Courseiva

CCNA Manage compliance by using Microsoft Purview Questions

75 of 104 questions · Page 1/2 · Manage compliance by using Microsoft Purview · Answers revealed

1
MCQeasy

A compliance officer needs to ensure that all documents in a SharePoint Online library are automatically labeled with a 'Confidential' sensitivity label if they contain at least one of a predefined list of sensitive information types such as credit card numbers or social security numbers. Users should be able to override the label with a business justification. Which Microsoft Purview feature should the officer configure?

A.Auto-labeling policy for SharePoint Online
B.Data Loss Prevention (DLP) policy
C.Retention label policy
D.Sensitivity label with manual classification
AnswerA

Auto-labeling policies in the Microsoft Purview compliance portal let you define conditions—such as sensitive info types, trainable classifiers, or custom keywords—that trigger automatic application of a sensitivity label to matching SharePoint Online documents. Once created, the policy runs continuously, and in enforcement mode it labels every existing and new file that meets the criteria, providing a scalable, centralized solution. You can also require users to justify lowering or removing the label, balancing automation with user oversight. This directly satisfies the need to ensure all relevant documents are classified automatically.

Why this answer

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on the detection of sensitive information types (e.g., credit card numbers, SSNs). This policy supports user override with a business justification, meeting the compliance officer's requirement exactly. Manual classification (Option D) would not automate the labeling, and DLP policies (Option B) focus on preventing data loss, not applying sensitivity labels.

Exam trap

Microsoft often tests the distinction between auto-labeling policies (which apply sensitivity labels automatically) and DLP policies (which enforce actions like blocking or alerting), causing candidates to confuse the two because both can detect sensitive information types.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies are designed to detect and block the sharing of sensitive data, not to automatically apply sensitivity labels to documents; they can trigger alerts or block actions but do not label content. Option C is wrong because retention label policies manage how long content is kept or deleted, not sensitivity classification; they are unrelated to labeling based on sensitive information types. Option D is wrong because a sensitivity label with manual classification requires users to manually apply the label, which does not satisfy the requirement for automatic labeling based on content detection.

2
MCQeasy

A compliance officer needs to prevent users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label
C.retention label
D.An information barrier policy
AnswerA

A Data Loss Prevention (DLP) policy in Microsoft Purview can inspect outbound email messages in real time for sensitive information types (e.g., credit card numbers, PII) and apply actions such as blocking delivery, redirecting the message, or allowing override with justification. While composing, the policy can display a policy tip to the user, providing immediate feedback that sharing such content is prohibited, which directly enforces the compliance officer's requirement to prevent email sharing.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information, such as credit card numbers, in transit (e.g., email) and enforce actions like blocking the message and displaying a policy tip to the user. DLP policies use sensitive information types (e.g., Credit Card Number) and rules to inspect content in Exchange Online, SharePoint, OneDrive, and Teams, allowing real-time blocking with user notification. This directly meets the compliance officer's requirement to prevent external sharing and provide immediate feedback.

Exam trap

Microsoft often tests the distinction between DLP policies and sensitivity labels, where candidates mistakenly think a sensitivity label alone can block email transmission, but labels require a DLP policy to enforce actions like blocking, while DLP policies can work independently of labels.

How to eliminate wrong answers

Option B (sensitivity label) is wrong because sensitivity labels classify and protect data at rest (e.g., encryption, visual markings) but do not natively block email transmission based on content inspection or provide policy tips in real-time; they require additional DLP policies to enforce actions on labeled content. Option C (retention label) is wrong because retention labels manage data lifecycle (retention and deletion) and have no capability to inspect email content for sensitive data or block messages. Option D (information barrier policy) is wrong because information barriers restrict communication between specific user groups (e.g., to prevent conflicts of interest) and do not scan for sensitive data like credit card numbers or block external sharing.

3
MCQeasy

You need to ensure that all documents in a SharePoint Online site are automatically labeled with a 'Confidential' sensitivity label. Which Microsoft Purview feature should you use?

A.Microsoft Purview auto-labeling policy
B.Microsoft Purview Data Loss Prevention policy
C.Microsoft Purview retention policy
D.Microsoft Purview manual labeling
AnswerA

Microsoft Purview auto-labeling policies apply sensitivity labels automatically to items matching specified conditions, such as documents in a SharePoint Online site, without user intervention. That satisfies the stem's requirement that all documents be labelled Confidential automatically rather than through manual or default labelling.

Why this answer

Auto-labeling policies can automatically apply sensitivity labels to documents in SharePoint Online based on conditions. Option B is wrong because Data Loss Prevention policies detect and protect sensitive data but do not apply labels. Option C is wrong because retention policies manage data retention and deletion, not sensitivity labels.

Option D is wrong because manual labeling requires user action, not automatic application.

4
MCQmedium

An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to create a policy that blocks users from pasting credit card numbers into web forms in Microsoft Edge. Which type of DLP policy should they configure?

A.Endpoint DLP
B.Exchange DLP
C.SharePoint DLP
D.Teams DLP
AnswerA

Endpoint DLP is the correct selection because it monitors Windows and macOS devices and can inspect user activities such as copying sensitive content to the clipboard. When a user attempts to paste that data into a web form, Endpoint DLP in Microsoft Edge or another supported Chromium-based browser can evaluate the policy condition and block the paste action. The capability relies on the Microsoft Purview endpoint agent being onboarded on the device, and it is the only option that controls clipboard operations at the endpoint itself.

Why this answer

Endpoint DLP is correct because it monitors and controls activities on Windows 10/11 and macOS endpoints, including the ability to block pasting sensitive data like credit card numbers into web forms in Microsoft Edge. This policy extends DLP protection to unmanaged browsers and specific user actions, such as paste, clipboard, and print, which are not covered by cloud-based DLP policies.

Exam trap

The trap here is that candidates often assume all DLP policies are cloud-based and overlook that only Endpoint DLP can enforce restrictions on local user actions like pasting into web forms, confusing it with Exchange or SharePoint DLP which only inspect data at rest or in transit within Microsoft 365 services.

How to eliminate wrong answers

Option B (Exchange DLP) is wrong because it only applies to email messages in transit or at rest in Exchange Online, not to web form pasting in Edge. Option C (SharePoint DLP) is wrong because it protects documents stored in SharePoint Online and OneDrive for Business, not user actions in a browser. Option D (Teams DLP) is wrong because it covers messages and files in Microsoft Teams chats and channels, not web form interactions in Edge.

5
MCQeasy

A company needs to automatically retain all emails sent to or from external partners for 7 years. They also need to ensure that after 7 years, the emails are permanently deleted. What should you configure in Microsoft Purview?

A.Create a retention label with a retention period of 7 years and publish it to all users.
B.Create a retention policy for Exchange email with a retention period of 7 years, followed by deletion.
C.Create an eDiscovery hold for all external partner communications.
D.Create a data loss prevention (DLP) policy to block deletion of emails after 7 years.
AnswerB

A retention policy scoped to Exchange mailboxes applies a seven-year retention period then deletes items, satisfying both the retain and permanent-deletion requirements. Retention policies act at workload level, covering all external-partner correspondence without per-item configuration.

Why this answer

A retention policy in Microsoft Purview can be scoped to Exchange email and configured with a 7-year retention period followed by permanent deletion. This automatically applies to all mailboxes and meets both the retain and delete requirements without user action.

Exam trap

The trap is confusing retention labels (manual/auto-applied per item) with retention policies (automatic, workload-wide); the requirement for 'all emails' points to a policy, not a label.

How to eliminate wrong answers

Option A is wrong because a retention label published to users requires manual or auto-labeling and does not guarantee automatic application to all emails; it is better for content that needs classification. Option C is wrong because an eDiscovery hold preserves content indefinitely for legal purposes and does not delete after 7 years. Option D is wrong because a DLP policy prevents sharing of sensitive data; it does not manage retention or deletion lifecycles.

6
Multi-Selecteasy

Which TWO Microsoft Purview solutions are primarily used for data classification?

Select 2 answers
A.Data Loss Prevention
B.Auto-labeling
C.Communication Compliance
D.Data Lifecycle Management
E.Sensitivity labels
AnswersB, E

Auto-labeling is a primary Purview solution used to classify data by automatically applying sensitivity labels to content. It evaluates files, emails, and other content against sensitive info types, patterns, and conditions, then assigns the appropriate label without manual intervention. This enables consistent, bulk classification across hybrid environments, and it can run in client-side or service-side (server-side) modes to label content before or after it is stored.

Why this answer

Auto-labeling (B) is correct because it is a Microsoft Purview Information Protection capability that automatically applies sensitivity labels to content by scanning it for sensitive information types, trainable classifiers, or exact data match, which is a core data-classification function. Sensitivity labels (E) are also correct because they are the primary mechanism in Microsoft Purview for manually classifying and protecting content by tagging it with a classification (for example, Confidential or Highly Confidential) that can enforce encryption and other protections. Together, sensitivity labels and auto-labeling form the classification backbone of Microsoft Purview Information Protection.

Data Loss Prevention (A) is not primarily a classification tool; it uses classification results to detect and block risky sharing of sensitive data. Communication Compliance (C) focuses on detecting policy violations in communications such as harassment or inappropriate content, not on classifying data. Data Lifecycle Management (D) governs retention and deletion of content rather than classifying it.

Exam trap

MS-102 often tests the distinction between classification and protection solutions, causing candidates to confuse DLP (which enforces) with auto-labeling (which classifies).

7
MCQmedium

A compliance officer needs to automatically retain emails that contain personally identifiable information (PII) for 10 years and then permanently delete them. Which Microsoft Purview feature should be configured?

A.Auto-apply retention labels based on sensitive information types
B.Data Lifecycle Management retention policy
C.Data classification
D.eDiscovery
AnswerA

Auto-apply retention labels are content-aware and can be configured to trigger whenever a sensitive information type—such as a credit card number, passport number, or other PII—is detected in an email. Once the label is applied, its retention settings enforce the 10-year retention period and, at the end of that period, automatically dispose of the item. This satisfies the requirement to selectively retain emails based on content, not just location or folder.

Why this answer

Auto-apply retention labels based on sensitive information types allow you to automatically classify and retain emails containing PII for a specified period (10 years) and then permanently delete them. This feature uses sensitive information types (e.g., Social Security Number, Credit Card Number) to detect PII and applies a retention label that enforces the retention and deletion actions at the item level, which is required for targeted compliance scenarios.

Exam trap

The trap here is that candidates often confuse Data Lifecycle Management retention policies (which apply broadly to all content in a location) with auto-apply retention labels (which apply only to content matching specific sensitive information types), leading them to incorrectly select option B.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policy applies to all content in a location (e.g., entire mailbox or site) and cannot automatically target only emails containing specific sensitive information like PII; it lacks the auto-classification capability based on content inspection. Option C is wrong because Data classification is a discovery and labeling tool that identifies and categorizes data but does not itself enforce retention or deletion actions; it requires a retention label or policy to act on the classification. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for automated retention and deletion based on content type.

8
MCQmedium

A compliance officer needs to prevent users from sending emails that contain credit card numbers to external recipients. When a user attempts to send such an email, the action should be blocked and a policy tip should be displayed in Outlook telling them why the email was blocked. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention (DLP) policy
B.Retention label policy
C.Microsoft Purview Information Protection sensitivity label
D.Compliance Manager
AnswerA

A Microsoft Purview Data Loss Prevention policy inspects Exchange email for sensitive information types such as credit card numbers, then enforces a block action for external recipients and surfaces a policy tip in Outlook explaining the block. This directly satisfies the stem's requirement to stop the send and notify the user.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to detect and block sensitive information, such as credit card numbers, from being sent to external recipients. When configured with a 'Block' action and a policy tip, it prevents the email from being sent and displays a customizable notification in Outlook explaining the reason. This directly meets the compliance officer's requirement to block the email and show a policy tip.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking based on content inspection), leading them to choose Option C because they think labeling alone can block emails.

How to eliminate wrong answers

Option B is wrong because a Retention label policy is used to retain or delete data based on compliance requirements, not to block the transmission of sensitive content in emails. Option C is wrong because a Microsoft Purview Information Protection sensitivity label applies classification and protection (e.g., encryption) to content, but it does not natively block outbound emails containing credit card numbers or display policy tips in Outlook. Option D is wrong because Compliance Manager is a risk assessment and compliance management tool that provides recommendations and tracks compliance posture, not a policy that enforces real-time blocking of sensitive data in email.

9
MCQmedium

A compliance officer needs to prevent users from sharing documents that have been labeled 'Highly Confidential' with external users. When a user attempts to share such a document externally, the action should be blocked and the user should see a policy tip. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity label encryption
C.Retention policy
D.Records management
AnswerA

A Microsoft Purview DLP policy can use sensitivity labels as conditions, and its actions can block sharing both via email (Exchange, Outlook) and external sharing in SharePoint/OneDrive. For example, when a condition like 'content contains a Confidential label' is met, the policy can block the sharing action and display a policy tip to the user before the block occurs. This directly enforces the compliance officer's requirement to prevent users from sharing content with a specific label, while the other mechanisms do not intercept the sharing action.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it can inspect content and context (including sensitivity labels) to enforce rules that block external sharing of documents labeled 'Highly Confidential' and display a policy tip to the user. DLP policies in Microsoft Purview are specifically designed to prevent accidental or intentional data leakage by monitoring and controlling sharing actions in real time.

Exam trap

The trap here is that candidates often confuse sensitivity label encryption (which protects the file) with DLP (which controls the sharing action), leading them to choose encryption when the requirement explicitly involves blocking the share and showing a policy tip.

How to eliminate wrong answers

Option B is wrong because sensitivity label encryption protects the document at rest and in transit by encrypting it, but it does not block the sharing action itself or show a policy tip; it only controls access after the file is shared. Option C is wrong because a retention policy is used to preserve or delete content after a specified period, not to block real-time sharing actions or display policy tips. Option D is wrong because records management marks content as a record to prevent deletion or modification, but it does not block external sharing or provide policy tips during sharing attempts.

10
MCQeasy

A compliance officer needs to block users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy.
B.Sensitivity label with encryption.
C.Microsoft Defender for Office 365 Safe Attachments policy.
D.Communication compliance policy.
AnswerA

DLP policies inspect email content for sensitive data types such as credit card numbers, block transmission to external recipients, and display policy tips to the sender. This directly satisfies the requirement to stop the email immediately while notifying the user.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information types (e.g., credit card numbers via predefined rule patterns matching the Luhn algorithm) in transit and enforce actions such as blocking the email and displaying a policy tip to the sender. This meets the compliance officer's requirement to block external sharing of credit card data immediately with user notification.

Exam trap

The trap here is that candidates often confuse the real-time blocking and notification capability of DLP with sensitivity labels (which only apply protection after classification) or communication compliance (which is a review-based solution, not a real-time enforcement mechanism).

How to eliminate wrong answers

Option B is wrong because a sensitivity label with encryption can protect content by restricting access or applying encryption, but it does not actively scan outbound email content for credit card numbers or block messages in transit with a policy tip. Option C is wrong because Microsoft Defender for Office 365 Safe Attachments policy focuses on scanning email attachments for malware and malicious content, not on detecting sensitive data patterns like credit card numbers. Option D is wrong because a communication compliance policy is designed to monitor and review internal/external communications for policy violations (e.g., harassment, insider trading) and typically requires manual review, not real-time blocking with a policy tip based on sensitive data patterns.

11
Multi-Selectmedium

A compliance officer needs to automatically classify documents in SharePoint Online that contain credit card numbers. The classification should apply a label that restricts access and adds a header. Which two Microsoft Purview features must be configured? (Choose two.)

Select 2 answers
A.Sensitivity labels
B.Retention labels
C.Data Loss Prevention (DLP) policies
D.Auto-labeling policies
AnswersA, D

Sensitivity labels are the core classification mechanism in Microsoft Purview Information Protection. When applied, they embed metadata into the document and enforce protection settings such as encryption, rights management restrictions, and visual markings like headers, footers, or watermarks. The label persists with the content even when it leaves the organization, ensuring classification and protection follow the file. This directly satisfies the compliance officer's need to classify documents, especially when combined with auto-labeling for full automation.

Why this answer

Sensitivity labels are correct because they are the Microsoft Purview feature that applies classification markings (such as headers and footers) and encryption or access restrictions to documents. For this scenario, a sensitivity label must be configured to enforce the required header and access restrictions on content containing credit card numbers.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP policies do not apply labels or headers—they only enforce actions like blocking or notification, whereas auto-labeling policies are required to automatically assign the sensitivity label.

12
MCQmedium

Your organization uses Microsoft Purview Information Protection. You need to ensure that when users manually apply a 'Confidential' label to a document in Word, the document is automatically marked with a footer 'CONFIDENTIAL' and encrypted. What must you configure?

A.Modify the sensitivity label policy to include the footer.
B.Create a DLP rule that applies the footer and encryption.
C.Set up auto-labeling to apply the footer and encryption.
D.Configure the sensitivity label's settings to include the footer and encryption.
AnswerD

Configuring the sensitivity label itself with footer and encryption settings satisfies the manual-labelling requirement. Label-scoped content marking and encryption apply automatically when a user selects 'Confidential' in Word, with no separate policy or client configuration needed. Microsoft Purview Information Protection enforces both directly at label application.

Why this answer

Sensitivity labels in Microsoft Purview Information Protection can be configured with content marking (headers, footers, watermarks) and encryption settings directly in the label definition. When a user manually applies the 'Confidential' label in Word, the label's configured footer and encryption are applied automatically to the document. This is the core behavior of sensitivity labels — the label itself carries the protection settings.

Exam trap

MS-102 often tests the confusion between label policies (which control label availability and default/mandatory settings) and label settings (which define the actual protection and marking) — candidates pick the policy option thinking it configures the footer.

How to eliminate wrong answers

Option A is wrong because a sensitivity label policy controls which users see which labels and whether labeling is mandatory or default, but it does not define the footer or encryption settings. Option B is wrong because DLP rules can detect and act on sensitive content but are not the mechanism that applies footer marking and encryption when a label is manually applied; DLP is for policy enforcement, not label content marking. Option C is wrong because auto-labeling applies labels automatically based on content inspection, whereas the scenario specifies the user manually applies the label — auto-labeling is not needed and would not configure the footer/encryption anyway.

13
MCQhard

A compliance officer needs to ensure that all emails containing sensitive information (e.g., passport numbers) are automatically encrypted when sent to external recipients. The encryption should be enforced without requiring users to manually select an option. Which Microsoft Purview feature should they configure?

A.Data Loss Prevention (DLP) policy with encryption action
B.Sensitivity labels with auto-labeling
C.Message Encryption (OME) policies
D.Communication Compliance
AnswerA

Data Loss Prevention (DLP) policies in Microsoft Purview can directly apply an encryption action to outgoing email by leveraging Azure Rights Management. When a DLP policy detects a sensitive information type (e.g., credit card numbers or personally identifiable information) in the message body or attachments, it automatically wraps the message with the 'Encrypt' action, enforcing transport-level protection without user intervention. This policy-based approach is purpose-built for compliance scenarios where data exfiltration must be prevented at the email boundary.

Why this answer

A Data Loss Prevention (DLP) policy with encryption action is correct because it automatically detects sensitive information (e.g., passport numbers) using sensitive info types and enforces encryption via Microsoft Purview Message Encryption (OME) as a rule action. This ensures that when an email containing such data is sent to an external recipient, the email is automatically encrypted without requiring user intervention, meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse sensitivity labels with auto-labeling as the solution for automatic encryption, but auto-labeling only applies labels based on conditions and does not enforce encryption unless the label itself is configured for encryption and the DLP policy triggers the action.

How to eliminate wrong answers

Option B is wrong because sensitivity labels with auto-labeling can classify and protect content but do not directly enforce encryption on outbound emails based on content detection; they require a DLP policy to trigger the encryption action. Option C is wrong because Message Encryption (OME) policies define encryption rules but are typically configured within DLP policies or mail flow rules; standalone OME policies do not automatically detect sensitive data and enforce encryption without additional conditions. Option D is wrong because Communication Compliance is designed to detect and investigate policy violations (e.g., harassment, insider trading) and does not provide automatic encryption of emails based on sensitive content.

14
MCQmedium

A compliance officer needs to prevent users from sharing protected health information (PHI) with external users in Microsoft Teams chat messages. When a user attempts to send a message containing a known PHI data type (e.g., medical record numbers), the message should be blocked and the sender should see a policy tip. Which Microsoft Purview solution should the officer configure?

A.Communication compliance policy
B.Data Loss Prevention (DLP) policy for Teams
C.Sensitivity labels applied to Teams
D.Information barriers
AnswerB

A Data Loss Prevention (DLP) policy for Teams can enforce real-time protection on chat and channel messages by scanning content for sensitive information types, including protected health information (PHI). When a match is detected, the policy blocks the message and shows the sender a policy tip, with options to allow override based on policy configuration. This directly prevents users from sharing PHI, making it the appropriate solution.

Why this answer

A Data Loss Prevention (DLP) policy for Microsoft Teams can be configured to detect and block sensitive information types, such as medical record numbers (a PHI data type), in chat messages. When a match occurs, the policy can block the message and display a policy tip to the sender, meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse Communication compliance (which reviews sent messages) with DLP (which blocks messages in transit), leading them to select Option A despite the requirement for real-time blocking and policy tips.

How to eliminate wrong answers

Option A is wrong because Communication compliance policies are designed to detect and review inappropriate or policy-violating communications (e.g., harassment, insider trading) after they are sent, not to block messages in real-time or enforce data loss prevention rules. Option C is wrong because sensitivity labels applied to Teams control access and protection (e.g., encryption, visual markings) at the container or file level, not the content of individual chat messages. Option D is wrong because Information barriers are used to prevent specific groups of users from communicating with each other (e.g., to avoid conflicts of interest), not to scan message content for sensitive data types like PHI.

15
MCQhard

Refer to the exhibit. You have a DLP policy in test mode as shown. A user reports that they received a notification that sharing credit card numbers is blocked, but they were still able to share them. What is the most likely reason?

A.The rule action 'BlockAccess' is not included in the policy.
B.The policy is in test mode, which does not enforce actions.
C.The condition 'SensitiveInformation' is not configured correctly.
D.The notification is not enabled in the policy.
AnswerB

DLP policies have a policy-level mode setting: 'Enforce', 'Test with policy tips', or 'Test without policy tips'. In 'Test' mode, Microsoft 365 processes the policy's conditions to identify sensitive content and generate incident reports, but all rule actions — including BlockAccess — are effectively disabled. The exhibit explicitly shows the policy is in test mode, which fully explains why nothing is blocked and no access restriction occurs. This is the designed behavior for validating rules before enforcement.

Why this answer

A DLP policy in test mode (also called simulation mode) evaluates rules and generates alerts, notifications, and activity reports, but it does not enforce the configured actions such as BlockAccess or Block. Therefore the user sees the policy tip/notification indicating the content is sensitive, yet the sharing is still allowed because the block action is not applied. This is the intended behavior for validating a policy before turning it on.

Exam trap

MS-102 often tests the confusion between 'policy tip shown' and 'action enforced' — candidates assume a notification means the block happened, forgetting that test/simulation mode only surfaces tips and alerts without enforcing actions.

How to eliminate wrong answers

Option A is wrong because even if BlockAccess were missing, the user would not receive a 'blocked' notification — the notification itself is generated by the rule, and the question states the notification appeared, implying the rule matched. Option C is wrong because if SensitiveInformation were misconfigured, the rule would not match credit card numbers at all and no notification would fire. Option D is wrong because the user did receive a notification, proving user notifications are enabled; the issue is enforcement, not notification.

16
Multi-Selectmedium

A compliance officer needs to automatically apply a 'Highly Confidential' sensitivity label to any email in Exchange Online that contains social security numbers. The labeling must happen automatically without user interaction. Which two Microsoft Purview components must be configured? (Select the option that correctly identifies both required components.)

Select 1 answer
A.sensitivity label with auto-labeling rule and a Data Loss Prevention policy
B.retention label and a Communication Compliance policy
C.sensitivity label and an auto-labeling policy
D.unified labeling client and a custom sensitive info type
AnswersC

Correct. A sensitivity label with an auto-labeling rule defines what to label and when, and an auto-labeling policy triggers the automatic application without user interaction. This pair fulfills the requirement.

Why this answer

To automatically apply a 'Highly Confidential' sensitivity label to emails containing social security numbers in Exchange Online, you must configure a sensitivity label (which defines the label and its protection settings) and an auto-labeling policy (which scans Exchange Online for the sensitive info type and applies the label automatically without user interaction). Data Loss Prevention (DLP) policies can detect sensitive information and take actions such as blocking or alerting, but they cannot directly apply sensitivity labels. Therefore, only option C correctly identifies both required components.

Exam trap

The trap is that candidates may incorrectly believe DLP policies can automatically apply sensitivity labels. In reality, DLP policies do not support this action; automatic labeling requires an auto-labeling policy or a retention label policy with auto-labeling, but for sensitivity labels, it must be an auto-labeling policy.

17
MCQmedium

Your organization uses Microsoft Purview Records Management. You need to ensure that records are marked as regulatory records and cannot be deleted or modified by any user, including administrators. The records must be retained for 10 years. What should you do?

A.Use a retention label marked as a regulatory record.
B.Create a retention policy with a preservation lock.
C.Use a retention label marked as a record.
D.Apply a default retention label to the SharePoint library.
AnswerA

A regulatory record label enforces immutability at the platform level: once applied, the item cannot be modified or deleted by anyone, including administrators, satisfying the stem's absolute protection requirement. It also supports a 10-year retention period, unlike standard records, which administrators can still remove.

Why this answer

A retention label configured as a regulatory record provides the highest level of immutability: it prevents any user, including administrators, from deleting or modifying the item, and the label itself cannot be removed or changed once applied. This meets the requirement that records cannot be deleted or modified by anyone. The 10-year retention period is set on the label.

Exam trap

MS-102 often tests the difference between a record and a regulatory record; candidates often pick 'record' because it sounds strict, but only 'regulatory record' prevents administrators from removing the label.

How to eliminate wrong answers

Option B is wrong because a retention policy with a preservation lock prevents the policy from being turned off or modified, but it does not prevent users from deleting items; it only ensures the policy remains in effect. Option C is wrong because a retention label marked as a record allows administrators to remove the label and then delete the item, so it does not provide the same level of protection as a regulatory record. Option D is wrong because a default retention label applied to a SharePoint library does not prevent deletion or modification by administrators; it only applies retention settings.

18
MCQeasy

A compliance officer needs to automatically detect documents in SharePoint Online that contain a custom pattern (e.g., employee ID in the format EMP-12345). The pattern will be used to apply a sensitivity label. Which Microsoft Purview feature should the officer use to define the pattern?

A.Sensitive information types
B.Data Loss Prevention (DLP) policies
C.Content search
D.Data classification reports
AnswerA

Sensitive information types define the detection logic itself, using built-in or custom regex patterns, keywords, and confidence thresholds to identify data like employee IDs. After you define a custom sensitive information type, it becomes a reusable condition that purge policies, auto-labeling, and DLP rules rely on. This is the correct answer because the compliance officer's requirement to 'automatically detect' a specific pattern starts with creating that type, not with a policy that merely consumes it.

Why this answer

Sensitive information types (SITs) in Microsoft Purview are specifically designed to define custom patterns, such as regular expressions for employee IDs like EMP-12345. Once defined, these SITs can be used in sensitivity labels to automatically classify and protect documents in SharePoint Online. This is the correct feature because it directly supports pattern-based detection for labeling.

Exam trap

The trap here is that candidates often confuse DLP policies with pattern definition, but DLP policies only consume pre-defined sensitive information types and cannot create them.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies enforce rules to prevent data exfiltration but do not define the pattern itself; they use existing sensitive information types. Option C is wrong because Content Search is a query tool for finding content based on keywords or metadata, not for defining reusable patterns for automatic labeling. Option D is wrong because Data classification reports provide visibility into classified data but do not allow creation of custom patterns.

19
Multi-Selectmedium

A compliance officer wants to automatically apply a retention label to documents that contain SWIFT codes (financial identifiers) when uploaded to SharePoint Online. Which two Microsoft Purview features are required for this configuration? (Choose two.)

Select 2 answers
A.Sensitivity label
B.Trainable classifier
C.Auto-apply retention label policy
D.Data Loss Prevention (DLP) policy
AnswersB, C

A trainable classifier is an AI-based content detection model in Microsoft Purview that you train with seed documents to recognize specific patterns, such as SWIFT codes. Once published, the classifier can be used as a condition inside an auto-apply retention label policy; when documents match the classifier's model, the policy automatically assigns the appropriate retention label. It is the detection component that identifies the content, not the policy that performs the actual label assignment.

Why this answer

A trainable classifier is required to identify content containing SWIFT codes based on pattern recognition and machine learning. Option C is correct because an auto-apply retention label policy is the mechanism that automatically assigns the retention label to documents when the classifier detects SWIFT codes in SharePoint Online.

Exam trap

The trap here is that candidates often confuse sensitivity labels with retention labels, or mistakenly think a DLP policy can directly apply retention labels, when in fact DLP policies only trigger alerts or block actions, not label assignment.

20
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 10 years, after which the documents must be automatically deleted. During the retention period, users must be allowed to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?

A.retention policy with a retention period of 10 years and an action to delete at the end of the period
B.retention label auto-applied to all documents in the site
C.Litigation hold on the site
D.Data Loss Prevention (DLP) policy with a retention action
AnswerA

A retention policy applied to the SharePoint site works at the container level, automatically covering every document and version without needing per-item labels or rules. Users can continue editing during the 10-year period, but deletion is blocked until the disposition action permanently deletes the files at period end. This directly satisfies both the preservation and the 10-year deletion requirement.

Why this answer

A retention policy can be applied to a SharePoint site to enforce a 10-year retention period with a deletion action at the end, while allowing users to edit documents during that period. This meets the compliance requirement because retention policies preserve content from deletion by users, but still permit editing. The 'delete at end of retention period' action ensures automatic removal after 10 years.

Exam trap

The trap here is that candidates often confuse retention labels with retention policies, thinking labels are required for site-wide retention, but policies are the correct tool for applying uniform retention and deletion to an entire site without manual labeling.

How to eliminate wrong answers

Option B is wrong because a retention label auto-applied to all documents would also work for retention and deletion, but the question asks for a 'solution' that is simpler and more appropriate for a site-wide requirement; retention labels are typically used for granular, item-level classification rather than blanket site-wide retention. Option C is wrong because Litigation hold preserves content indefinitely (no automatic deletion) and prevents editing in some configurations, which does not meet the 10-year deletion requirement. Option D is wrong because Data Loss Prevention (DLP) policies are designed to prevent data leakage and enforce security rules, not to manage retention or deletion of documents.

21
MCQmedium

A compliance administrator needs to ensure that all documents in a SharePoint library are retained for exactly 7 years and then allow users to manually dispose of them sooner after a review. What should they configure in Microsoft Purview?

A.Create a retention label with a retention period of 7 years and enable disposition review
B.Create a retention label with a retention period of 7 years and no additional action
C.Create a sensitivity label that restricts access
D.Create a record label
AnswerA

A retention label with a 7-year period and disposition review is the correct choice because it retains the document for the full regulatory period, yet the disposition review step triggers a manual approval workflow at the end of the retention period. During that review, an authorized user can approve early disposal, satisfying the requirement that documents be manually dispose-able if approved, rather than being automatically deleted or locked indefinitely.

Why this answer

The requirement specifies a fixed 7-year retention period followed by user-initiated disposal after a review. A retention label with a retention period of 7 years and disposition review enabled allows content to be retained for exactly 7 years, after which a disposition review triggers a manual approval process for disposal. This matches the need for both mandatory retention and manual disposal after review.

Exam trap

The trap here is that candidates often confuse retention labels with record labels, assuming that any label with a retention period automatically supports manual disposal, but only retention labels with disposition review enabled provide the specific workflow for user-initiated disposal after review.

How to eliminate wrong answers

Option B is wrong because a retention label with no additional action will automatically delete the content after 7 years without any user review or manual disposal option, which violates the requirement to allow users to manually dispose of items sooner after a review. Option C is wrong because a sensitivity label is designed to classify and protect data through encryption or access restrictions, not to enforce retention or disposition workflows; it does not provide any retention period or disposal review capability. Option D is wrong because a record label marks content as a record (immutable) and typically prevents deletion or modification, which contradicts the requirement to allow manual disposal after review; records require a disposition review but are not designed for flexible user-initiated disposal.

22
MCQmedium

Your organization uses Microsoft Purview to enforce data loss prevention (DLP) policies. Users report that a DLP policy blocks legitimate sharing of a document containing sensitive financial data. You need to allow the sharing while still protecting the data. What should you do?

A.Disable the DLP policy and create a new one with broader conditions.
B.Add the user to the DLP policy's super user group.
C.Modify the DLP policy to exclude the specific document type.
D.Configure a policy tip to allow override with a business justification.
AnswerD

Policy tips with override let users supply a business justification to bypass the block, satisfying the need to permit legitimate sharing while retaining protection. The override is logged and auditable, so sensitive financial data remains governed rather than simply unblocked.

Why this answer

Configuring a policy tip to allow override with a business justification enables users to legitimately share the document while still being audited. Policy tips notify users when their action violates a DLP policy and allow them to override with a justification, which is logged for review. Option A is wrong because disabling the policy removes protection entirely.

Option B is wrong because adding a user to a super user group bypasses all DLP checks, which is not appropriate. Option C is wrong because excluding the document type could weaken protection for all similar documents.

23
MCQmedium

An organization has a legal requirement to preserve certain contracts as immutable records. Once a contract is declared as a record, it must not be editable or deletable by users, including administrators. Which Microsoft Purview solution should be configured?

A.Data Loss Prevention
B.eDiscovery (Premium)
C.Communication Compliance
D.Records Management
AnswerD

Records Management, a feature of Microsoft Purview, uses retention labels with the 'Mark as a record' action to make content immutable: the item cannot be edited, renamed, or deleted, and a full audit trail is recorded. Once a contract is labeled as a record, users—and in the case of regulatory records, even system administrators—cannot alter or purge it before the specified retention period expires. This exactly addresses the legal requirement to preserve contracts in a tamper-proof form, unlike the other three options.

Why this answer

Records Management in Microsoft Purview is designed to declare items as immutable records, locking them against editing or deletion by any user, including administrators. This satisfies the legal requirement for preserving contracts as unchangeable records by applying retention labels that enforce strict regulatory compliance.

Exam trap

The trap here is that candidates confuse Records Management with eDiscovery holds, thinking a legal hold provides immutability, but eDiscovery holds only prevent deletion during litigation and do not prevent editing or permanent record locking.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies prevent unauthorized sharing or leakage of sensitive data but do not enforce immutability or prevent editing/deletion of records. Option B is wrong because eDiscovery (Premium) is used for legal hold, search, and export of content for litigation, not for making records permanently immutable. Option C is wrong because Communication Compliance monitors and analyzes communications for policy violations (e.g., harassment, insider trading) and does not provide record locking or immutability features.

24
Multi-Selectmedium

You are the Microsoft 365 Administrator for a multinational organization that must comply with various regulatory requirements, including GDPR, SOX, and internal data retention policies. You are deploying Microsoft Purview compliance solutions. Which four of the following actions are valid steps when managing compliance using Microsoft Purview? (Choose all that apply. There are four correct answers.)

Select 4 answers
.Create a DLP policy that prevents users from sharing credit card numbers via email with external recipients.
.Use a retention label to automatically delete documents containing trade secrets after 7 years.
.Configure a sensitivity label with sublabels that apply different markings (e.g., 'Confidential' and 'Highly Confidential') to the same document.
.Enable auditing in the Microsoft 365 compliance portal to track user activities such as file downloads and mailbox access.
.Assign a retention policy to a user's mailbox that deletes all emails immediately after they are sent.
.Apply a sensitivity label to a SharePoint site that blocks all external sharing of documents stored in that site.

Why this answer

Creating a DLP policy that prevents sharing credit card numbers via email with external recipients is a valid step because Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive information types (e.g., credit card numbers) and enforce actions such as blocking external sharing. This directly supports compliance with regulations like GDPR and SOX by preventing unauthorized data exfiltration.

Exam trap

Microsoft often tests the misconception that sensitivity labels can directly control external sharing of documents within a site, when in reality they control site-level settings (e.g., privacy) while external sharing is governed by SharePoint sharing policies.

25
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site associated with the Finance department for 7 years, and after that automatically delete them. During the retention period, users must not be able to edit or delete the documents. Which solution should they use?

A.Create a retention policy scoped to the site with 'Retain as records' action
B.Create a retention label with 'Retain as regulatory records' and publish it to the site, then use auto-apply based on site location
C.Create a sensitivity label with 'Retain as records' and apply it manually
D.Create a litigation hold for the site
AnswerB

A regulatory records label is the only way to make content both uneditable and undeletable; publishing the label to the site makes it available, and an auto-apply policy scoped by site location automatically assigns it to every document, eliminating reliance on manual user action. Once applied, the label blocks editing and deletion by users and even administrators, and the retention period cannot be shortened. This fully satisfies the compliance requirement for retaining all documents with record integrity.

Why this answer

A retention label with 'Retain as regulatory records' locks the document against editing or deletion during the retention period, and auto-applying the label based on site location ensures all documents in the Finance site inherit the 7-year retention and automatic deletion. This meets the compliance officer's requirement for immutable retention and automatic disposal without manual user intervention.

Exam trap

The trap here is confusing 'Retain as records' (which only prevents deletion after the retention period) with 'Retain as regulatory records' (which prevents editing and deletion during the entire retention period), leading candidates to incorrectly choose Option A.

How to eliminate wrong answers

Option A is wrong because a retention policy with 'Retain as records' action does not prevent users from editing or deleting documents during the retention period; it only prevents deletion after the retention period ends. Option C is wrong because a sensitivity label with 'Retain as records' is not a valid construct; sensitivity labels manage sensitivity and protection, not retention, and manual application does not guarantee all documents are covered. Option D is wrong because a litigation hold preserves documents indefinitely (until the hold is released) and does not enforce a specific 7-year retention period or automatic deletion; it also does not prevent editing, only deletion.

26
MCQeasy

Your company is implementing Microsoft Purview Records Management. You need to ensure that invoices are retained for seven years after they are paid, and then automatically deleted. Which type of label should you create?

A.Disposition review label assigned to invoices
B.Retention policy applied to all documents in SharePoint
C.Retention label with disposition review after the trigger event
D.Sensitivity label with auto-labeling
AnswerC

Retention labels can start retention from a trigger event and then dispose.

Why this answer

A retention label with a disposition review after a trigger event can automate deletion after a specified period (7 years) triggered by an event (invoice payment). Option A is incorrect because a disposition review label requires manual review before deletion, whereas the requirement is automatic deletion. Option B is incorrect because a retention policy applies to all documents in a location and cannot be scoped to specific items based on metadata like payment date.

Option D is incorrect because sensitivity labels are for classification and protection, not retention management.

27
MCQeasy

A user in your organization receives a 'Message blocked' notification when trying to send an email with a credit card number. The DLP policy is configured to block such emails. The user claims the credit card number is a valid test number used for training. What should you do to allow the email while maintaining security?

A.Configure a policy tip to allow override with a business justification.
B.Exclude the user from the DLP policy.
C.Disable the DLP policy temporarily.
D.Add the user to the DLP policy's super user group.
AnswerA

Configuring a DLP policy tip to allow an override with a business justification enables the user to send the blocked message while the event is recorded in the audit log and DLP reports. This preserves the policy for all other users and content, and provides a controlled, reviewable exception for legitimate business needs. Unlike broader changes, this is the intended mechanism to balance productivity with data protection.

Why this answer

Configuring a policy tip with override allows the user to justify the override with a business justification, which is audited. This maintains security by notifying the user and recording the override for compliance. Option B (excluding the user) removes DLP protection entirely for that user, which is insecure.

Option C (disabling the policy) disables protection for all users. Option D (adding to super user group) bypasses all DLP checks for the user, which is too permissive.

28
MCQeasy

Your organization needs to prevent users from sharing documents containing personally identifiable information (PII) with external users. You have Microsoft Purview Data Loss Prevention (DLP) deployed. What should you configure?

A.Apply a sensitivity label that blocks external sharing.
B.Create a DLP policy that detects PII and restricts sharing to external users.
C.Configure a conditional access policy in Microsoft Entra ID to block external sharing.
D.Enable auditing for all document sharing activities.
AnswerB

A DLP policy scoped to the PII sensitive information type inspects documents and enforces restrictions when external sharing is attempted. Microsoft Purview evaluates the content against that classifier and blocks or warns on the sharing action, directly satisfying the requirement to stop PII leaving to external users.

Why this answer

Microsoft Purview DLP is specifically designed to detect sensitive information types (like PII) in documents and apply protective actions, such as blocking external sharing. A DLP policy can be scoped to locations like SharePoint, OneDrive, Exchange, and Teams, and can enforce rules that prevent users from sharing content containing PII with external users. This directly addresses the requirement by combining detection and enforcement.

Exam trap

MS-102 often tests the distinction between DLP and sensitivity labels, where candidates might think a sensitivity label alone can block external sharing, but DLP is required for content-based enforcement.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are primarily for classification and protection (e.g., encryption), but they do not inherently block external sharing; labels can be used with DLP, but alone they do not enforce sharing restrictions. Option C is wrong because conditional access policies in Microsoft Entra ID control access to cloud apps based on conditions like user, device, and location, but they do not inspect document content for PII or block sharing actions. Option D is wrong because enabling auditing only provides visibility into sharing activities; it does not prevent or block the sharing of PII.

29
Multi-Selectmedium

A compliance officer needs to automatically apply a sensitivity label that encrypts documents in SharePoint Online when the documents contain a custom regex pattern (e.g., employee ID). The labeling must occur automatically without requiring user interaction. Which two Microsoft Purview components must be configured? (Select the option that correctly identifies both components.)

Select 1 answer
A.An auto-labeling policy and a sensitivity label with encryption configured
B.Data Loss Prevention (DLP) policy and a sensitivity label
C.retention label and an auto-labeling policy
D.sensitive info type and a sensitivity label
AnswersA

Correct. An auto-labeling policy automatically applies the sensitivity label to documents matching the custom regex pattern, and the sensitivity label with encryption provides the required protection.

Why this answer

Auto-labeling in Microsoft Purview requires three elements: (1) a custom sensitive info type (SIT) defined with the regex pattern (e.g., employee ID), (2) a sensitivity label configured with encryption, and (3) an auto-labeling policy that uses the SIT as a condition to apply the label without user interaction. Option A is incomplete because it omits the custom SIT needed to detect the regex pattern; without it, the auto-labeling policy has no condition to match. Option D includes the SIT and label but lacks the auto-labeling policy, so it cannot apply labels automatically.

The question's framing as 'two components' is flawed; the correct set is the SIT, the label, and the auto-labeling policy.

Exam trap

Candidates often forget that auto-labeling policies require a sensitive info type (SIT) as the detection condition. A custom regex pattern must be defined as a custom SIT; the label and policy alone cannot detect it. Also, DLP policies do not apply sensitivity labels—they only detect and protect/block.

30
MCQmedium

A compliance officer needs to monitor employee communications across Microsoft Teams and Outlook for potential insider trading, using predefined policies. The solution must detect keywords like 'insider tip' and 'stock' and allow designated reviewers to take action. Which Microsoft Purview solution should the officer use?

A.Communication Compliance
B.Data Loss Prevention
C.eDiscovery (Premium)
D.Records Management
AnswerA

Communication Compliance is a Microsoft Purview solution that provides proactive monitoring of user communications across email, Microsoft Teams, Yammer, and third-party sources. It uses customizable policies and machine learning-based trainable classifiers to detect potential regulatory violations—including insider trading, harassment, or conflicts of interest—and then routes alerts for investigation and remediation within the compliance portal. This makes it the correct tool for an ongoing, automated surveillance of employee communications rather than a reactive or archival mechanism.

Why this answer

Communication Compliance is the correct Microsoft Purview solution because it is specifically designed to detect sensitive keywords (e.g., 'insider tip' and 'stock') in Microsoft Teams chats, channel messages, and Outlook emails using predefined or customizable policies. It enables designated reviewers to investigate and take remediation actions such as removing messages or escalating for legal review, directly addressing the insider trading monitoring requirement.

Exam trap

The trap here is that candidates confuse Communication Compliance with Data Loss Prevention because both involve policy-based detection, but DLP is about preventing data exfiltration, not monitoring for insider trading keywords with reviewer workflows.

How to eliminate wrong answers

Option B (Data Loss Prevention) is wrong because DLP focuses on preventing unauthorized sharing of sensitive data (e.g., credit card numbers or PII) by blocking or alerting on outbound content, not on monitoring communications for insider trading keywords or enabling reviewer actions. Option C (eDiscovery Premium) is wrong because eDiscovery is used for legal hold, search, and export of content as evidence in litigation or investigations, not for real-time policy-based monitoring and remediation of communications. Option D (Records Management) is wrong because Records Management deals with classifying, retaining, and disposing of records based on regulatory requirements, not with detecting specific keywords in live communications or enabling reviewer workflows.

31
MCQhard

A compliance officer needs to preserve all communications (email and Teams messages) for employees in the legal department for a minimum of 7 years. Additionally, any deletion (by users or system) must be blocked, and after the retention period, the items must be disposed of automatically. The solution must also ensure that the communications are marked as 'records' to prevent tampering. Which Microsoft Purview solution should the officer configure?

A.Litigation hold on the legal department's mailboxes and Teams
B.retention label configured with 'Mark items as a record' and a retention period of 7 years, then delete automatically
C.Preservation hold library in SharePoint Online
D.Data Loss Prevention (DLP) policy with retention action
AnswerB

A retention label configured with 'Mark items as a record' makes content immutable: after application, users and administrators cannot edit or delete the item until the retention period expires. Setting the retention period to 7 years and selecting 'delete automatically' ensures the communication is preserved for the full regulatory period and then automatically purged. This is the only option that combines record immutability, a fixed 7-year timeframe, and automatic deletion, which matches the compliance officer's exact requirement.

Why this answer

A retention label with 'Mark items as a record' enforces immutability (prevents tampering) and, when configured with a 7-year retention period followed by automatic deletion, meets the compliance officer's requirements for preservation, blocking deletion, and automatic disposal. This label can be applied to both Exchange Online mailboxes (email) and Teams messages via auto-labeling policies, covering all communications for the legal department.

Exam trap

The trap here is that candidates often confuse Litigation Hold (which preserves indefinitely without automatic deletion) with a retention label that includes both a fixed retention period and record marking, failing to recognize that Litigation Hold does not meet the 'dispose automatically after 7 years' requirement.

How to eliminate wrong answers

Option A is wrong because a Litigation Hold preserves content indefinitely (or until manually removed) but does not enforce automatic deletion after a specific period, nor does it mark items as 'records' to prevent tampering. Option C is wrong because the Preservation Hold Library is a SharePoint Online feature that applies to document libraries, not to Exchange Online mailboxes or Teams messages, and it does not provide record marking or automatic deletion scheduling. Option D is wrong because a Data Loss Prevention (DLP) policy is designed to detect and prevent sensitive data leakage, not to enforce retention, record marking, or automatic disposal; it lacks the ability to block deletion or mark items as records.

32
MCQhard

Your organization, Fabrikam Inc., uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You have a DLP policy that blocks sharing of credit card numbers in Teams messages. Recently, users have reported that they cannot share legitimate credit card numbers for business purposes, even with customers. You need to allow users to override the block for legitimate sharing, but require them to provide a business justification. What should you configure?

A.Create a second DLP policy with a lower priority that allows credit card sharing, and assign it to a security group containing authorized users.
B.Add the users to an exempt group in the DLP policy so they are not blocked.
C.Configure the DLP policy to show a policy tip that allows users to override the block with a business justification, and enable audit logging for overrides.
D.Configure the DLP policy to allow overrides without justification, and monitor usage.
AnswerC

Enabling the override with justification in the policy tip satisfies the requirement to permit legitimate sharing while capturing a reason. The policy tip appears in Teams, letting users proceed after entering a business justification, and audit logging records each override for later review and compliance reporting.

Why this answer

DLP policy tips in Microsoft Teams can be configured to allow users to override a block, and the override can require a business justification that is captured in the audit log. This preserves the protective control while providing a documented exception path for legitimate business scenarios like sharing a customer's own credit card number. Enabling audit logging ensures the override and justification are recorded for compliance review.

Exam trap

MS-102 often tests the confusion between exempting users from a DLP policy (removing all protection) and configuring a policy tip with override (preserving protection while allowing documented exceptions) — candidates pick the exemption path thinking it is more granular when it is actually broader.

How to eliminate wrong answers

Option A is wrong because creating a second lower-priority allow policy does not provide a per-incident override with justification — it silently permits sharing for an entire group, removing the control rather than creating a documented exception. Option B is wrong because exempting users from the DLP policy removes all protection for them, which is broader than needed and defeats the purpose of the policy. Option D is wrong because allowing overrides without requiring justification removes the accountability and audit trail that compliance requires; the question explicitly states users must provide a business justification.

33
MCQmedium

A compliance officer needs to prevent users from sending emails that contain social security numbers to external recipients. When a user attempts to send such an email from Outlook, the email should be blocked and a policy tip should be displayed explaining why the email was blocked. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels
C.Communication compliance
D.eDiscovery
AnswerA

DLP policies in Exchange Online are the correct mechanism because they inspect email content in transit against sensitive information types (e.g., credit card numbers, social security numbers) and can trigger a real-time block action, such as rejecting or quarantining the message before it reaches the recipient. DLP also surfaces policy tips in Outlook to notify users that their message violates a policy, giving them a chance to modify or resend it. This proactive, content-aware enforcement is exactly what the compliance officer needs.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to detect sensitive information, such as social security numbers, in emails and enforce actions like blocking the message and displaying a policy tip. This meets the compliance officer's requirement to prevent external sending of sensitive data while providing user notification.

Exam trap

Microsoft often tests the distinction between DLP (which can block and notify in real-time) and sensitivity labels (which apply protection but do not block sending based on content detection), leading candidates to confuse classification with enforcement.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data through encryption and visual markings but do not natively block outbound emails based on content detection or display policy tips. Option C is wrong because communication compliance focuses on monitoring and reviewing internal/external communications for policy violations (e.g., harassment or insider trading) rather than real-time blocking of specific sensitive data patterns. Option D is wrong because eDiscovery is used for searching and exporting content for legal or investigative purposes, not for preventing data exfiltration or enforcing real-time email restrictions.

34
MCQmedium

You are a compliance administrator for Fabrikam Inc. The company uses Microsoft Purview Information Barriers. You need to prevent users in the Sales department from communicating with users in the Research department in Microsoft Teams. However, both departments must be able to communicate with the Legal department. What should you do first?

A.Create a DLP policy that blocks Teams messages between Sales and Research.
B.Create an information barrier segment for each department and define blocked and allowed communication policies between them.
C.Assign sensitivity labels to users in Sales and Research to prevent collaboration.
D.Configure a Teams messaging policy that disables chat for the Sales and Research departments.
AnswerB

Information barriers use segments to group users and policies to define allowed or blocked communication between segments. You must first create segments for Sales, Research, and Legal, then define policies that block Sales-Research and allow Sales-Legal and Research-Legal. This is the foundational step to enforce the restriction.

Why this answer

Information barriers are the correct feature to restrict communication between specific groups in Microsoft Teams. The first step is to create segments for each department, then define policies that specify which segments can communicate. This allows blocking Sales-Research while permitting both to communicate with Legal.

Exam trap

The trap here is assuming DLP or Teams messaging policies can enforce ethical walls, when information barriers are the purpose-built solution.

35
MCQeasy

You are a compliance administrator. You need to search for emails that contain trade secrets sent by a specific user in the last month. The search must include all mailboxes. What should you use?

A.eDiscovery (Premium) case.
B.Data Loss Prevention reports.
C.Audit log search.
D.Content search in Microsoft Purview.
AnswerD

Content search in Microsoft Purview is the correct tool because it performs a full-text query across all Exchange Online mailboxes using a KQL query. You can combine keywords such as "confidential" with date filters like "sent >= 01/01/2024" to find messages containing the specified text, and you can include inactive mailboxes and public folders. It directly meets the requirement to search for specific keywords inside emails, not merely metadata about them.

Why this answer

Content search in Microsoft Purview allows searching across all mailboxes for specific keywords and date ranges, making it the appropriate tool to find emails containing trade secrets from a specific user in the last month. Option D is correct. Option A is wrong because eDiscovery (Premium) is designed for complex legal workflows and not for basic content search.

Option B is wrong because Audit log search tracks user and admin activities, not email content. Option C is wrong because Data Loss Prevention (DLP) reports show policy matches and alerts, but do not allow searching across mailbox content for specific keywords.

36
MCQeasy

A compliance officer needs to identify documents in SharePoint Online that contain confidential business information by using a machine learning model. Which Microsoft Purview solution should be configured?

A.A: Data Lifecycle Management
B.B: Information Protection (trainable classifiers)
C.C: eDiscovery
D.D: Communication Compliance
AnswerB

Information Protection's trainable classifiers are machine learning models that learn to recognize specific content patterns from seed documents and then automatically classify SharePoint documents. Once trained, these classifiers can drive sensitivity labels, retention labels, or communication compliance policies, enabling automatic identification without manual scanning. This is the correct approach because the compliance officer needs to identify documents based on content, and trainable classifiers are purpose-built for that.

Why this answer

Trainable classifiers in Microsoft Purview Information Protection use machine learning models to identify documents containing sensitive or confidential business information based on content patterns and context. Unlike simple keyword matching, trainable classifiers learn from sample documents to accurately detect specific types of confidential data, such as intellectual property or financial reports, in SharePoint Online.

Exam trap

The trap here is that candidates often confuse trainable classifiers with simple keyword-based sensitivity labels or DLP policies, but the question specifically requires a machine learning model, which only trainable classifiers provide.

How to eliminate wrong answers

Option A is wrong because Data Lifecycle Management focuses on retention and deletion policies for data governance, not on identifying confidential content via machine learning. Option C is wrong because eDiscovery is designed for legal discovery and search of content for litigation or investigation, not for proactive classification using ML models. Option D is wrong because Communication Compliance monitors communications (e.g., email, Teams) for policy violations like harassment or insider trading, not for identifying confidential business documents in SharePoint.

37
MCQmedium

A compliance officer needs to automatically apply a sensitivity label named 'Confidential' to documents stored in SharePoint Online whenever the documents contain social security numbers. Users must be prevented from removing the label. Which configuration should the officer implement?

A.Create a retention label with auto-labeling based on sensitive info types
B.Create a sensitivity label with auto-labeling and set 'Require justification to remove the label'
C.Use Microsoft Information Protection (MIP) unified labeling client to apply labels
D.Configure Data Loss Prevention (DLP) policy to apply the label
AnswerB

Sensitivity labels with auto-labeling can apply the label automatically based on sensitive info types. However, to prevent users from removing the label, you must configure advanced protection settings (e.g., require justification to remove the label) rather than just 'Mark content as mandatory', which only requires a label to be present. Despite the inaccurate setting name, the correct concept is using sensitivity labels with appropriate protection settings.

Why this answer

Sensitivity labels support auto-labeling based on sensitive info types (e.g., social security numbers). To prevent users from removing the label, configure the label policy setting 'Require justification to remove a label or lower classification label'. Option B correctly combines auto-labeling with this protection setting.

Retention labels (A) manage lifecycle, the MIP unified labeling client (C) is outdated, and DLP policies (D) can apply labels but do not inherently prevent label removal.

Exam trap

The trap is confusing 'Mark content as mandatory' (which requires a label but does not prevent removal) with the protection setting that restricts removal, such as 'Require justification to remove a label or lower classification label'. The correct answer uses sensitivity label auto-labeling with that protective setting.

How to eliminate wrong answers

Option A is wrong because retention labels are designed for data retention and deletion policies, not for classification or protection; they cannot apply sensitivity labels or prevent removal. Option C is wrong because the MIP unified labeling client is a legacy tool for on-premises or hybrid scenarios, not for cloud-native auto-labeling in SharePoint Online; it also does not enforce mandatory labeling. Option D is wrong because DLP policies can detect sensitive data and trigger actions like blocking or notification, but they cannot directly apply sensitivity labels; they rely on labels already being present.

38
MCQmedium

Refer to the exhibit. You run the Get-RetentionCompliancePolicy cmdlet and see the output. Your organization wants to retain all ProjectX documents for 10 years and then allow users to delete them. However, users complain that documents are being deleted automatically. What is the issue?

A.The retention action is set to Delete instead of NoAction.
B.The policy is disabled, so it should not be enforcing.
C.The mode is set to Enable, which means the policy is in test mode.
D.The retention trigger is set to DateCreated, which is incorrect.
AnswerB

The policy is disabled, so it should not be causing automatic deletion. This is the correct identification of the issue as stated.

Why this answer

The policy is disabled (Enabled: False), so it is not enforcing any retention or deletion actions. However, users are complaining that documents are being deleted automatically, which cannot be caused by this disabled policy. The issue is likely another policy or process.

Option A is incorrect because even if the retention action is 'Delete', it has no effect since the policy is disabled. Option C is incorrect because Mode 'Enable' means the policy is active when enabled, but since it is disabled, mode is irrelevant. Option D is incorrect because 'DateCreated' is a valid retention trigger.

39
MCQeasy

Your organization needs to implement a Microsoft Purview data classification solution that scans data in Microsoft 365, Azure SQL Database, and Amazon S3. Which Microsoft Purview feature should you use?

A.Microsoft Purview Data Loss Prevention
B.Microsoft Purview Information Protection sensitivity labels
C.Microsoft Purview eDiscovery
D.Microsoft Purview Data Map
AnswerD

Microsoft Purview Data Map is the unified metadata backbone that discovers, classifies, and maps data across Microsoft 365, Azure SQL Database, and Amazon S3. It satisfies the multi-source scanning requirement by providing a single catalogue spanning on-premises, multicloud, and SaaS sources.

Why this answer

Microsoft Purview Data Map is the foundational metadata and scanning service that discovers and classifies data across sources including Microsoft 365, Azure SQL Database, and Amazon S3. It registers sources, runs scans, applies classification rules, and builds the data estate catalog that other Purview solutions consume. Because the requirement spans multi-cloud and on-prem sources, the Data Map is the correct feature.

Exam trap

MS-102 often tests the confusion between Data Map (discovery/catalog) and Information Protection (labeling/enforcement), so candidates pick labels when the scenario is really about multi-source scanning.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention enforces policies on data in motion/use within supported workloads and does not scan Amazon S3 or build a cross-cloud catalog. Option B is wrong because sensitivity labels classify and protect content primarily in Microsoft 365 and supported apps, not arbitrary external sources like S3. Option C is wrong because eDiscovery is a legal/HR workflow for identifying and preserving content for litigation, not a data classification scanning engine.

40
Multi-Selectmedium

Your company is implementing Microsoft Purview Information Protection to classify and protect sensitive documents. You need to ensure that all documents containing personally identifiable information (PII) are automatically labeled. Which TWO actions should you take? (Select TWO.)

Select 2 answers
A.Define a custom sensitive info type in Microsoft Purview that matches your organization's PII patterns.
B.Train users to manually apply a sensitivity label to documents containing PII.
C.Configure a sensitivity label to encrypt documents containing PII.
D.Create a retention label for documents containing PII.
E.Create an auto-labeling policy in Microsoft Purview that applies a sensitivity label to documents containing PII.
AnswersA, E

A custom sensitive info type defines the regex, keyword list and confidence level matching your organisation's specific PII formats, which built-in types may miss. Auto-labeling policies then reference this type, satisfying the requirement that all PII-containing documents are detected accurately.

Why this answer

Option A is correct because defining a custom sensitive information type in Microsoft Purview lets you match your organization's specific PII patterns (for example, using regular expressions, keywords, and confidence levels) so that the classification engine can reliably detect the PII unique to your environment. Option E is correct because an auto-labeling policy in Microsoft Purview is the mechanism that automatically applies a sensitivity label to documents that match sensitive information types, which is exactly what is required to label PII-containing documents without user intervention. Option B is incorrect because training users to apply labels manually does not provide the automatic labeling the scenario requires.

Option C is incorrect because configuring a sensitivity label to encrypt documents only defines the protection action of a label; by itself it does not automatically detect or label PII content. Option D is incorrect because a retention label governs how long content is kept or deleted, not how it is classified and protected for PII.

Exam trap

MS-102 often tests the pairing of a sensitive info type with an auto-labeling policy — candidates pick encryption or retention labels thinking those achieve automatic classification, but only auto-labeling policies apply sensitivity labels based on content detection.

41
MCQmedium

A compliance officer needs to automatically retain documents in a SharePoint Online document library for 7 years and then automatically delete them. The retention must be applied based on when the document is created. Which Microsoft Purview feature should be configured?

A.Data Lifecycle Management
B.Records Management
C.eDiscovery
D.Communication Compliance
AnswerA

Data Lifecycle Management in Microsoft Purview is the solution specifically built to automate retention and deletion based on configured policies. It uses retention labels and policies to apply rules like 'retain for 7 years then delete' triggered by content age or events. This lets you meet compliance obligations without manual intervention, making it the correct choice for automatically retaining documents.

Why this answer

Data Lifecycle Management (DLM) in Microsoft Purview allows you to create retention labels that automatically retain content for a specified period (e.g., 7 years) based on the date the document was created, and then trigger a disposal action such as deletion. This feature is designed specifically for managing the lifecycle of data in SharePoint Online, including automatic retention and deletion based on metadata like creation date.

Exam trap

The trap here is that candidates often confuse Records Management with Data Lifecycle Management, assuming that any retention policy must involve records, when in fact DLM handles automated retention and deletion without requiring the content to be declared a record.

How to eliminate wrong answers

Option B (Records Management) is wrong because Records Management is focused on declaring content as records (immutable, auditable) and applying retention that prevents deletion or modification, not on automatically deleting content after a set period. Option C (eDiscovery) is wrong because eDiscovery is used for searching, holding, and exporting content for legal or investigative purposes, not for automated retention and deletion policies. Option D (Communication Compliance) is wrong because Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, sensitive info) in Microsoft Teams, Exchange, and Yammer, not for managing document lifecycle retention or deletion.

42
MCQmedium

Your organization receives a data subject request (DSR) to export personal data of a user. Which Microsoft Purview solution should you use to search for and export the data?

A.Microsoft Purview retention policies
B.Microsoft Purview Audit
C.Microsoft Purview eDiscovery
D.Microsoft Purview Data Loss Prevention
AnswerC

Microsoft Purview eDiscovery supports searching across Microsoft 365 content and exporting results, matching the requirement to locate and export a user's personal data for a DSR. It provides the case-based search, hold and export capabilities that DSR fulfilment demands.

Why this answer

Microsoft Purview eDiscovery allows you to search for content across Microsoft 365 and export it, which is necessary to fulfill a data subject request (DSR) to export personal data. Option A is incorrect because retention policies are used to retain data for a specified period, not to export it. Option B is incorrect because audit logs track activities but do not provide content search or export capabilities.

Option D is incorrect because Data Loss Prevention (DLP) is designed to prevent data leaks, not to export data.

43
Multi-Selecthard

A compliance officer needs to ensure that all documents containing a custom sensitive info type (Employee ID with pattern EMP-####) are automatically labeled with a retention label that retains the documents for 3 years. Which two Microsoft Purview components must be configured? (Choose two.)

Select 2 answers
A.sensitivity label
B.retention label
C.data loss prevention (DLP) policy
D.An auto-labeling policy for retention labels
AnswersB, D

A retention label defines the retention and deletion rules for content at a granular level, such as preserving documents for a specific number of days, years, or permanently. You can apply it manually to individual items or through auto-labeling policies, and it triggers a retention period that cannot be overridden by users. For the compliance officer's requirement to manage document retention, this is the direct and authoritative mechanism.

Why this answer

A retention label is required to specify the retention period (3 years) for the documents. An auto-labeling policy for retention labels is needed to automatically apply that retention label based on the detection of the custom sensitive info type (Employee ID pattern EMP-####). Together, these two components enable automatic classification and retention without manual user intervention.

Exam trap

The trap here is that candidates often confuse sensitivity labels with retention labels, or think a DLP policy can apply retention labels, but Microsoft Purview separates these functions: DLP controls data movement, while auto-labeling policies for retention labels handle automatic retention label assignment.

44
MCQmedium

The legal department is investigating a potential data breach involving a specific user. The compliance officer needs to place a hold on all content in the user's Exchange Online mailbox and OneDrive for Business to prevent deletion until the investigation is complete. Which Microsoft Purview solution should the officer use?

A.Content Search
B.eDiscovery (Standard)
C.eDiscovery (Premium)
D.Audit log
AnswerB

eDiscovery (Standard), also known as eDiscovery in the classic compliance center, is a case-based workflow that allows you to create a case and then place legal holds on specific content locations, including Exchange mailboxes, OneDrive for Business sites, SharePoint sites, and Teams. These holds preserve data in full fidelity, preventing users from permanently deleting or modifying content, even if retention policies are not configured. For a data breach investigation, creating an eDiscovery (Standard) case and applying a hold is the correct, cost-effective method to ensure the relevant content remains intact while you search and analyze it.

Why this answer

eDiscovery (Standard) allows you to place a hold on Exchange Online mailboxes and OneDrive for Business sites to preserve content from deletion during an investigation. This hold prevents users and automated processes from permanently deleting items, ensuring data integrity for legal or compliance reviews.

Exam trap

The trap here is that candidates often confuse the search-only capability of Content Search with the preservation functionality of eDiscovery (Standard), or mistakenly think eDiscovery (Premium) is required for holds, when in fact holds are a standard feature of eDiscovery (Standard).

How to eliminate wrong answers

Option A is wrong because Content Search is used to search for content across Microsoft 365 but cannot place a hold to preserve data; it only returns search results. Option C is wrong because eDiscovery (Premium) extends eDiscovery (Standard) with advanced analytics and review sets, but placing a hold is a core feature of eDiscovery (Standard) and does not require Premium. Option D is wrong because Audit log records user and admin activities for forensic analysis but does not prevent deletion of content; it only logs what happened.

45
Multi-Selectmedium

Your organization uses Microsoft Purview Compliance Manager to manage compliance activities. Which TWO actions can be performed directly from Compliance Manager?

Select 2 answers
A.Assign an improvement action to a user.
B.Upload evidence for an improvement action.
C.View and manage DLP alerts.
D.Create a retention policy for Exchange Online.
E.Create a sensitivity label.
AnswersA, B

Assigning an improvement action to a user is a core function inside Compliance Manager. Every improvement action has an owner field, and you can set that owner directly from the action's details page to assign responsibility. This ensures accountability for specific regulatory controls and enables tracking of implementation status within the compliance scoring workflow.

Why this answer

Compliance Manager is a solution within Microsoft Purview that provides a centralized dashboard for managing compliance activities. It allows you to assign improvement actions to specific users to track responsibility and progress, and to upload evidence files directly to an improvement action to demonstrate compliance with a control. These are core, direct functions of the Compliance Manager interface.

Exam trap

The trap here is that candidates confuse the Microsoft Purview compliance portal's overall capabilities with the specific, limited set of actions that can be performed directly within the Compliance Manager solution, leading them to select actions that are available elsewhere in the portal but not inside Compliance Manager.

46
MCQeasy

Your company is implementing Microsoft Purview Audit (Standard). You need to search for activities performed by a specific user in Exchange Online. Which log should you query?

A.Unified audit log.
B.DLP incident reports.
C.Azure AD audit logs.
D.Mailbox audit logs only.
AnswerA

Purview Audit (Standard) writes Exchange Online activities to the unified audit log, which is the only searchable repository for user-level events in Microsoft 365. Querying it satisfies the requirement to find activities performed by a specific user, since mailbox audit records surface there rather than in transport or IIS logs.

Why this answer

Microsoft Purview Audit (Standard) stores all audit events — including Exchange Online user activities — in the Unified audit log, which is queried via the Microsoft Purview compliance portal or the Search-UnifiedAuditLog PowerShell cmdlet. To find activities performed by a specific user in Exchange Online, you search the Unified audit log and filter by the user's UPN and the relevant Exchange workloads/activities. This is the single centralized log for Purview Audit (Standard) across Microsoft 365 services.

Exam trap

MS-102 often tests the misconception that mailbox audit logs and the Unified audit log are separate query targets in Purview Audit (Standard) — in fact, Exchange Online activities are surfaced through the Unified audit log, and 'mailbox audit logs only' is a distractor that misrepresents the architecture.

How to eliminate wrong answers

Option B (DLP incident reports) is wrong because DLP incident reports only surface data-loss-prevention policy matches, not general user activity auditing. Option C (Azure AD audit logs) is wrong because Azure AD (Entra ID) audit logs capture identity and directory events (sign-ins, role changes, app consents), not Exchange Online mailbox activities. Option D (Mailbox audit logs only) is wrong because mailbox audit logs are the legacy per-mailbox auditing mechanism; in Purview Audit (Standard), mailbox activities are surfaced through the Unified audit log, and 'only' makes the option incorrect as a query target.

47
MCQmedium

Refer to the exhibit. You run the PowerShell command shown. The output shows no results. The user confirms they downloaded files from SharePoint last week. What is the most likely cause?

A.The UserIds parameter is misspelled.
B.The RecordType parameter is incorrect.
C.Audit logging is not enabled for the user.
D.The Operations parameter is incorrect.
AnswerC

The unified audit log contains no eligible events for this search if audit logging is not enabled for the user, even when every command parameter is correct. In Microsoft 365, user activities such as FileDownloaded are published to the audit log only when auditing is enabled at the tenant level and the user has the required license. Because the command itself is valid, the empty output indicates that audit events were never generated for this user, not that the syntax is flawed.

Why this answer

The PowerShell command shown is likely Search-UnifiedAuditLog, which queries the unified audit log. If the output is empty despite the user having downloaded files from SharePoint, the most likely cause is that audit logging (specifically, mailbox or SharePoint audit logging) is not enabled for that user or workload. Without audit logging turned on, no events are recorded, so the search returns nothing.

Exam trap

The trap is assuming that an empty audit log search means no activity occurred, when it often means audit logging was never enabled or the events have not yet been ingested.

How to eliminate wrong answers

Option A is wrong because a misspelled UserIds parameter would typically cause a syntax error or an error message, not a silent empty result, and the user ID is usually valid. Option B is wrong because RecordType for SharePoint file downloads would be SharePointFileOperation, and if it were incorrect, the command might return other record types or an error, but the scenario implies no results at all. Option D is wrong because an incorrect Operations parameter would filter out events, but the more fundamental issue is that no events exist because auditing is disabled.

48
MCQmedium

Your organization uses Microsoft Purview Records Management and has a file plan that categorizes records by department. You need to ensure that HR records are retained for seven years after employee termination, while finance records are retained for ten years after the end of the fiscal year. What is the most efficient way to implement this?

A.Create a single retention label with a trigger event and adjust the retention period using PowerShell.
B.Create two retention labels: one for HR with termination trigger and seven-year retention, and one for Finance with end-of-fiscal-year trigger and ten-year retention.
C.Define the retention settings in the file plan and apply them to both departments.
D.Create two retention policies, one for HR and one for Finance, each with the appropriate retention period.
AnswerB

Retention labels support event-based triggers, letting HR use a termination trigger and Finance an end-of-fiscal-year trigger, each with its own retention period. Two labels satisfy both departmental rules within one file plan, avoiding separate policies per department.

Why this answer

Retention labels in Microsoft Purview Records Management support event-based retention triggers, and each label can have its own retention period and trigger type. Creating one label for HR with a termination trigger and seven-year retention, and another for Finance with an end-of-fiscal-year trigger and ten-year retention, directly maps to the two distinct business requirements. Labels are the correct construct for file-plan-based records management because they can be published to specific locations and applied per-item.

Exam trap

MS-102 often tests the distinction between retention policies (location-wide, no event triggers) and retention labels (item-level, support event-based triggers) — candidates pick policies because they sound simpler, missing that event-based retention requires labels.

How to eliminate wrong answers

Option A is wrong because a single retention label cannot have two different trigger events and two different retention periods — a label has one retention configuration, so this cannot satisfy both HR and Finance requirements. Option C is wrong because the file plan is a container for organizing labels, not a place to define per-department retention settings; retention settings live on the labels themselves. Option D is wrong because retention policies apply uniformly to a location (e.g., all Exchange mailboxes) and do not support event-based triggers like employee termination or end-of-fiscal-year — those triggers require retention labels, not policies.

49
MCQeasy

Your organization needs to ensure that all emails containing credit card numbers are automatically encrypted before being sent to external recipients. Which Microsoft Purview solution should you configure?

A.Configure a DLP policy that uses the 'Encrypt email messages' action.
B.Create a sensitivity label that applies encryption and auto-labeling.
C.Set up a retention policy with encryption.
D.Implement a Communication Compliance policy.
AnswerA

DLP policies in Microsoft Purview can be configured with the action 'Encrypt email messages' to automatically apply IRM (Azure RMS) protection to any outbound email that matches a sensitive info type condition. This action uses the built-in encryption template and does not require a separate label to be defined. When an email triggers a DLP rule, the message is encrypted in transit and at rest, enforcing access controls before delivery.

Why this answer

A Microsoft Purview DLP policy can detect sensitive information types like credit card numbers (via the Credit Card Number SIT) and apply the 'Encrypt email messages' action, which uses Office 365 Message Encryption (OME) to encrypt the email before it leaves the organization. This directly satisfies the requirement to automatically encrypt emails containing credit card numbers sent to external recipients. DLP policies are evaluated at send time and can enforce encryption without user intervention.

Exam trap

MS-102 often tests the distinction between DLP and sensitivity labels; candidates pick sensitivity labels because they also encrypt, but DLP is the correct tool for automatic, content-based encryption of emails containing specific sensitive data.

How to eliminate wrong answers

Option B is wrong because sensitivity labels with auto-labeling can apply encryption, but they are primarily designed for classification and protection of content at rest and in transit; they do not automatically trigger based on sensitive content detection in the same way DLP does, and auto-labeling for email encryption based on SITs is less direct than a DLP rule. Option C is wrong because retention policies govern data lifecycle and deletion, not encryption. Option D is wrong because Communication Compliance policies are for detecting and reviewing inappropriate or risky communications (e.g., harassment, regulatory violations) and do not encrypt emails.

50
MCQmedium

A company must ensure that all outgoing emails containing credit card numbers are blocked from being sent to external recipients. When a user attempts to send such an email, it should be blocked immediately, and the user should see a policy tip explaining the rule. Which Microsoft Purview solution should the administrator configure?

A.Data Loss Prevention (DLP) policy
B.Sensitivity labels
C.Retention labels
D.Communication compliance
AnswerA

DLP policies inspect outbound email content in Exchange Online and block messages containing sensitive data such as credit card numbers, satisfying the immediate-blocking requirement. Policy tips display in Outlook, giving the sender the required explanation of why the message was stopped.

Why this answer

A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information, such as credit card numbers, in transit (email) and enforce real-time actions like blocking the message and displaying a policy tip to the user. DLP policies in Microsoft Purview can be configured with conditions that match credit card number patterns using built-in sensitive info types, and the action 'Block messages' with a policy tip notification is available for Exchange Online mail flow. This ensures immediate blocking and user notification without requiring any manual labeling or classification.

Exam trap

The trap here is that candidates often confuse sensitivity labels with DLP because both involve 'protection,' but sensitivity labels require manual or automatic classification and do not perform real-time content inspection or blocking of outbound emails based on sensitive data patterns.

How to eliminate wrong answers

Option B is wrong because sensitivity labels are used to classify and protect data at rest (e.g., documents and emails) by applying encryption or visual markings, but they do not natively detect credit card numbers in real-time during email transmission or enforce blocking with policy tips. Option C is wrong because retention labels are designed to manage data lifecycle and retention policies (e.g., how long to keep or delete data), not to inspect email content for sensitive information or block outbound messages. Option D is wrong because communication compliance is focused on monitoring and reviewing internal and external communications for policy violations (e.g., harassment or insider trading), but it does not provide real-time blocking of emails based on sensitive data patterns or display policy tips to users.

51
MCQmedium

A compliance officer needs to prevent users from sharing confidential documents with external users outside the organization. The policy should block sharing via email attachments or sharing links from SharePoint Online. Which Microsoft Purview solution should be configured?

A.Sensitivity labels
B.Data Loss Prevention (DLP)
C.Retention policies
D.Information barriers
AnswerB

DLP policies are the correct technical control because they can identify sensitive information in messages and files and automatically block specific actions such as sending an external email or creating an external sharing link in SharePoint and OneDrive. When a rule is triggered, DLP can block the activity outright, show a policy tip, or require a user to justify an override, giving compliance officers a real-time enforcement mechanism. DLP works across Exchange, SharePoint, OneDrive, Teams, and endpoints, making it the only option listed that explicitly prevents the sharing of sensitive content.

Why this answer

Data Loss Prevention (DLP) in Microsoft Purview is designed to identify, monitor, and automatically protect sensitive information across Exchange Online, SharePoint Online, and OneDrive for Business. By creating a DLP policy with a rule that blocks sharing of confidential documents via email attachments or sharing links to external users, the compliance officer can enforce the required restriction. DLP policies can inspect content for sensitive data types (e.g., credit card numbers, custom confidential labels) and apply actions such as blocking the sharing action or sending a notification.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which apply protection) with DLP policies (which enforce actions like blocking), leading them to choose Option A, but labels alone cannot block sharing; they require a DLP policy to enforce the block action.

How to eliminate wrong answers

Option A is wrong because sensitivity labels are used to classify and protect data by applying encryption, markings, or access restrictions, but they do not natively block sharing actions based on external user detection; DLP policies are required to enforce such blocking rules. Option C is wrong because retention policies are designed to preserve or delete content after a specified period, not to prevent real-time sharing of documents with external users. Option D is wrong because information barriers restrict communication and collaboration between specific internal groups or users (e.g., to avoid conflicts of interest), but they do not block sharing with external users outside the organization.

52
MCQeasy

Your organization needs to automatically detect and classify documents containing passport numbers in SharePoint Online. Which Microsoft Purview feature should you use?

A.eDiscovery (Premium).
B.Auto-labeling with sensitivity labels.
C.Data Lifecycle Management (DLM) policy.
D.Data Loss Prevention (DLP) policy.
AnswerB

Auto-labelling with sensitivity labels applies trainable classifiers and sensitive information types during scanning, so passport numbers are detected and classified without user input. This satisfies the requirement for automatic detection in SharePoint Online, unlike manual labelling or purely client-side classification.

Why this answer

Auto-labeling with sensitivity labels in Microsoft Purview can automatically detect sensitive content such as passport numbers using built-in or custom sensitive information types (SITs) and then apply a sensitivity label to the document. This is the only feature among the options designed to both detect and classify (label) content at scale in SharePoint Online. The label can then drive encryption, retention, and other protections.

Exam trap

MS-102 often tests the confusion between DLP (which takes protective actions like blocking) and auto-labeling (which classifies content with sensitivity labels); candidates frequently pick DLP when the requirement is to classify.

How to eliminate wrong answers

Option A is wrong because eDiscovery (Premium) is used for identifying, preserving, collecting, and reviewing content for legal or investigative purposes, not for automatically classifying documents with sensitivity labels. Option C is wrong because Data Lifecycle Management (DLM) policies govern retention and deletion of content, not detection and classification of sensitive data. Option D is wrong because DLP policies detect sensitive content and can block or warn on sharing, but they do not apply sensitivity labels to classify documents.

53
MCQhard

Your organization uses Microsoft Purview Compliance Manager. You need to assign a control to a specific user for implementation. What should you do?

A.Assign the user the Compliance Manager role.
B.Edit the control and assign a new owner.
C.Create a DLP policy to enforce the control.
D.Modify the assessment to include the user.
AnswerB

Editing the control lets you set a new owner, which is exactly how Compliance Manager delegates implementation responsibility. Ownership assignment sits on the control itself, not on assessments or improvement actions, so reassigning the owner directly satisfies the requirement to make one named user accountable for that control.

Why this answer

In Microsoft Purview Compliance Manager, each control within an assessment has an 'Assigned to' field that designates the individual responsible for implementing and documenting that control. Editing the control and assigning a new owner is the correct way to delegate accountability for a specific control to a user. This assignment is purely for tracking and workflow purposes and does not grant any permissions to the user.

Exam trap

MS-102 often tests the confusion between assigning a role (which grants permissions) and assigning a control owner (which assigns accountability) — candidates incorrectly pick the role option thinking it delegates the control.

How to eliminate wrong answers

Option A is wrong because the Compliance Manager role grants access to the Compliance Manager solution itself, not ownership of a specific control; role assignment and control ownership are separate concepts. Option C is wrong because DLP policies enforce data-handling rules on content and have nothing to do with assigning control ownership in Compliance Manager. Option D is wrong because modifying the assessment changes the scope of controls being evaluated, not who is responsible for a particular control.

54
MCQmedium

An organization is involved in litigation and needs to search for all communications containing a specific keyword across Exchange Online, SharePoint Online, and OneDrive for Business. The results must be preserved as evidence without allowing deletion. Which Microsoft Purview solution should the compliance officer use?

A.Data Loss Prevention
B.eDiscovery (Premium)
C.Communication Compliance
D.Retention Labels
AnswerB

eDiscovery (Premium) is the Microsoft 365 workload designed for legal discovery: it uses a single search index across Exchange Online, SharePoint Online, OneDrive, and Teams, allowing keywords, conditional operators, and custodian-based collection. It can place a legal hold on matched content, making it immutable and preserving all versions and metadata until released. Review sets then provide advanced analytics, redaction, tagging, and export for litigation workflows, so it directly answers the need to search and preserve.

Why this answer

eDiscovery (Premium) is the correct solution because it provides end-to-end workflow for identifying, preserving, collecting, reviewing, and exporting content across Exchange Online, SharePoint Online, and OneDrive for Business. It supports legal hold to preserve data in-place, preventing deletion or alteration, and can search all communications for specific keywords using advanced query capabilities.

Exam trap

The trap here is that candidates often confuse eDiscovery (Premium) with Retention Labels or Communication Compliance because all three involve content management, but only eDiscovery (Premium) provides the legal hold and cross-workload search capabilities required for litigation evidence preservation.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) is designed to prevent accidental sharing of sensitive data through policies and alerts, not to search, preserve, or hold content for litigation. Option C is wrong because Communication Compliance focuses on monitoring and detecting policy violations (e.g., harassment, insider trading) in communications, not on preserving evidence or placing legal holds. Option D is wrong because Retention Labels are used to classify and apply retention or deletion rules to content, but they do not provide the search, hold, or export capabilities required for litigation discovery.

55
Multi-Selecthard

A compliance officer needs to automatically apply a sensitivity label to all documents in SharePoint Online that contain a credit card number. The label must mark the document as 'Confidential' and encrypt it. Which two Microsoft Purview components must be configured to achieve automatic labeling based on sensitive content? (Choose two.)

Select 2 answers
A.Sensitivity label
B.Auto-labeling policy
C.Data Loss Prevention (DLP) policy
D.Retention label policy
AnswersA, B

A sensitivity label is the actual content-classification construct that carries the required protection settings, such as 'Confidential' with encryption, in Microsoft Purview. Creating the label is mandatory because the auto-labeling policy can only reference an existing label and apply it to content. Therefore, the correct answer to 'automatically apply a sensitivity label' includes provisioning this label with the desired encryption and permissions.

Why this answer

Sensitivity labels define the classification and protection settings (e.g., 'Confidential' marking and encryption). Auto-labeling policies automatically apply those labels to documents containing sensitive information types, such as credit card numbers, without requiring user intervention. Together, they enable automatic labeling based on sensitive content in SharePoint Online.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling policies, but DLP policies only monitor and block data movement, while auto-labeling policies are the correct mechanism to automatically apply sensitivity labels based on content detection.

56
MCQeasy

A compliance officer needs to mark documents in a SharePoint Online library as regulatory records. These records must be immutable (cannot be modified or deleted) for 3 years. After 3 years, a disposition review must be initiated to decide if the records can be deleted. Which Microsoft Purview solution should the officer configure?

A.Retention label configured to mark items as records with a retention period of 3 years and disposition review
B.Data Lifecycle Management retention policy with disposition review
C.Sensitivity label with encryption
D.eDiscovery case with hold
AnswerA

This configuration directly fulfills both requirements. Applying the label marks each SharePoint item as a record, which makes the content immutable so it cannot be edited or deleted by users, and the 3-year retention period starts when the item is labeled. At the end of the period, disposition review requires a designated reviewer to approve deletion, providing a controlled, auditable end-of-life process. This is the standard way in Microsoft 365 to enforce record classification and scheduled disposition on individual documents.

Why this answer

A retention label configured to mark items as regulatory records enforces immutability (no modification or deletion) for the specified retention period of 3 years. After the retention period expires, the disposition review triggers a workflow where a reviewer must approve or reject deletion, meeting the compliance officer's requirement exactly.

Exam trap

The trap here is that candidates often confuse retention policies (which apply broadly to containers) with retention labels (which apply granularly to items and support regulatory records and disposition reviews), leading them to choose Option B incorrectly.

How to eliminate wrong answers

Option B is wrong because Data Lifecycle Management retention policies apply at the container level (site or library) and cannot mark individual items as regulatory records; they also do not support disposition review after the retention period. Option C is wrong because sensitivity labels with encryption protect content via access controls and encryption, but they do not enforce immutability or a retention period with disposition review. Option D is wrong because an eDiscovery case with hold preserves content for legal purposes but does not enforce a fixed retention period or trigger a disposition review; it is designed for litigation holds, not regulatory record management.

57
MCQmedium

A compliance administrator needs to automatically apply a retention label to all documents in a SharePoint Online site that contain Social Security numbers. The label should retain the documents for 5 years and then automatically delete them. Which feature should they configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label with auto-labeling
C.retention label with auto-labeling
D.An information barrier policy
AnswerC

Auto-labeling retention labels use sensitive information types, such as Social Security numbers, to detect matching content and apply the label automatically. The label's retention settings then retain documents for five years before deleting them, meeting both requirements.

Why this answer

Retention labels with auto-labeling are designed to automatically apply retention settings based on sensitive information types, such as Social Security numbers, and can enforce a retention period (5 years) followed by automatic deletion. This feature is part of Microsoft Purview's records management and uses trainable classifiers or sensitive info types to trigger the label assignment on SharePoint Online documents.

Exam trap

The trap here is that candidates confuse DLP policies (which detect and protect) with retention labels (which manage lifecycle), leading them to choose Option A because both involve sensitive data detection, but only retention labels can enforce deletion after a set period.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy detects and protects sensitive data but does not apply retention labels or manage lifecycle actions like retention and deletion; DLP policies block or warn, not retain. Option B is wrong because sensitivity labels with auto-labeling focus on classification and protection (encryption, markings) rather than retention and deletion schedules; they do not enforce a 5-year retention followed by automatic deletion. Option D is wrong because an information barrier policy restricts communication and collaboration between groups, not document lifecycle management or retention labeling.

58
MCQhard

Your company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. Users are sharing credit card numbers in Teams chat messages. You have a DLP policy that detects credit card numbers and blocks the message. However, users report that they can still send messages containing credit card numbers without any block. What is the most likely reason?

A.The DLP policy for Teams is only applied when external users are part of the chat.
B.The DLP policy does not apply to transient messages like chat.
C.The DLP policy is not configured to include the users' group.
D.The DLP policy only applies to channel messages, not private chats.
AnswerA

Microsoft Purview DLP policies for Teams chats are often configured with a scope that specifically targets communications involving external participants. If the policy's application is limited to chats where external users are present, then internal-only Teams conversations would fall outside its enforcement scope. This explains why users can still send messages containing credit card numbers without being blocked in internal chats, directly addressing the scenario where the policy is not effective.

Why this answer

DLP for Teams chat messages only scans messages that include at least one user from outside the organization (external users). If both sender and recipient are internal, the policy does not apply. Option B is incorrect because DLP policies can be scoped to specific users.

Option C is incorrect because Teams DLP policies cover both chat and channel messages. Option D is incorrect because DLP policies apply to both persistent and transient messages.

59
MCQhard

Your company uses Microsoft Purview Data Lifecycle Management. You have a policy that retains items for 3 years and then deletes them. A user places an eDiscovery hold on a folder that contains items subject to this policy. What happens to those items after 3 years?

A.They are retained for an additional 3 years.
B.They are deleted after 3 years.
C.They are preserved until the hold is removed.
D.They are moved to a separate location.
AnswerC

An eDiscovery hold overrides the retention policy's deletion action, so items are kept rather than removed at three years. Preservation continues until the hold is released, satisfying the hold's requirement to retain potentially relevant content.

Why this answer

eDiscovery hold takes precedence over the deletion policy. Items under a hold are preserved indefinitely until the hold is removed, regardless of any retention and deletion policies. Option C correctly states they are preserved until the hold is removed.

Option A is incorrect because hold overrides the policy, not extending it. Option B is incorrect because items are not deleted while under hold. Option D is incorrect because items are not moved to a separate location.

60
MCQhard

Refer to the exhibit. You are reviewing a Microsoft Purview auto-labeling policy configuration. The SensitivityTypes GUID corresponds to a sensitive info type that detects credit card numbers. The LabelId is for a 'Confidential' label. Users report that documents containing credit card numbers are not being automatically labeled. What is the most likely reason?

A.The 'Confidential' label is not published to users.
B.The sensitive info type GUID is incorrect.
C.Users do not have the appropriate license for auto-labeling.
D.The auto-labeling policy is not scoped to the correct locations (e.g., SharePoint, Exchange).
AnswerD

For an auto-labeling policy to apply labels, it must be explicitly scoped to the locations where content resides, such as SharePoint sites, Exchange mailboxes, and OneDrive. The exhibit shows that the policy does not include these locations, or includes only a subset, so the policy never scans the content. Without proper location scoping, no labeling occurs even if the label and SIT are configured correctly.

Why this answer

Auto-labeling policies in Microsoft Purview must be scoped to the locations where the sensitive data resides (Exchange, SharePoint, OneDrive, etc.). If the policy is not scoped to the correct locations, documents containing credit card numbers in those locations will never be evaluated, so no automatic labeling occurs. This is the most common configuration oversight when auto-labeling appears to do nothing.

Exam trap

The trap is focusing on label publication or licensing when the most common cause of silent auto-labeling failure is a misconfigured policy scope that omits the locations where the sensitive data actually resides.

How to eliminate wrong answers

Option A is wrong because if the 'Confidential' label were not published to users, manual labeling would fail, but auto-labeling uses the label's ID directly and does not require the label to be published to users for the policy to apply. Option B is wrong because an incorrect sensitive info type GUID would cause the policy to match nothing, but the question states the GUID corresponds to a credit card SID — the exhibit confirms it is correct. Option C is wrong because licensing issues would typically prevent policy creation or show explicit license errors, not silent non-labeling of matching documents.

61
MCQhard

A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?

A.Sensitivity labels with encryption and usage rights
B.Data Loss Prevention (DLP) policy
C.Information Barriers
D.Microsoft Purview Information Protection without encryption
AnswerA

Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.

Why this answer

Sensitivity labels with encryption and usage rights allow administrators to apply Azure Rights Management (Azure RMS) protection to documents, which can restrict actions such as printing and copying. By configuring a sensitivity label with specific usage rights (e.g., 'View Only' or disabling 'Extract' and 'Print'), external users are prevented from printing or copying content even after the document is downloaded or accessed in SharePoint Online. This is the only Purview feature that directly enforces persistent content-level restrictions on external users.

Exam trap

The trap here is that candidates often confuse DLP policies with content protection, assuming DLP can restrict printing or copying after access, when in fact DLP only controls data in transit or at rest and does not enforce persistent usage rights on the document itself.

How to eliminate wrong answers

Option B is wrong because Data Loss Prevention (DLP) policies detect and block sensitive information from being shared or exfiltrated, but they do not enforce persistent usage restrictions like preventing printing or copying after access is granted. Option C is wrong because Information Barriers are designed to prevent communication and collaboration between specific groups or users (e.g., to avoid conflicts of interest), not to control document-level actions like printing or copying. Option D is wrong because Microsoft Purview Information Protection without encryption applies labels for classification and auditing but does not enforce any technical restrictions on content usage; encryption is required to enforce usage rights.

62
MCQeasy

A compliance officer needs to preserve all mailbox data for a user who is under a legal investigation. The data must be preserved indefinitely, and no deletion (by the user or system) should be possible. Which Microsoft Purview feature should the officer use?

A.Litigation Hold
B.Retention Policy
C.Data Loss Prevention (DLP)
D.Sensitivity labels
AnswerA

Litigation Hold is the correct choice because it preserves all mailbox content indefinitely, including deleted items and prior versions, and blocks both user purges and automatic Exchange retention cleanup. In Exchange Online, Litigation Hold temporarily overrides deletion and applies an indefinite hold that is only lifted when the hold is explicitly removed by an administrator, making it a true preservation-for-compliance mechanism.

Why this answer

Litigation Hold is the correct feature because it preserves all mailbox content indefinitely, preventing any deletion by the user or automated processes like the Managed Folder Assistant. It ensures that data is immutable for eDiscovery purposes, meeting the compliance officer's requirement for indefinite preservation under legal investigation.

Exam trap

The trap here is that candidates often confuse Retention Policies with Litigation Hold, thinking a retention policy can indefinitely preserve data, but retention policies have configurable expiration periods and can allow deletion, whereas Litigation Hold provides an immutable, indefinite hold specifically for legal scenarios.

How to eliminate wrong answers

Option B (Retention Policy) is wrong because retention policies can allow deletion after a specified period or apply actions like 'Delete' or 'Retain and Delete,' which does not guarantee indefinite preservation and can be overridden by user actions. Option C (Data Loss Prevention (DLP)) is wrong because DLP policies are designed to detect and prevent accidental sharing of sensitive data, not to preserve or hold mailbox data for legal purposes. Option D (Sensitivity labels) is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption or marking), but they do not prevent deletion or provide indefinite hold capabilities for mailbox items.

63
MCQeasy

You are a Microsoft 365 administrator for Litware Inc. The company uses Microsoft Purview Records Management. A file plan has been created with a retention label named 'Project Alpha'. You need to ensure that documents labeled 'Project Alpha' are retained for five years after the project ends, and then automatically deleted. What should you configure on the retention label?

A.Set the retention period to five years and trigger retention based on 'When items were last modified'.
B.Set the retention period to five years and trigger retention based on 'When items were created'.
C.Set the retention period to five years and choose 'When an event occurs' as the retention trigger.
D.Set the retention period to five years and configure a disposition review at the end of the period.
AnswerC

Event-based retention allows you to specify a custom event, such as 'Project ends', which starts the retention period. This ensures documents are retained for five years after the project ends and then deleted. This configuration meets the requirement precisely.

Why this answer

The requirement is to retain documents for five years after the project ends, which is a classic event-based retention scenario. Configuring the retention label to use 'When an event occurs' allows you to define a custom event like project completion, starting the retention period then. The label should also be set to delete items after the retention period to meet the automatic deletion requirement.

Exam trap

The trap here is selecting a creation or modification trigger, which does not align with the business event of project completion.

64
MCQmedium

A compliance officer needs to retain all documents in a SharePoint Online site for 7 years and then automatically delete them. During the retention period, users must be able to edit the documents but not delete them. Which Microsoft Purview solution should the officer configure?

A.retention policy configured with a retention period of 7 years and an action to delete items automatically
B.retention label configured with a retention period and an action to delete after 7 years
C.data lifecycle management policy
D.An eDiscovery hold
AnswerA

A retention policy in Microsoft Purview applies at the container level, such as a SharePoint site or Exchange mailbox, and can be configured with a 7-year retention period followed by automatic deletion of items. This container-based scope ensures all documents in the site are covered without requiring per-item labels or manual classification. During the retention period, content is protected from permanent deletion by users, and after the 7 years the policy triggers an automatic purge, exactly matching the compliance officer's requirement.

Why this answer

A retention policy in Microsoft Purview can be applied at the site level to enforce a 7-year retention period with automatic deletion, while allowing users to edit documents during that time. The policy prevents deletion by users because the retention lock overrides user permissions, ensuring compliance with the requirement to block deletion but permit edits.

Exam trap

The trap here is that candidates confuse retention labels with retention policies, assuming labels can enforce site-wide deletion and edit permissions, but labels are item-level and require manual application or auto-labeling, whereas policies apply broadly and include the necessary deletion prevention.

How to eliminate wrong answers

Option B is wrong because a retention label requires manual or auto-classification and is typically applied to individual items, not an entire site, and it does not inherently prevent user deletion during the retention period unless combined with a retention policy. Option C is wrong because a data lifecycle management policy focuses on managing data across its lifecycle (e.g., archiving or moving to cold storage) but does not enforce a retention period with deletion prevention and automatic deletion in the same way as a retention policy. Option D is wrong because an eDiscovery hold preserves content for legal or investigative purposes but does not automatically delete items after a set period; it is designed for indefinite holds until released, not scheduled deletion.

65
MCQmedium

A compliance officer needs to prevent users from copying sensitive data (e.g., credit card numbers) from a finance application into personal email or documents. The solution must inspect the content in real-time and block the action if sensitive data is detected. Which Microsoft Purview feature should the officer configure?

A.Data Loss Prevention (DLP) policies
B.Sensitivity labels
C.Retention labels
D.eDiscovery
AnswerA

DLP policies are the correct choice because they perform real-time content inspection on endpoints and cloud apps, matching against sensitive information types (e.g., credit card numbers, PII) and then enforcing protective actions. A DLP policy can specifically block copy, paste, print, or transfer of that data to unauthorized destinations, and it can also trigger user notifications or incident reports. This is the only option that directly intercepts and prevents user copying actions at the point of resource access.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are designed to inspect content in real-time as users attempt to copy, paste, or share sensitive data (e.g., credit card numbers) from applications like finance apps into personal email or documents. DLP uses deep content analysis via sensitive information types and policy tips to block the action before the data leaves the controlled environment, meeting the compliance officer's requirement for real-time blocking.

Exam trap

The trap here is that candidates often confuse sensitivity labels (which protect data at rest) with DLP policies (which enforce real-time action blocking), leading them to select sensitivity labels because they think labeling alone prevents copying, but labels do not block user actions in real-time.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data at rest (e.g., encryption or visual markings) but do not perform real-time content inspection or block copy/paste actions; they require user or automated labeling after data is created. Option C is wrong because retention labels manage data lifecycle (retention and deletion) based on policies, not real-time content inspection or blocking of data exfiltration. Option D is wrong because eDiscovery is used for searching, preserving, and exporting data for legal or investigative purposes, not for preventing data loss in real-time.

66
MCQeasy

A compliance officer needs to automatically apply a retention label to all documents in SharePoint Online that contain the exact phrase 'Contract'. The label must retain the documents for 10 years. Which Microsoft Purview feature should the officer configure?

A.retention policy applied to the entire site
B.Data Loss Prevention (DLP) policy
C.An auto-apply retention label using a trainable classifier
D.An auto-apply retention label using a content query (KQL)
AnswerD

An auto-apply retention label using a content query (KQL) is the only option that directly satisfies the requirement. In Microsoft Purview, you create an auto-apply retention label policy, select "Apply label to content that matches a query," and enter a KQL expression such as "Contract" to match documents containing that exact phrase. The KQL query runs against the search index, automatically assigns the retention label to matching content, and enforces the configured retention period. This approach is rule-based and deterministic, precisely targeting the literal string "Contract" as specified.

Why this answer

An auto-apply retention label using a content query (KQL) allows you to define a specific keyword or phrase (e.g., 'Contract') to automatically label documents in SharePoint Online that contain that exact text. This meets the requirement to retain documents for 10 years by applying the label based on content matching, without needing a pre-trained classifier.

Exam trap

The trap here is that candidates often confuse auto-apply labels with trainable classifiers, thinking a machine learning model is needed for any content-based labeling, when in fact a simple KQL query is sufficient for exact phrase matching.

How to eliminate wrong answers

Option A is wrong because a retention policy applied to the entire site retains all content in the site, not just documents containing the exact phrase 'Contract', and it does not use a label—it applies retention settings directly without the granularity of label-based auto-application. Option B is wrong because a Data Loss Prevention (DLP) policy is designed to prevent data exfiltration or leakage by blocking or alerting on sensitive content, not to automatically apply retention labels for compliance purposes. Option C is wrong because a trainable classifier uses machine learning to identify patterns or categories (e.g., contracts in general), not an exact phrase match, and requires training and tuning, making it unsuitable for a simple keyword-based requirement.

67
MCQhard

Your organization is implementing Microsoft Purview Communication Compliance to detect potential insider trading. You need to scan internal emails for specific patterns and assign reviewers from the legal team. What is the minimum number of policies required?

A.One policy with multiple conditions.
B.Three policies: one for patterns, one for reviewers, and one for storage.
C.Zero, as Communication Compliance does not support custom policies.
D.Two policies: one for each pattern.
AnswerA

A single Communication Compliance policy can combine multiple conditions, such as keyword or sensitive information type matches, to detect insider trading patterns across internal email. Reviewer assignment to the legal team is configured within that same policy, so no additional policies are needed to satisfy both the detection and review requirements.

Why this answer

A single Communication Compliance policy can contain multiple conditions (such as sensitive info types, keyword dictionaries, and trainable classifiers) and can define multiple reviewers or reviewer groups within the same policy. Since the requirement is to scan internal emails for specific patterns AND assign legal reviewers, both can be configured inside one policy, making one the minimum number required.

Exam trap

MS-102 often tests the misconception that each condition or reviewer group requires its own policy, when in fact Communication Compliance policies are designed to bundle multiple conditions and reviewers into a single policy.

How to eliminate wrong answers

Option B is wrong because reviewers and patterns are configured within the same policy — there is no separate 'storage' policy concept in Communication Compliance, and splitting patterns across policies is unnecessary. Option C is wrong because Communication Compliance fully supports custom policies with custom conditions and reviewers. Option D is wrong because multiple patterns can be combined as conditions inside a single policy; you do not need one policy per pattern.

68
MCQmedium

Your company has a Microsoft 365 E5 subscription. You need to prevent users from sharing files containing credit card numbers with external users. What should you configure?

A.A retention policy for SharePoint sites.
B.An information barrier policy.
C.A sensitivity label with encryption.
D.A DLP policy that blocks sharing of content with sensitive info type.
AnswerD

A DLP policy that blocks sharing of content matching a sensitive information type directly enforces the credit card number constraint, since Microsoft Purview's built-in credit card sensitive info type detects those patterns and blocks external sharing in Microsoft 365 E5.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft 365 can detect sensitive information types such as credit card numbers and block sharing with external users. DLP policies are designed to prevent accidental or intentional sharing of sensitive data across Exchange, SharePoint, OneDrive, and Teams, making it the correct control for this requirement.

Exam trap

MS-102 often tests the distinction between DLP (which blocks sharing based on content inspection) and sensitivity labels (which classify and protect but do not automatically block sharing based on content), so candidates who pick sensitivity labels miss the requirement for automatic blocking.

How to eliminate wrong answers

Option A is wrong because a retention policy governs how long content is kept or deleted, not whether it can be shared externally. Option B is wrong because information barrier policies prevent specific users or groups from communicating with each other, not from sharing files containing sensitive data with external users. Option C is wrong because a sensitivity label with encryption protects content but does not automatically block sharing based on the presence of credit card numbers; it requires user action or auto-labeling, and encryption alone does not prevent external sharing if the user chooses to share.

69
MCQhard

You are a compliance administrator for Contoso Ltd. The company uses Microsoft Purview Information Protection with sensitivity labels. A new regulation requires that all documents labeled 'Highly Confidential' must be encrypted and only accessible by members of the 'Legal' group, even when shared externally. You have published a label named 'Highly Confidential' with encryption settings. You need to ensure that the label enforces these requirements when applied to documents in Office apps. What should you configure in the label's encryption settings?

A.Assign permissions to the 'Legal' group with 'Viewer' role, and clear the option 'Let users assign permissions'.
B.Assign permissions to the 'Legal' group with 'Viewer' role and set 'Do not forward' for the content.
C.Assign permissions to the 'Legal' group with 'Viewer' role and enable 'Let users assign permissions'.
D.Assign permissions to the 'Legal' group with 'Co-Author' role and set an expiration date for the content.
AnswerA

Assigning Viewer permissions to the Legal group ensures that only members of that group can read the content, and clearing 'Let users assign permissions' prevents users from altering the permissions when applying the label. This enforces the encryption and access restriction required by the regulation, ensuring that only Legal can access the documents.

Why this answer

To enforce that only the Legal group can access documents labeled 'Highly Confidential', the encryption settings must assign permissions exclusively to that group and prevent users from changing those permissions. Assigning Viewer role limits access to read-only for Legal, and disabling user assignment ensures the label's protection cannot be overridden. This meets the regulatory requirement for encryption and access control.

Exam trap

The trap here is assuming that any permission assignment to the Legal group automatically excludes others, when in fact user-assigned permissions could allow broader access if not disabled.

70
Multi-Selecthard

Which THREE components are required to implement auto-labeling for sensitivity labels in Microsoft 365?

Select 3 answers
A.A sensitivity label configured for auto-labeling.
B.A DLP policy for the same sensitive info type.
C.A sensitive info type or trainable classifier.
D.An auto-labeling policy that specifies the label and locations.
E.An information barrier policy.
AnswersA, C, D

Auto-labelling requires a sensitivity label whose settings define what the policy applies; without a label configured for auto-labelling there is nothing for the policy to assign. It satisfies the stem's requirement as the mandatory label component of the three-part configuration.

Why this answer

Auto-labeling in Microsoft 365 requires three core components. Option A is correct because a sensitivity label must be configured for auto-labeling (i.e., its auto-labeling setting enabled) so it can be applied automatically to matching content. Option C is correct because the auto-labeling policy must reference a sensitive info type (such as a built-in SIT or a custom SIT) or a trainable classifier to detect the content to label.

Option D is correct because an auto-labeling policy is the container that binds the label to the detection rules and specifies the workloads/locations (Exchange, SharePoint, OneDrive) where labeling runs. Option B is not required: a DLP policy is a separate data loss prevention control and is not a prerequisite for auto-labeling, even if it uses the same sensitive info type. Option E is not required: information barrier policies restrict communication between groups and are unrelated to sensitivity label auto-labeling.

Exam trap

MS-102 often tests the components of auto-labeling and confuses it with DLP; candidates might incorrectly include a DLP policy as a requirement, but auto-labeling policies are separate and do not require DLP.

71
MCQmedium

Your organization uses Microsoft Purview Data Lifecycle Management. You need to review the disposition of content that has reached the end of its retention period. What should you configure?

A.Create a DLP policy to notify administrators.
B.Place the content on an eDiscovery hold.
C.Enable disposition review in the retention policy or label.
D.Create a retention label with a retention period.
AnswerC

Disposition review lets reviewers examine content at the end of its retention period before permanent deletion, satisfying the requirement to review disposition. Configuring it on the retention policy or label routes expired items to a review queue in Microsoft Purview, where reviewers approve destruction or extend retention.

Why this answer

Disposition review is a feature in Microsoft Purview Data Lifecycle Management that allows you to review content before it is permanently deleted at the end of its retention period. To enable it, you must configure the retention policy or retention label to trigger a disposition review. This ensures that content is not automatically deleted without human oversight, which is often required for regulatory or legal reasons.

Exam trap

MS-102 often tests the difference between retention and disposition; candidates may think that setting a retention period automatically triggers review, but disposition review must be explicitly enabled.

How to eliminate wrong answers

Option A is wrong because DLP policies are for preventing data loss, not for managing retention disposition. Option B is wrong because an eDiscovery hold preserves content indefinitely, which is the opposite of disposition review. Option D is wrong because creating a retention label with a retention period alone does not enable disposition review; you must specifically enable the disposition review option on the label or policy.

72
MCQhard

You are the compliance administrator for Contoso Ltd., a multinational corporation with 10,000 users. The company uses Microsoft 365 E5 licenses and has deployed Microsoft Purview. The legal department requires that all email communications related to ongoing litigation be preserved for the duration of the case. You have identified the custodians and relevant keywords. You need to ensure that all relevant emails are preserved, regardless of whether users delete them. Additionally, you need to allow authorized reviewers to search and export the preserved emails without affecting the original data. Finally, you must ensure that the preservation is lifted automatically when the case is closed. What should you do?

A.Create an eDiscovery (Premium) case, add custodians, place them on hold, and use the case to search and export. Close the case to release the hold.
B.Configure a DLP policy to protect sensitive data and preserve the emails.
C.Create a retention label with a preservation action and publish it to the entire organization.
D.Place an in-place hold on all mailboxes using the Exchange admin center.
AnswerA

eDiscovery (Premium) is the correct solution because it provides a centralized case object that ties together custodians, holds, searches, and exports. Adding custodians places them on hold, ensuring their data is preserved across Exchange, SharePoint, and OneDrive for Business, while the case interface enables targeted searching and exporting. Closing the case (with release hold option) cleanly removes the holds, and the case record preserves an audit trail of the investigation.

Why this answer

eDiscovery (Premium) cases in Microsoft Purview are purpose-built for litigation workflows: they let you add custodians, place them on legal hold, run targeted searches, and export results without altering the source data. Closing the case automatically releases the custodian holds, which satisfies the requirement that preservation be lifted when the case ends. This is the only option that combines custodian-scoped preservation, reviewer search/export, and automatic hold release in one workflow.

Exam trap

MS-102 often tests the distinction between retention labels, DLP, and eDiscovery holds, tricking candidates into choosing a retention label because it sounds like 'preservation' when the scenario actually requires case-based legal hold with automatic release.

How to eliminate wrong answers

Option B is wrong because DLP policies detect and protect sensitive information in motion or at rest but do not place mailboxes on legal hold or provide case-based search and export for litigation. Option C is wrong because retention labels apply retention or preservation actions based on label policy scope and do not automatically release holds when a specific legal case closes, nor do they provide eDiscovery search/export tooling. Option D is wrong because Exchange in-place holds (or the newer Litigation Hold) preserve mailbox content but are not tied to a case lifecycle, so they must be manually removed and do not offer the case-scoped custodian management and review workflow required.

73
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Purview Data Loss Prevention (DLP) policies?

Select 2 answers
A.Set retention periods for documents containing credit card numbers.
B.Show a policy tip to users when they attempt to share sensitive data.
C.Block users from sharing sensitive information via email.
D.Add a watermark to sensitive documents.
E.Automatically encrypt sensitive files when shared.
AnswersB, C

Policy tips deliver real-time, in-context warnings within supported apps such as Outlook, Word and Teams when a user's action matches a DLP rule condition, satisfying the requirement to notify users attempting to share sensitive data. Enforcement occurs at the point of egress, letting users justify or override before the item leaves the tenant.

Why this answer

Option B is correct because Microsoft Purview DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and SharePoint) when their actions match a DLP rule, warning them before they share sensitive data. Option C is correct because DLP policies can enforce blocking actions, such as preventing users from sending emails containing sensitive information like credit card or Social Security numbers, via Exchange/Outlook and other workloads. Option A is not a DLP function; retention periods are configured with retention labels and retention policies in Microsoft Purview Data Lifecycle Management (or records management), not DLP.

Option D is not a DLP action; watermarks are applied through sensitivity labels with content marking (or Azure Information Protection), not DLP policies. Option E is not a DLP action; automatic encryption is achieved through sensitivity labels with encryption settings, not DLP, which focuses on detecting and restricting/blocking sharing rather than encrypting files.

Exam trap

MS-102 often tests the specific actions DLP can take versus those it cannot, such as encryption or watermarking; candidates may incorrectly assume DLP can encrypt or watermark files.

74
Matchingmedium

Match each Microsoft 365 role to its administrative scope.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Full access to all admin features

Resets passwords for non-admins

Manages Exchange Online

Manages users and groups

Manages security policies

Why these pairings

These roles are part of Azure AD role-based access control. The correct matches are: Global Administrator (full access), User Administrator (users/groups), Exchange Administrator (Exchange settings). Common confusions include mixing Global and User Administrator scopes, or User and Exchange Administrator scopes.

75
Multi-Selectmedium

Which TWO actions can you perform using Microsoft Purview eDiscovery (Premium)? (Choose two.)

Select 2 answers
A.Place a legal hold on custodians' mailboxes and sites.
B.Export search results to a local computer for review.
C.Create and apply retention labels to documents.
D.Automatically delete emails older than a specified date.
E.Configure sensitivity labels to encrypt documents.
AnswersA, B

Custodial holds preserve mailbox and site content in place, satisfying the legal-hold requirement during an investigation. eDiscovery (Premium) adds custodian management and hold notifications beyond standard eDiscovery, keeping potentially relevant data immutable until the case closes.

Why this answer

Option A is correct because eDiscovery (Premium) supports placing legal holds on custodians, which preserves mailbox and site content (including Exchange mailboxes, SharePoint sites, and OneDrive accounts) to prevent spoliation during an investigation. Option B is correct because eDiscovery (Premium) allows you to export search results and review sets to a local computer for offline review, typically via the Export tool in the case. Option C is incorrect because retention labels are created and published through Microsoft Purview Records Management or Data Lifecycle Management, not through eDiscovery (Premium).

Option D is incorrect because automatic deletion of emails by age is handled by retention policies in Data Lifecycle Management, not eDiscovery (Premium). Option E is incorrect because sensitivity labels and encryption are configured through Microsoft Purview Information Protection, not eDiscovery (Premium).

Page 1 of 2 · 104 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage compliance by using Microsoft Purview questions.