrong because an information barrier policy restricts communication and collaboration between groups, not document lifecycle management or retention labeling.

28
MCQhard

A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?

A.Sensitivity labels with encryption and usage rights
B.Data Loss Prevention (DLP) policy
C.Information Barriers
D.Microsoft Purview Information Protection without encryption
AnswerA

Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.

Why this answer

Sensitivity labels with encryption and usage rights allow administrators to apply Azure Rights Management (Azure RMS) protection to documents, which can restrict actions such as printing and copying. By configuring a sensitivity label with specific usage rights (e.g., 'View Only' or disabling 'Extract' and 'Print'), external users are prevented from printing or copying content even after the document is downloaded or accessed in SharePoint Online. This is the only Purview feature that directly enforces persistent content-level restrictions on external users.

Exam trap

The trap here is that candidates often confuse DLP policies with content protection, assuming DLP can restrict printing or copying after access, when in fact DLP only controls data in transit or at rest and does not enforce persistent usage rights on the document itself.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies detect and block sensitive information from being shared or exfiltrated, but they do not enforce persistent usage restrictions like preventing printing or copying after access is granted. Option C is wrong because Information Barriers are designed to prevent communication and collaboration between specific groups or users (e.g., to avoid conflicts of interest), not to control document-level actions like printing or copying. Option D is wrong because Microsoft Purview Information Protection without encryption applies labels for classification and auditing but does not enforce any technical restrictions on content usage; encryption is required to enforce usage rights.

29
MCQeasy

A compliance officer needs to preserve all mailbox data for a user who is under a legal investigation. The data must be preserved indefinitely, and no deletion (by the user or system) should be possible. Which Microsoft Purview feature should the officer use?

A.Litigation Hold
B.Retention Policy
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Litigation Hold is the correct choice because it preserves all mailbox content indefinitely, including deleted items and prior versions, and blocks both user purges and automatic Exchange retention cleanup. In Exchange Online, Litigation Hold temporarily overrides deletion and applies an indefinite hold that is only lifted when the hold is explicitly removed by an administrator, making it a true preservation-for-compliance mechanism.

Why this answer

Litigation Hold is the correct feature because it preserves all mailbox content indefinitely, preventing any deletion by the user or automated processes like the Managed Folder Assistant. It ensures that data is immutable for eDiscovery purposes, meeting the compliance officer's requirement for indefinite preservation under legal investigation.

Exam trap

The trap here is that candidates often confuse Retention Policies with Litigation Hold, thinking a retention policy can indefinitely preserve data, but retention policies have configurable expiration periods and can allow deletion, whereas Litigation Hold provides an immutable, indefinite hold specifically for legal scenarios.

How to eliminate wrong answers

Option B (Retention Policy) is wrong because retention policies can allow deletion after a specified period or apply actions like 'Delete' or 'Retain and Delete,' which does not guarantee indefinite preservation and can be overridden by user actions. Option C (Data Loss Prevention (DLP)) is wrong because DLP policies are designed to detect and prevent accidental sharing of sensitive data, not to preserve or hold mailbox data for legal purposes. Option D (Sensitivity labels) is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption or marking), but they do not prevent deletion or provide indefinite hold capabilities for mailbox items.

30
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site for 7 years and then automatically delete them. During the retention period, users must be able to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?

A.retention policy configured with a retention period of 7 years and an action to delete items automatically
B.retention label configured with a retention period and an action to delete after 7 years
C.data lifecycle management policy
D.An eDiscovery hold
AnswerA

A retention policy in Microsoft Purview applies at the container level, such as a SharePoint site or Exchange mailbox, and can be configured with a 7-year retention period followed by automatic deletion of items. This container-based scope ensures all documents in the site are covered without requiring per-item labels or manual classification. During the retention period, content is protected from permanent deletion by users, and after the 7 years the policy triggers an automatic purge, exactly matching the compliance officer's requirement.

Why this answer

A retention policy in Microsoft Purview can be applied at the site level to enforce a 7-year retention period with automatic deletion, while allowing users to edit documents during that time. The policy prevents deletion by users because the retention lock overrides user permissions, ensuring compliance with the requirement to block deletion but permit edits.

Exam trap

The trap here is that candidates confuse retention labels with retention policies, assuming labels can enforce site-wide deletion and edit permissions, but labels are item-level and require manual application or auto-labeling, whereas policies apply broadly and include the necessary deletion prevention.

How to eliminate wrong answers

Option B is wrong because a retention label requires manual or auto-classification and is typically applied to individual items, not an entire site, and it does not inherently prevent user deletion during the retention period unless combined with a retention policy. Option C is wrong because a data lifecycle management policy focuses on managing data across its lifecycle (e.g., archiving or moving to cold storage) but does not enforce a retention period with deletion prevention and automatic deletion in the same way as a retention policy. Option D is wrong because an eDiscovery hold preserves content for legal or investigative purposes but does not automatically delete items after a set period; it is designed for indefinite holds until released, not scheduled deletion.

31
MCQmedium

A compliance officer needs to prevent users from copying sensitive data (e.g., credit card numbers) from a finance application into personal email or documents. The solution must inspect the content in real-time and block the action if sensitive data is detected. Which Microsoft Purview feature should the officer configure?

A.Data Loss Prevention (DLP) policies
B.Sensitivity labels
C.Retention labels
D.eDiscovery
AnswerA

DLP policies are the correct choice because they perform real-time content inspection on endpoints and cloud apps, matching against sensitive information types (e.g., credit card numbers, PII) and then enforcing protective actions. A DLP policy can specifically block copy, paste, print, or transfer of that data to unauthorized destinations, and it can also trigger user notifications or incident reports. This is the only option that directly intercepts and prevents user copying actions at the point of resource access.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are designed to inspect content in real-time as users attempt to copy, paste, or share sensitive data (e.g., credit card numbers) from applications like finance apps into personal email or documents. DLP uses deep content analysis via sensitive information types and policy tips to block the action before the data leaves the controlled environment, meeting the compliance officer's requirement for real-time blocking.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which protect data at rest) with DLP policies (which enforce real-time action blocking), leading them to select sensitivity labels because they think labeling alone prevents copying, but labels do not block user actions in real-time.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data at rest (e.g., encryption or visual markings) but do not perform real-time content inspection or block copy/paste actions; they require user or automated labeling after data is created. Option C is wrong because retention labels manage data lifecycle (retention and deletion) based on policies, not real-time content inspection or blocking of data exfiltration. Option D is wrong because eDiscovery is used for searching, preserving, and exporting data for legal or investigative purposes, not for preventing data loss in real-time.

32
MCQeasy

A compliance officer needs to automatically apply a retention label to all documents in SharePoint Online that contain the exact phrase 'Contract'. The label must retain the documents for 10 years. Which Microsoft Purview feature should the officer configure?

A.retention policy applied to the entire site
B.Data Loss Prevention (DLP) policy
C.An auto-apply retention label using a trainable classifier
D.An auto-apply retention label using a content query (KQL)
AnswerD

An auto-apply retention label using a content query (KQL) is the only option that directly satisfies the requirement. In Microsoft Purview, you create an auto-apply retention label policy, select "Apply label to content that matches a query," and enter a KQL expression such as "Contract" to match documents containing that exact phrase. The KQL query runs against the search index, automatically assigns the retention label to matching content, and enforces the configured retention period. This approach is rule-based and deterministic, precisely targeting the literal string "Contract" as specified.

Why this answer

An auto-apply retention label using a content query (KQL) allows you to define a specific keyword or phrase (e.g., 'Contract') to automatically label documents in SharePoint Online that contain that exact text. This meets the requirement to retain documents for 10 years by applying the label based on content matching, without needing a pre-trained classifier.

Exam trap

The trap here is that candidates often confuse auto-apply labels with trainable classifiers, thinking a machine learning model is needed for any content-based labeling, when in fact a simple KQL query is sufficient for exact phrase matching.

How to eliminate wrong answers

Option A is wrong because a retention policy applied to the entire site retains all content in the site, not just documents containing the exact phrase 'Contract', and it does not use a label—it applies retention settings directly without the granularity of label-based auto-application. Option B is wrong because a Data Loss Prevention (DLP) policy is designed to prevent data exfiltration or leakage by blocking or alerting on sensitive content, not to automatically apply retention labels for compliance purposes. Option C is wrong because a trainable classifier uses machine learning to identify patterns or categories (e.g., contracts in general), not an exact phrase match, and requires training and tuning, making it unsuitable for a simple keyword-based requirement.

33
Multi-Selectmedium

A compliance officer needs to automatically detect and apply a sensitivity label to documents in SharePoint Online that contain personally identifiable information (PII) such as social security numbers. The label should be applied automatically, and users must be able to override the label with a justification. Which two Microsoft Purview components must be configured to achieve this?

Select 1 answer
A.sensitive info type (SIT) and an auto-labeling policy
B.sensitivity label with auto-labeling for SharePoint and a policy tip
C.data loss prevention (DLP) policy and a retention label
D.default sensitivity label and a compliance tag
AnswersA

Correct. An auto-labeling policy uses SITs to detect PII and applies a sensitivity label. The override with justification is configured in the sensitivity label policy settings.

Why this answer

An auto-labeling policy can scan SharePoint Online for sensitive info types (SITs) like social security numbers and automatically apply a sensitivity label. The policy can be configured to allow users to override the label with a justification via the 'Mandatory labeling with justification' setting in the sensitivity label policy. Option B is incorrect because policy tips are a feature of Data Loss Prevention (DLP) policies, not sensitivity label auto-labeling.

User override with justification is handled by the sensitivity label policy's 'Mandatory labeling' setting, not a policy tip. Therefore, only option A correctly identifies the required components.

Exam trap

Candidates may think that a sensitivity label with auto-labeling for SharePoint and a policy tip work together for override justification. However, policy tips are a DLP feature, not a sensitivity label mechanism. The override with justification is handled by the sensitivity label policy's 'Mandatory labeling' setting.

34
Matchingmedium

Match each Microsoft 365 role to its administrative scope.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Full access to all admin features

Resets passwords for non-admins

Manages Exchange Online

Manages users and groups

Manages security policies

Why these pairings

These roles are part of Azure AD role-based access control. The correct matches are: Global Administrator (full access), User Administrator (users/groups), Exchange Administrator (Exchange settings). Common confusions include mixing Global and User Administrator scopes, or User and Exchange Administrator scopes.

35
MCQmedium

An organization is involved in a legal case and needs to preserve all emails in a user's mailbox, including future emails, without deleting or modifying them. The user must continue to work normally. Which Microsoft Purview feature should be applied to the user's mailbox?

A.Litigation Hold
B.Retention policy
C.Sensitivity label
D.Data Loss Prevention (DLP)
AnswerA

Litigation Hold is the correct choice because it preserves all mailbox content in its original state, including items that users edit or delete, by placing the entire mailbox on hold within the Recoverable Items folder. This in-place hold suspends the normal purging of deleted items and version tracking, allowing legal teams to review everything via eDiscovery without disrupting user workflows. Unlike other options, Litigation Hold is specifically designed to meet legal preservation obligations and can be applied to a user's entire mailbox or specific folders.

Why this answer

Litigation Hold (option A) is the correct feature because it preserves all mailbox content, including future emails, in its original state without allowing deletion or modification by users or automated processes. Unlike a retention policy, Litigation Hold places the entire mailbox on indefinite hold, ensuring that any item changed or deleted by the user is retained in the Recoverable Items folder, while the user continues to work normally. This meets the legal preservation requirement without disrupting daily operations.

Exam trap

Microsoft often tests the distinction between Litigation Hold and Retention Policy, where candidates mistakenly choose Retention Policy because they think it 'retains' data, but they miss that Retention Policy can delete data after a period, whereas Litigation Hold preserves everything indefinitely without deletion.

How to eliminate wrong answers

Option B (Retention policy) is wrong because retention policies are designed to manage data lifecycle by deleting or retaining items based on age or rules, not to preserve all content indefinitely for legal hold; they can delete items after a specified period, which violates the preservation requirement. Option C (Sensitivity label) is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption or marking), but they do not prevent deletion or modification of emails, nor do they preserve mailbox content for legal purposes. Option D (Data Loss Prevention (DLP)) is wrong because DLP policies detect and prevent accidental sharing of sensitive information (e.g., credit card numbers) but do not impose holds or preserve mailbox items; they focus on data exfiltration prevention, not legal preservation.

36
Multi-Selecthard

Which THREE actions can be taken by a Microsoft Purview Data Loss Prevention (DLP) policy in Exchange Online?

Select 3 answers
A.Block the email from being sent
B.Allow the sender to override the block
C.Block all emails from the sender
D.Notify the sender with a policy tip
E.Encrypt the email message
AnswersA, D, E

In Microsoft Purview Data Loss Prevention (DLP), a policy can be configured with an action to block the transmission of an email that contains sensitive information. When the condition is met, the DLP engine can prevent the message from leaving the sender's mailbox, either silently or with a policy tip, depending on the rule configuration. This is a primary enforcement mechanism to stop data exfiltration before it occurs, as the email is never delivered to the recipient.

Why this answer

DLP policies in Exchange Online can block sending, encrypt the message, and notify the sender with a policy tip. Justifying override is not an action; it's a user response. Blocking all emails is not granular; DLP actions are rule-based.

37
MCQmedium

A compliance officer needs to prevent users from accidentally sharing documents containing credit card numbers with external users via email. The block should occur at the time the user attempts to send the email. Which Microsoft Purview feature should be configured?

A.Communication compliance
B.Data Loss Prevention (DLP)
C.Records management
D.Insider risk management
AnswerB

Data Loss Prevention (DLP) policies in Microsoft 365 enforce real-time protection by inspecting email messages for sensitive info types (e.g., credit card numbers, Social Security numbers) and applying actions such as blocking the message from leaving the organization, with optional user override and notification. These policies are integrated with Exchange Online transport rules, allowing them to evaluate outbound mail before delivery. DLP is the correct choice because it directly addresses the requirement to prevent accidental sharing through proactive, policy-based blocking.

Why this answer

Data Loss Prevention (DLP) is the correct feature because it is specifically designed to inspect email content in transit for sensitive data patterns, such as credit card numbers, and enforce policy actions like blocking the message at the transport layer. In Microsoft Purview, DLP policies can be configured to scan Exchange Online messages in real time using sensitive information types (e.g., Credit Card Number) and apply a block action with an optional policy tip to the user before the email leaves the outbound queue.

Exam trap

The trap here is that candidates often confuse Communication compliance (which also monitors email) with DLP, but Communication compliance is a reactive auditing tool for policy violations, not a proactive, inline blocking mechanism for sensitive data.

How to eliminate wrong answers

Option A is wrong because Communication compliance is designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading) after they are sent, not to block outbound emails containing sensitive data in real time. Option C is wrong because Records management focuses on classifying, retaining, and disposing of records based on regulatory requirements, not on inspecting or blocking email content during transmission. Option D is wrong because Insider risk management uses analytics to identify risky user activities (e.g., data exfiltration patterns) over time, but it does not provide inline blocking of email messages at the moment of sending.

38
MCQmedium

A compliance officer needs to prevent users from sharing documents labeled 'Confidential' via email with external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip displayed. Which Microsoft Purview feature should be configured?

A.Retention labels
B.Data Loss Prevention (DLP) policy
C.Sensitivity labels
D.Information barriers
AnswerB

DLP policies are the correct control because they inspect message content and context in transit and can match sensitive information types or sensitivity labels. With a rule, DLP can block or warn when email is shared with external users, and can even block the send action entirely while allowing an override with justification. This makes DLP the only option that directly enforces a sharing restriction based on content classification.

Why this answer

A Data Loss Prevention (DLP) policy is the correct Microsoft Purview feature because it is specifically designed to inspect email content and attachments for sensitive information, such as documents labeled 'Confidential', and enforce actions like blocking the email and displaying a policy tip to the user. DLP policies can be configured with conditions that detect sensitivity labels and apply protective actions, including blocking external sharing and notifying users via policy tips.

Exam trap

Microsoft often tests the misconception that sensitivity labels alone can enforce blocking actions, but in reality, sensitivity labels only apply classification and protection (e.g., encryption) and must be combined with a DLP policy to inspect and block outbound email based on those labels.

How to eliminate wrong answers

Option A is wrong because retention labels are used to manage data lifecycle (retain or delete content) and do not have the capability to block email transmission or display policy tips. Option C is wrong because sensitivity labels classify and protect data (e.g., encryption, marking) but do not directly enforce real-time blocking of email sharing with external recipients; DLP policies are required to inspect and block outbound email based on those labels. Option D is wrong because information barriers restrict communication and collaboration between specific groups of users within an organization, not between internal and external recipients, and cannot block email based on document labels or display policy tips.

39
Multi-Selectmedium

A compliance administrator needs to automatically apply a retention label to documents in a SharePoint Online site that contain the keyword 'Project Alpha'. The label should retain the documents for 5 years and then delete them. Which two Microsoft Purview features must be configured to achieve this? (Choose two.)

Select 2 answers
A.Trainable classifiers
B.Auto-labeling policy for SharePoint Online
C.Document Fingerprinting
D.Sensitive info type with a keyword dictionary (e.g., 'Project Alpha')
AnswersB, D

Auto-labeling policy for SharePoint Online is the correct feature because it uses conditions (like sensitive info types or trainable classifiers) to automatically apply a retention label to matching documents. To satisfy the requirement, you configure the policy with a sensitive info type that includes a keyword dictionary for 'Project Alpha', and assign the 2-year retention label. This policy runs continuously and can target all or specific SharePoint sites, providing the required automatic labeling.

Why this answer

An auto-labeling policy for SharePoint Online (option B) is required because it can automatically apply a retention label to documents based on conditions such as the presence of specific keywords. The sensitive info type with a keyword dictionary (option D) defines the condition by creating a custom sensitive information type that matches the exact phrase 'Project Alpha', which the auto-labeling policy then uses to trigger the label application.

Exam trap

The trap here is that candidates often confuse trainable classifiers with keyword-based sensitive info types, assuming machine learning is needed for any content detection, when in fact a simple keyword dictionary is sufficient and more appropriate for fixed terms.

40
MCQeasy

A compliance officer needs to ensure that any email sent from the organization that contains personally identifiable information (PII) such as social security numbers is automatically encrypted when the recipient is outside the organization. Which Microsoft Purview solution should the officer configure?

A.Sensitivity labels with auto-labeling
B.Data Loss Prevention (DLP) policy with encryption action
C.Office 365 Message Encryption (OME) configuration
D.Retention policy and labels
AnswerB

Microsoft Purview DLP policies are the correct solution because they operate on outbound email in transit within Exchange Online, scanning message body and attachments for sensitive data types. When a match occurs, the policy can automatically apply encryption as a protective action (via OME) and even show a policy tip or notify the sender, exactly meeting the requirement to ensure any email containing sensitive data is secured at send.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview can be configured with an 'Encrypt email messages' action that automatically applies Office 365 Message Encryption (OME) to emails containing sensitive information types (e.g., Social Security Number) when sent to external recipients. This meets the compliance requirement for automatic encryption based on content detection, without requiring user intervention or manual label application.

Exam trap

The trap here is that candidates confuse the underlying encryption technology (OME) with the policy that triggers it, leading them to select OME configuration (Option C) instead of the DLP policy that actually detects PII and enforces the encryption action.

How to eliminate wrong answers

Option A is wrong because sensitivity labels with auto-labeling can apply classification and protection, but they are designed for persistent labeling across documents and emails, not specifically to trigger encryption based on PII detection at the point of sending; auto-labeling for emails requires Exchange mail flow rules or DLP policies to enforce encryption. Option C is wrong because Office 365 Message Encryption (OME) is the underlying encryption technology, not a policy or configuration that automatically detects PII and triggers encryption; OME must be invoked by a DLP policy or mail flow rule. Option D is wrong because retention policies and labels manage data lifecycle and deletion, not real-time content inspection or encryption of outbound emails.

41
MCQmedium

A legal department needs to preserve all communications related to an ongoing lawsuit. They identify specific users and require that their mailbox items and OneDrive files are not altered or deleted. Which Microsoft Purview feature should be used?

A.Litigation Hold
B.Retention Policy
C.Data Loss Prevention (DLP)
D.eDiscovery
AnswerA

Litigation Hold is the correct mechanism because it places a preservation hold on an entire mailbox and OneDrive for Business site in-place, preventing items from being permanently deleted or altered. Every version of a document and every mailbox item, including deleted items and items edited by users, is retained in the Recoverable Items folder until the hold is released. Deletion by users, as well as cleanup by retention policies, is blocked for held content, ensuring all communications related to the legal matter remain discoverable in their original location.

Why this answer

Litigation Hold is the correct feature because it preserves all mailbox items and OneDrive files for specific users in their current state, preventing any alteration or deletion by users or automated processes. This is essential for legal holds where data must be immutable for eDiscovery purposes, and it applies at the user level rather than broadly across the organization.

Exam trap

The trap here is that candidates often confuse retention policies with litigation holds, thinking retention policies can preserve data indefinitely, but retention policies allow deletion after the retention period and do not block user-initiated edits or deletions during the policy's active duration.

How to eliminate wrong answers

Option B (Retention Policy) is wrong because retention policies are designed for managing data lifecycle and can delete or archive items after a specified period, but they do not prevent users from modifying or deleting content while the policy is active; litigation hold explicitly locks content. Option C (Data Loss Prevention) is wrong because DLP focuses on preventing sensitive data from being shared or leaked through rules and policies, not on preserving data from alteration or deletion. Option D (eDiscovery) is wrong because eDiscovery is a tool for searching, holding, and exporting data as part of legal investigations, but it is not a hold feature itself; litigation hold is the underlying mechanism that eDiscovery uses to preserve content.

42
MCQmedium

A compliance officer needs to retain all email messages in a user's Exchange Online mailbox for 7 years after the message is sent or received, and then automatically delete them. The retention must be enforced regardless of user actions. Which Microsoft Purview solution should be used?

A.Litigation hold
B.Retention policy with Exchange location
C.Classification policy
D.In-place eDiscovery hold
AnswerB

A retention policy can retain and then delete content after a specified period.

Why this answer

A retention policy with the Exchange location in Microsoft Purview allows you to define a retention period (e.g., 7 years) and then automatically delete messages after that period. It enforces the retention regardless of user actions because it operates at the service level, not relying on user cooperation. This meets the compliance officer's requirement for mandatory, time-based retention and deletion.

Exam trap

The trap here is that candidates often confuse Litigation hold (which preserves indefinitely) with a retention policy (which can both preserve and delete after a set time), leading them to select Litigation hold for time-based deletion scenarios.

How to eliminate wrong answers

Option A is wrong because Litigation hold preserves all mailbox content indefinitely until the hold is removed, but it does not automatically delete messages after a specific period; it is designed for legal preservation, not time-based retention with deletion. Option C is wrong because Classification policy (e.g., sensitivity labels) applies metadata and protection actions but does not enforce time-based retention or automatic deletion of email messages. Option D is wrong because In-place eDiscovery hold is a deprecated feature that preserves content for eDiscovery purposes without automatic deletion; it also does not support time-based retention policies.

43
MCQeasy

A compliance officer wants to prevent users from sending emails that contain personally identifiable information (PII), such as social security numbers, to external recipients. If a user attempts to send such an email from Outlook, the email should be blocked and a policy tip explaining the block should be displayed. Which Microsoft Purview solution should the officer configure?

A.Microsoft Purview Data Loss Prevention (DLP) policy
B.Microsoft Purview Information Protection sensitivity label
C.Microsoft Purview Records Management retention label
D.Microsoft Purview eDiscovery case
AnswerA

A Microsoft Purview Data Loss Prevention (DLP) policy is exactly designed for this scenario: when applied to Exchange Online, it inspects outbound messages in transit against sensitive info types (such as social security numbers or credit card numbers) and can take corrective actions like blocking the message before it leaves the organization, optionally allowing an end-user override with justification and a policy tip in Outlook. This combination of content inspection, transport-level enforcement, and real-time user notification makes it the correct choice for preventing users from sending emails with specific sensitive data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block sensitive information, such as PII (e.g., social security numbers), in transit. When a DLP rule matches, it can block the email and display a policy tip in Outlook, informing the user why the message was blocked. This meets the compliance officer's requirement to prevent external sending of PII with real-time user notification.

Exam trap

The trap here is that candidates confuse sensitivity labels (which apply protection at rest) with DLP policies (which enforce actions on data in motion), leading them to choose Option B because they associate labels with 'protecting' PII, but labels do not block outbound email or trigger policy tips.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data at rest (e.g., encryption, visual markings) but do not natively block outbound email based on content inspection or display policy tips in Outlook. Option C is wrong because retention labels manage data lifecycle (retention and deletion) and are not designed to inspect or block email content in transit. Option D is wrong because eDiscovery cases are used for legal hold, search, and export of content, not for real-time prevention of email sending or policy tip enforcement.

44
MCQmedium

A compliance officer needs to prevent users from sending emails that contain sensitive information, such as social security numbers, to external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip should be displayed to the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label with encryption
C.Information Rights Management (IRM)
D.retention label with deletion
AnswerA

A DLP policy in Microsoft Purview integrates with Exchange Online to inspect email content in transit and at the client. It uses sensitive information types (e.g., U.S. Social Security Number) as conditions and can apply an action to 'Block the message' from being sent, optionally allowing the sender to override with a business justification. At the same time, policy tips are displayed in Outlook, Outlook on the web, and Mail for iOS/Android during composition, providing real-time guidance before the message leaves the client. This is the only option that actually prevents the email from being sent and educates the sender.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to inspect email content for sensitive information (e.g., social security numbers) and can block the message while displaying a policy tip to the user. This matches the requirement exactly, as DLP policies enforce actions on data in transit (email) with user notifications.

Exam trap

The trap here is that candidates confuse sensitivity labels (which protect data at rest) with DLP (which protects data in motion), leading them to choose Option B because they think encryption prevents sending, but encryption does not block the email or show a policy tip at the point of sending.

How to eliminate wrong answers

Option B (sensitivity label with encryption) is wrong because sensitivity labels primarily classify and protect data at rest (e.g., files in SharePoint) and can apply encryption, but they do not natively block outbound email in real-time or display policy tips during send. Option C (Information Rights Management) is wrong because IRM protects content after delivery by restricting actions like forwarding or printing, but it does not inspect or block emails before they are sent based on sensitive data patterns. Option D (retention label with deletion) is wrong because retention labels manage data lifecycle (e.g., how long to keep or when to delete) and have no capability to scan outbound email content or block transmission.

45
Multi-Selecthard

A Microsoft Purview auto-labeling policy for sensitivity labels is matching too many SharePoint documents after simulation. Which two changes would most directly reduce false positives before enabling automatic labeling? (Choose two.)

Select 2 answers
A.Increase the confidence level or instance-count requirement for the sensitive information type
B.Add supporting keyword or contextual conditions to the auto-labeling rule
C.Turn on automatic labeling immediately and wait for users to report problems
D.Replace the sensitivity label with a retention label
AnswersA, B

Raising the confidence level or instance-count threshold in the sensitive information type (SIT) increases the probability that the detected pattern is a genuine match rather than an isolated or coincidental string. Confidence reflects the match strength of the classification engine, and instance count requires multiple occurrences in the same item, both of which reduce false positives in an auto-labeling policy.

Why this answer

Increasing the confidence level or instance-count requirement for the sensitive information type (SIT) directly reduces false positives by raising the threshold for what qualifies as a match. A higher confidence level means the classification engine requires stronger evidence (e.g., more keywords or a closer proximity to a pattern), while a higher instance count requires the sensitive data to appear multiple times in the document. Both adjustments make the auto-labeling rule more selective, ensuring only documents with a high likelihood of containing the specified sensitive content are labeled.

Exam trap

The trap here is that candidates may think immediate enforcement (Option C) is the fastest way to fix false positives, but Microsoft explicitly recommends using simulation mode to tune rules before enabling automatic labeling, and waiting for user reports is not a valid tuning strategy.

46
MCQhard

A compliance officer needs to automatically identify and label content that is conceptually similar to existing sensitive documents, such as internal strategy memos or proprietary technical specifications, without relying on explicit keywords or recognized sensitive information types. Which Microsoft Purview solution should the officer use to achieve this?

A.trainable classifier
B.sensitive information type
C.An auto-labeling policy with a retention label
D.Data Loss Prevention (DLP) policy that blocks sharing
AnswerA

Trainable classifiers are designed to identify content based on examples and can learn to recognize documents that are conceptually similar, such as internal memos or proprietary specs, without needing exact keywords or predefined sensitive info types.

Why this answer

A trainable classifier uses machine learning to identify content based on patterns and context learned from sample documents, making it ideal for recognizing conceptually similar content without relying on explicit keywords or predefined sensitive information types. This allows the compliance officer to automatically label internal strategy memos or proprietary technical specifications that share conceptual similarity with existing sensitive documents.

Exam trap

The trap here is that candidates often confuse trainable classifiers with sensitive information types, assuming that keyword or regex-based patterns are sufficient for conceptual similarity, when in fact trainable classifiers are the only Microsoft Purview solution that uses machine learning to identify content based on learned patterns rather than explicit rules.

How to eliminate wrong answers

Option B is wrong because sensitive information types rely on predefined patterns (e.g., regex, keywords, checksums) and cannot identify conceptually similar content without explicit keywords or recognized types. Option C is wrong because an auto-labeling policy with a retention label applies labels based on conditions like sensitive info types or trainable classifiers, but the retention label itself does not perform conceptual identification; the labeling policy would still require a trainable classifier to trigger. Option D is wrong because a Data Loss Prevention (DLP) policy that blocks sharing can use classifiers or sensitive info types to enforce actions, but it is a protective control, not a labeling solution for automatic identification and labeling of conceptually similar content.

47
MCQmedium

A legal hold is required for all emails in a user's mailbox related to a litigation case. The administrator needs to ensure that the mailbox content is preserved even if the user tries to delete emails. Which Microsoft Purview feature should be used?

A.Litigation Hold
B.eDiscovery (Standard) case hold
C.Retention policy
D.In-Place Hold
AnswerA

Litigation Hold is a dedicated hold feature in Exchange Online (under Microsoft Purview) that preserves an entire mailbox in-place, including all deleted and edited items, by maintaining copies in the Recoverable Items folder. It applies instantly and remains in effect until explicitly removed, making it the precise mechanism for legally requiring every email in a user's mailbox to be retained. Unlike policy-based deletion or case-scoped holds, Litigation Hold is designed for indefinite, mailbox-wide legal preservation without requiring a separate eDiscovery case.

Why this answer

Litigation Hold is the correct choice because it is a Microsoft Purview feature specifically designed to preserve all mailbox content, including deleted items and original versions of modified items, for legal or compliance purposes. When enabled, it places the user's entire mailbox on hold, preventing permanent deletion by the user or automated processes, and ensures that all data related to a litigation case is retained indefinitely until the hold is removed.

Exam trap

The trap here is that candidates often confuse Litigation Hold with eDiscovery case holds or retention policies, but Litigation Hold is the simplest and most direct feature for preserving an entire mailbox indefinitely for legal purposes, without needing to create a case or define retention rules.

How to eliminate wrong answers

Option B (eDiscovery (Standard) case hold) is wrong because it is used to preserve content for a specific eDiscovery case, but it requires creating an eDiscovery case and associating a hold with that case, which is more complex and not the simplest direct method for a single user's mailbox in a litigation scenario. Option C (Retention policy) is wrong because retention policies are designed for managing data lifecycle based on age or other criteria, not for indefinite preservation in response to a legal hold, and they can allow deletion after a specified period. Option D (In-Place Hold) is wrong because In-Place Hold is a legacy Exchange Online feature that has been deprecated in favor of Litigation Hold and eDiscovery holds; it is no longer available in modern Microsoft Purview deployments.

Ready to test yourself?

Try a timed practice session using only Manage compliance by using Microsoft Purview questions.