Courseiva

CCNA Manage compliance by using Microsoft Purview Questions

29 of 104 questions · Page 2/2 · Manage compliance by using Microsoft Purview · Answers revealed

76
MCQeasy

Your organization uses Microsoft Purview Communication Compliance to detect inappropriate messages in Microsoft Teams. You need to configure a policy that monitors for potential harassment based on a built-in classifier. The policy should alert designated reviewers when a match is found. What is the minimum configuration required?

A.Create a communication compliance policy, select the built-in harassment classifier, specify the users to monitor, and assign reviewers.
B.Create a retention policy for Teams messages, then create a communication compliance policy with the harassment classifier.
C.Create a DLP policy that blocks harassment, then configure communication compliance to review DLP alerts.
D.Apply a sensitivity label to all Teams messages, then create a communication compliance policy that scans for the label.
AnswerA

Creating a communication compliance policy is the sole configuration required to start detecting harassment. The built-in harassment classifier uses pre-trained machine learning models to flag potentially abusive or threatening language in Exchange, Teams, and Yammer messages. You must specify the users or groups whose messages are monitored, and assigning reviewers ensures the flagged messages are investigated and resolved. No additional components such as retention policies, DLP policies, or sensitivity labels are needed as prerequisites.

Why this answer

The minimum configuration to monitor for potential harassment using Communication Compliance is to create a communication compliance policy, select the built-in harassment classifier, specify the users to monitor, and assign reviewers. No retention policy, DLP policy, or sensitivity label is required.

77
MCQmedium

Your organization uses Microsoft Purview eDiscovery (Premium) for a legal investigation. You need to collect data from Microsoft Teams chat messages and channel conversations. The case manager wants to search for specific keywords and exclude irrelevant content. What should you do?

A.Use Content Search (Standard) with keyword queries.
B.Create a DLP policy to capture matching content.
C.Use Communication Compliance to review messages.
D.Create a collection in eDiscovery (Premium) with a KQL query to search Teams data.
AnswerD

Create a collection in eDiscovery (Premium) and use a KQL query to search Teams data; this is the correct approach because eDiscovery Premium natively indexes Teams chats, threads, meeting messages, and attachments, and supports advanced query filters for scoping. The collection ingests hits into a review set where you can analyze, tag, add to a hold, and export with metadata for litigation.

Why this answer

EDiscovery (Premium) collections allow searching Microsoft Teams chat messages and channel conversations using KQL queries with conditions to include specific keywords and exclude irrelevant content. Option A is incorrect because Content Search (Standard) is less powerful and lacks advanced filtering capabilities for Teams data. Option B is incorrect because DLP policies are designed for data loss prevention, not legal discovery.

Option C is incorrect because Communication Compliance is for monitoring communications, not for eDiscovery searches.

78
MCQmedium

An organization is involved in a legal case and needs to preserve all emails in a user's mailbox, including future emails, without deleting or modifying them. The user must continue to work normally. Which Microsoft Purview feature should be applied to the user's mailbox?

A.Litigation Hold
B.Retention policy
C.Sensitivity label
D.Data Loss Prevention (DLP)
AnswerA

Litigation Hold is the correct choice because it preserves all mailbox content in its original state, including items that users edit or delete, by placing the entire mailbox on hold within the Recoverable Items folder. This in-place hold suspends the normal purging of deleted items and version tracking, allowing legal teams to review everything via eDiscovery without disrupting user workflows. Unlike other options, Litigation Hold is specifically designed to meet legal preservation obligations and can be applied to a user's entire mailbox or specific folders.

Why this answer

Litigation Hold (option A) is the correct feature because it preserves all mailbox content, including future emails, in its original state without allowing deletion or modification by users or automated processes. Unlike a retention policy, Litigation Hold places the entire mailbox on indefinite hold, ensuring that any item changed or deleted by the user is retained in the Recoverable Items folder, while the user continues to work normally. This meets the legal preservation requirement without disrupting daily operations.

Exam trap

Microsoft often tests the distinction between Litigation Hold and Retention Policy, where candidates mistakenly choose Retention Policy because they think it 'retains' data, but they miss that Retention Policy can delete data after a period, whereas Litigation Hold preserves everything indefinitely without deletion.

How to eliminate wrong answers

Option B (Retention policy) is wrong because retention policies are designed to manage data lifecycle by deleting or retaining items based on age or rules, not to preserve all content indefinitely for legal hold; they can delete items after a specified period, which violates the preservation requirement. Option C (Sensitivity label) is wrong because sensitivity labels classify and protect data based on sensitivity (e.g., encryption or marking), but they do not prevent deletion or modification of emails, nor do they preserve mailbox content for legal purposes. Option D (Data Loss Prevention (DLP)) is wrong because DLP policies detect and prevent accidental sharing of sensitive information (e.g., credit card numbers) but do not impose holds or preserve mailbox items; they focus on data exfiltration prevention, not legal preservation.

79
Multi-Selecthard

Which THREE actions can be taken by a Microsoft Purview Data Loss Prevention (DLP) policy in Exchange Online?

Select 3 answers
A.Block the email from being sent
B.Allow the sender to override the block
C.Block all emails from the sender
D.Notify the sender with a policy tip
E.Encrypt the email message
AnswersA, D, E

In Microsoft Purview Data Loss Prevention (DLP), a policy can be configured with an action to block the transmission of an email that contains sensitive information. When the condition is met, the DLP engine can prevent the message from leaving the sender's mailbox, either silently or with a policy tip, depending on the rule configuration. This is a primary enforcement mechanism to stop data exfiltration before it occurs, as the email is never delivered to the recipient.

Why this answer

DLP policies in Exchange Online can block sending, encrypt the message, and notify the sender with a policy tip. Justifying override is not an action; it's a user response. Blocking all emails is not granular; DLP actions are rule-based.

80
MCQmedium

A compliance officer needs to prevent users from accidentally sharing documents containing credit card numbers with external users via email. The block should occur at the time the user attempts to send the email. Which Microsoft Purview feature should be configured?

A.Communication compliance
B.Data Loss Prevention (DLP)
C.Records management
D.Insider risk management
AnswerB

Data Loss Prevention (DLP) policies in Microsoft 365 enforce real-time protection by inspecting email messages for sensitive info types (e.g., credit card numbers, Social Security numbers) and applying actions such as blocking the message from leaving the organization, with optional user override and notification. These policies are integrated with Exchange Online transport rules, allowing them to evaluate outbound mail before delivery. DLP is the correct choice because it directly addresses the requirement to prevent accidental sharing through proactive, policy-based blocking.

Why this answer

Data Loss Prevention (DLP) is the correct feature because it is specifically designed to inspect email content in transit for sensitive data patterns, such as credit card numbers, and enforce policy actions like blocking the message at the transport layer. In Microsoft Purview, DLP policies can be configured to scan Exchange Online messages in real time using sensitive information types (e.g., Credit Card Number) and apply a block action with an optional policy tip to the user before the email leaves the outbound queue.

Exam trap

The trap here is that candidates often confuse Communication compliance (which also monitors email) with DLP, but Communication compliance is a reactive auditing tool for policy violations, not a proactive, inline blocking mechanism for sensitive data.

How to eliminate wrong answers

Option A is wrong because Communication compliance is designed to detect and remediate inappropriate or policy-violating communications (e.g., harassment, insider trading) after they are sent, not to block outbound emails containing sensitive data in real time. Option C is wrong because Records management focuses on classifying, retaining, and disposing of records based on regulatory requirements, not on inspecting or blocking email content during transmission. Option D is wrong because Insider risk management uses analytics to identify risky user activities (e.g., data exfiltration patterns) over time, but it does not provide inline blocking of email messages at the moment of sending.

81
MCQmedium

A compliance officer needs to prevent users from sharing documents labeled 'Confidential' via email with external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip displayed. Which Microsoft Purview feature should be configured?

A.Retention labels
B.Data Loss Prevention (DLP) policy
C.Sensitivity labels
D.Information barriers
AnswerB

DLP policies are the correct control because they inspect message content and context in transit and can match sensitive information types or sensitivity labels. With a rule, DLP can block or warn when email is shared with external users, and can even block the send action entirely while allowing an override with justification. This makes DLP the only option that directly enforces a sharing restriction based on content classification.

Why this answer

A Data Loss Prevention (DLP) policy is the correct Microsoft Purview feature because it is specifically designed to inspect email content and attachments for sensitive information, such as documents labeled 'Confidential', and enforce actions like blocking the email and displaying a policy tip to the user. DLP policies can be configured with conditions that detect sensitivity labels and apply protective actions, including blocking external sharing and notifying users via policy tips.

Exam trap

Microsoft often tests the misconception that sensitivity labels alone can enforce blocking actions, but in reality, sensitivity labels only apply classification and protection (e.g., encryption) and must be combined with a DLP policy to inspect and block outbound email based on those labels.

How to eliminate wrong answers

Option A is wrong because retention labels are used to manage data lifecycle (retain or delete content) and do not have the capability to block email transmission or display policy tips. Option C is wrong because sensitivity labels classify and protect data (e.g., encryption, marking) but do not directly enforce real-time blocking of email sharing with external recipients; DLP policies are required to inspect and block outbound email based on those labels. Option D is wrong because information barriers restrict communication and collaboration between specific groups of users within an organization, not between internal and external recipients, and cannot block email based on document labels or display policy tips.

82
Multi-Selectmedium

A compliance officer needs to ensure that all documents uploaded to SharePoint Online that contain passport numbers are automatically labeled with a 'Highly Confidential' sensitivity label. Which two Microsoft Purview features must be configured together to achieve this? (Choose two.)

Select 2 answers
A.Auto-labeling policy for SharePoint Online
B.Data Loss Prevention (DLP) policy
C.Retention label policy
D.Sensitive info type (passport number)
AnswersA, D

An auto-labeling policy for SharePoint Online is the correct mechanism because it automatically applies a sensitivity label to documents when they match specified conditions, such as containing a passport number via a sensitive info type. This policy can run in simulation mode to assess coverage and then enforce labeling on all existing and new files in a site, ensuring consistent classification without manual user action. This directly satisfies the compliance requirement for labeling every uploaded document.

Why this answer

An auto-labeling policy in Microsoft Purview can automatically apply a sensitivity label to documents containing sensitive information, such as passport numbers, when they are uploaded to SharePoint Online. This policy uses conditions based on sensitive info types to trigger the labeling action without user intervention.

Exam trap

The trap here is that candidates often confuse DLP policies with auto-labeling policies, but DLP does not apply sensitivity labels—it only monitors and blocks data sharing, while auto-labeling is the correct feature for automatic label assignment.

83
Multi-Selectmedium

A compliance administrator needs to automatically apply a retention label to documents in a SharePoint Online site that contain the keyword 'Project Alpha'. The label should retain the documents for 5 years and then delete them. Which two Microsoft Purview features must be configured to achieve this? (Choose two.)

Select 2 answers
A.Trainable classifiers
B.Auto-labeling policy for SharePoint Online
C.Document Fingerprinting
D.Sensitive info type with a keyword dictionary (e.g., 'Project Alpha')
AnswersB, D

Auto-labeling policy for SharePoint Online is the correct feature because it uses conditions (like sensitive info types or trainable classifiers) to automatically apply a retention label to matching documents. To satisfy the requirement, you configure the policy with a sensitive info type that includes a keyword dictionary for 'Project Alpha', and assign the 2-year retention label. This policy runs continuously and can target all or specific SharePoint sites, providing the required automatic labeling.

Why this answer

An auto-labeling policy for SharePoint Online (option B) is required because it can automatically apply a retention label to documents based on conditions such as the presence of specific keywords. The sensitive info type with a keyword dictionary (option D) defines the condition by creating a custom sensitive information type that matches the exact phrase 'Project Alpha', which the auto-labeling policy then uses to trigger the label application.

Exam trap

The trap here is that candidates often confuse trainable classifiers with keyword-based sensitive info types, assuming machine learning is needed for any content detection, when in fact a simple keyword dictionary is sufficient and more appropriate for fixed terms.

84
MCQeasy

A compliance officer needs to ensure that any email sent from the organization that contains personally identifiable information (PII) such as social security numbers is automatically encrypted when the recipient is outside the organization. Which Microsoft Purview solution should the officer configure?

A.Sensitivity labels with auto-labeling
B.Data Loss Prevention (DLP) policy with encryption action
C.Office 365 Message Encryption (OME) configuration
D.Retention policy and labels
AnswerB

Microsoft Purview DLP policies are the correct solution because they operate on outbound email in transit within Exchange Online, scanning message body and attachments for sensitive data types. When a match occurs, the policy can automatically apply encryption as a protective action (via OME) and even show a policy tip or notify the sender, exactly meeting the requirement to ensure any email containing sensitive data is secured at send.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview can be configured with an 'Encrypt email messages' action that automatically applies Office 365 Message Encryption (OME) to emails containing sensitive information types (e.g., Social Security Number) when sent to external recipients. This meets the compliance requirement for automatic encryption based on content detection, without requiring user intervention or manual label application.

Exam trap

The trap here is that candidates confuse the underlying encryption technology (OME) with the policy that triggers it, leading them to select OME configuration (Option C) instead of the DLP policy that actually detects PII and enforces the encryption action.

How to eliminate wrong answers

Option A is wrong because sensitivity labels with auto-labeling can apply classification and protection, but they are designed for persistent labeling across documents and emails, not specifically to trigger encryption based on PII detection at the point of sending; auto-labeling for emails requires Exchange mail flow rules or DLP policies to enforce encryption. Option C is wrong because Office 365 Message Encryption (OME) is the underlying encryption technology, not a policy or configuration that automatically detects PII and triggers encryption; OME must be invoked by a DLP policy or mail flow rule. Option D is wrong because retention policies and labels manage data lifecycle and deletion, not real-time content inspection or encryption of outbound emails.

85
Multi-Selecteasy

Your company is implementing Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers in emails. Which THREE actions can a DLP policy take when a match is found?

Select 3 answers
A.Delete the email from the recipient's inbox.
B.Encrypt the email automatically.
C.Allow the user to override the block with a business justification.
D.Send a notification to the user with a policy tip.
E.Block the email from being sent.
AnswersC, D, E

Permits the sender to bypass the block by supplying a business justification, satisfying the need for a documented exception path. The override is recorded for audit, balancing strict credit card protection against legitimate business email flow.

Why this answer

Option C is correct because Microsoft Purview DLP policies can be configured with user override capabilities, allowing users to provide a business justification to bypass a block action when a sensitive information match is detected. Option D is correct because DLP policies can display policy tips to users in supported workloads like Outlook, notifying them that their email contains sensitive content and explaining the policy that triggered the match. Option E is correct because blocking the email from being sent is a core DLP enforcement action that prevents the message containing credit card numbers from leaving the organization.

Option A is incorrect because DLP policies do not retroactively delete emails from a recipient's inbox; they act at send time or at rest through retention/retention labels, not as a DLP match action. Option B is incorrect because DLP policies do not automatically encrypt emails as a match action; encryption is handled through sensitivity labels, Azure Information Protection, or Exchange mail flow rules, not DLP policy actions.

Exam trap

MS-102 often tests the specific actions DLP can take versus those it cannot, such as encryption or deletion; candidates may incorrectly assume DLP can encrypt or delete emails.

86
MCQmedium

A legal department needs to preserve all communications related to an ongoing lawsuit. They identify specific users and require that their mailbox items and OneDrive files are not altered or deleted. Which Microsoft Purview feature should be used?

A.Litigation Hold
B.Retention Policy
C.Data Loss Prevention (DLP)
D.eDiscovery
AnswerA

Litigation Hold is the correct mechanism because it places a preservation hold on an entire mailbox and OneDrive for Business site in-place, preventing items from being permanently deleted or altered. Every version of a document and every mailbox item, including deleted items and items edited by users, is retained in the Recoverable Items folder until the hold is released. Deletion by users, as well as cleanup by retention policies, is blocked for held content, ensuring all communications related to the legal matter remain discoverable in their original location.

Why this answer

Litigation Hold is the correct feature because it preserves all mailbox items and OneDrive files for specific users in their current state, preventing any alteration or deletion by users or automated processes. This is essential for legal holds where data must be immutable for eDiscovery purposes, and it applies at the user level rather than broadly across the organization.

Exam trap

The trap here is that candidates often confuse retention policies with litigation holds, thinking retention policies can preserve data indefinitely, but retention policies allow deletion after the retention period and do not block user-initiated edits or deletions during the policy's active duration.

How to eliminate wrong answers

Option B (Retention Policy) is wrong because retention policies are designed for managing data lifecycle and can delete or archive items after a specified period, but they do not prevent users from modifying or deleting content while the policy is active; litigation hold explicitly locks content. Option C (Data Loss Prevention) is wrong because DLP focuses on preventing sensitive data from being shared or leaked through rules and policies, not on preserving data from alteration or deletion. Option D (eDiscovery) is wrong because eDiscovery is a tool for searching, holding, and exporting data as part of legal investigations, but it is not a hold feature itself; litigation hold is the underlying mechanism that eDiscovery uses to preserve content.

87
MCQmedium

A compliance officer needs to retain all email messages in a user's Exchange Online mailbox for 7 years after the message is sent or received, and then automatically delete them. The retention must be enforced regardless of user actions. Which Microsoft Purview solution should be used?

A.Litigation hold
B.Retention policy with Exchange location
C.Classification policy
D.In-place eDiscovery hold
AnswerB

A retention policy applied to the Exchange location enforces retention at the mailbox level, independent of user deletion or edits. Setting a seven-year retention period then deletion meets the requirement that messages be kept for seven years and removed automatically.

Why this answer

A retention policy with the Exchange location in Microsoft Purview allows you to define a retention period (e.g., 7 years) and then automatically delete messages after that period. It enforces the retention regardless of user actions because it operates at the service level, not relying on user cooperation. This meets the compliance officer's requirement for mandatory, time-based retention and deletion.

Exam trap

The trap here is that candidates often confuse Litigation hold (which preserves indefinitely) with a retention policy (which can both preserve and delete after a set time), leading them to select Litigation hold for time-based deletion scenarios.

How to eliminate wrong answers

Option A is wrong because Litigation hold preserves all mailbox content indefinitely until the hold is removed, but it does not automatically delete messages after a specific period; it is designed for legal preservation, not time-based retention with deletion. Option C is wrong because Classification policy (e.g., sensitivity labels) applies metadata and protection actions but does not enforce time-based retention or automatic deletion of email messages. Option D is wrong because In-place eDiscovery hold is a deprecated feature that preserves content for eDiscovery purposes without automatic deletion; it also does not support time-based retention policies.

88
Matchingmedium

Match each Microsoft 365 migration tool to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Migrate mailboxes from on-premises to Exchange Online

Migrate files from on-premises to SharePoint and OneDrive

Sync on-premises identities to Azure AD

Orchestrate large-scale migrations

Migrate data from Google Workspace

Why these pairings

Correct matches: Exchange Migration (cutover) migrates entire on-premises Exchange organization; SPMT migrates files and SharePoint content; Mover migrates files from cloud storage; Azure AD Connect synchronizes identities. Common confusions include mixing the purpose of Mover with Exchange migration and SPMT with identity synchronization.

89
MCQmedium

A compliance officer wants to automatically apply a 'Confidential' sensitivity label to documents in SharePoint Online that contain credit card numbers. The label should be applied when the documents are created or modified. Which Microsoft Purview feature should be configured?

A.Create an auto-labeling policy for sensitivity labels
B.Create a retention label policy
C.Create a Data Loss Prevention (DLP) policy
D.Configure a default sensitivity label
AnswerA

Auto-labeling policies for sensitivity labels scan content in Microsoft 365 using sensitive information types and pattern matching to detect data such as personal, financial, or health information. When a match occurs, the policy automatically applies a configured sensitivity label—like 'Confidential'—directly to the file or email. This is the only mechanism here that both analyzes content and applies a sensitivity label, satisfying the compliance officer's requirement. Additionally, auto-labeling policies can run in simulation mode to tune detection before full enforcement.

Why this answer

Auto-labeling policies for sensitivity labels in Microsoft Purview can automatically apply a sensitivity label to documents in SharePoint Online based on sensitive information types, such as credit card numbers. This policy scans documents when they are created or modified and applies the label without user intervention, meeting the compliance officer's requirement.

Exam trap

The trap here is that candidates often confuse a DLP policy's ability to detect sensitive data with the ability to automatically apply a sensitivity label, but DLP policies only trigger alerts or block actions, not label documents.

How to eliminate wrong answers

Option B is wrong because retention label policies are designed to manage data retention and deletion, not to apply sensitivity labels for classification or protection. Option C is wrong because a Data Loss Prevention (DLP) policy can detect and block sharing of sensitive data but cannot automatically apply a sensitivity label to documents. Option D is wrong because configuring a default sensitivity label applies the label to new documents automatically but does not scan for specific content like credit card numbers, nor does it trigger on modification.

90
MCQeasy

A compliance officer wants to prevent users from sending emails that contain personally identifiable information (PII), such as social security numbers, to external recipients. If a user attempts to send such an email from Outlook, the email should be blocked and a policy tip explaining the block should be displayed. Which Microsoft Purview solution should the officer configure?

A.Microsoft Purview Data Loss Prevention (DLP) policy
B.Microsoft Purview Information Protection sensitivity label
C.Microsoft Purview Records Management retention label
D.Microsoft Purview eDiscovery case
AnswerA

A Microsoft Purview Data Loss Prevention (DLP) policy is exactly designed for this scenario: when applied to Exchange Online, it inspects outbound messages in transit against sensitive info types (such as social security numbers or credit card numbers) and can take corrective actions like blocking the message before it leaves the organization, optionally allowing an end-user override with justification and a policy tip in Outlook. This combination of content inspection, transport-level enforcement, and real-time user notification makes it the correct choice for preventing users from sending emails with specific sensitive data.

Why this answer

Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block sensitive information, such as PII (e.g., social security numbers), in transit. When a DLP rule matches, it can block the email and display a policy tip in Outlook, informing the user why the message was blocked. This meets the compliance officer's requirement to prevent external sending of PII with real-time user notification.

Exam trap

The trap here is that candidates confuse sensitivity labels (which apply protection at rest) with DLP policies (which enforce actions on data in motion), leading them to choose Option B because they associate labels with 'protecting' PII, but labels do not block outbound email or trigger policy tips.

How to eliminate wrong answers

Option B is wrong because sensitivity labels classify and protect data at rest (e.g., encryption, visual markings) but do not natively block outbound email based on content inspection or display policy tips in Outlook. Option C is wrong because retention labels manage data lifecycle (retention and deletion) and are not designed to inspect or block email content in transit. Option D is wrong because eDiscovery cases are used for legal hold, search, and export of content, not for real-time prevention of email sending or policy tip enforcement.

91
Drag & Dropmedium

Drag and drop the steps to configure Data Loss Prevention (DLP) policies in Microsoft Purview in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

DLP policies are created in Purview, conditions and actions defined, and then deployed after testing.

92
MCQmedium

A compliance officer needs to prevent users from sending emails that contain sensitive information, such as social security numbers, to external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip should be displayed to the user. Which Microsoft Purview solution should the officer configure?

A.Data Loss Prevention (DLP) policy
B.sensitivity label with encryption
C.Information Rights Management (IRM)
D.retention label with deletion
AnswerA

A DLP policy in Microsoft Purview integrates with Exchange Online to inspect email content in transit and at the client. It uses sensitive information types (e.g., U.S. Social Security Number) as conditions and can apply an action to 'Block the message' from being sent, optionally allowing the sender to override with a business justification. At the same time, policy tips are displayed in Outlook, Outlook on the web, and Mail for iOS/Android during composition, providing real-time guidance before the message leaves the client. This is the only option that actually prevents the email from being sent and educates the sender.

Why this answer

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to inspect email content for sensitive information (e.g., social security numbers) and can block the message while displaying a policy tip to the user. This matches the requirement exactly, as DLP policies enforce actions on data in transit (email) with user notifications.

Exam trap

The trap here is that candidates confuse sensitivity labels (which protect data at rest) with DLP (which protects data in motion), leading them to choose Option B because they think encryption prevents sending, but encryption does not block the email or show a policy tip at the point of sending.

How to eliminate wrong answers

Option B (sensitivity label with encryption) is wrong because sensitivity labels primarily classify and protect data at rest (e.g., files in SharePoint) and can apply encryption, but they do not natively block outbound email in real-time or display policy tips during send. Option C (Information Rights Management) is wrong because IRM protects content after delivery by restricting actions like forwarding or printing, but it does not inspect or block emails before they are sent based on sensitive data patterns. Option D (retention label with deletion) is wrong because retention labels manage data lifecycle (e.g., how long to keep or when to delete) and have no capability to scan outbound email content or block transmission.

93
Multi-Selecthard

A Microsoft Purview auto-labeling policy for sensitivity labels is matching too many SharePoint documents after simulation. Which two changes would most directly reduce false positives before enabling automatic labeling? (Choose two.)

Select 2 answers
A.Increase the confidence level or instance-count requirement for the sensitive information type
B.Add supporting keyword or contextual conditions to the auto-labeling rule
C.Turn on automatic labeling immediately and wait for users to report problems
D.Replace the sensitivity label with a retention label
AnswersA, B

Raising the confidence level or instance-count threshold in the sensitive information type (SIT) increases the probability that the detected pattern is a genuine match rather than an isolated or coincidental string. Confidence reflects the match strength of the classification engine, and instance count requires multiple occurrences in the same item, both of which reduce false positives in an auto-labeling policy.

Why this answer

Increasing the confidence level or instance-count requirement for the sensitive information type (SIT) directly reduces false positives by raising the threshold for what qualifies as a match. A higher confidence level means the classification engine requires stronger evidence (e.g., more keywords or a closer proximity to a pattern), while a higher instance count requires the sensitive data to appear multiple times in the document. Both adjustments make the auto-labeling rule more selective, ensuring only documents with a high likelihood of containing the specified sensitive content are labeled.

Exam trap

The trap here is that candidates may think immediate enforcement (Option C) is the fastest way to fix false positives, but Microsoft explicitly recommends using simulation mode to tune rules before enabling automatic labeling, and waiting for user reports is not a valid tuning strategy.

94
Multi-Selecteasy

Which TWO features are part of Microsoft Purview Communication Compliance?

Select 2 answers
A.Restricting communication between specific groups.
B.Applying retention labels to communications.
C.Policy tips to notify users of policy violations.
D.Detection of inappropriate or offensive language in emails.
E.Automatic encryption of sensitive communications.
AnswersC, D

Policy tips are a native Communication Compliance capability, surfacing real-time notifications to users within Outlook and Teams when their messages match a configured policy. This directly satisfies the stem's requirement for a feature belonging to Communication Compliance, distinguishing it from unrelated Microsoft Purview solutions such as Data Loss Prevention or Insider Risk Management.

Why this answer

Option C is correct because Communication Compliance policies can display policy tips to users in supported clients (for example, Outlook and Teams) to warn them in real time when their message may violate an organizational policy, helping deter risky communications. Option D is correct because Communication Compliance uses trainable classifiers and built-in sensitive information types to detect inappropriate or offensive language, harassment, threats, and other policy-violating content in emails and other communications. Option A is not a Communication Compliance feature; restricting communication between specific groups is handled by Exchange transport rules or information barriers.

Option B is not part of Communication Compliance; retention labels are applied through Microsoft Purview Data Lifecycle Management and Records Management. Option E is not part of Communication Compliance; automatic encryption of sensitive communications is provided by sensitivity labels with encryption or Exchange data loss prevention/transport rules.

95
MCQeasy

You need to implement a solution that allows users to classify documents containing personal data as 'Highly Confidential' and automatically encrypt them when shared via email. What should you configure?

A.A sensitivity label with auto-labeling and encryption.
B.A retention label with a disposition action.
C.An information barrier policy.
D.A DLP policy with an action to block sharing.
AnswerA

Sensitivity labels in Microsoft Purview can be configured to automatically apply encryption when content matches specified conditions, such as credit card numbers or confidential keywords. This auto-labeling can occur at rest or during document creation, and the encryption enforces permissions that protect data both inside and outside the organization. Because the requirement is to classify and encrypt, this is the only option that directly fulfills both actions.

Why this answer

A sensitivity label with auto-labeling and encryption is correct because sensitivity labels in Microsoft Purview Information Protection can be configured to automatically classify documents based on sensitive data types (e.g., personal data) and apply encryption to protect the content when shared via email. The auto-labeling feature uses conditions like pattern matching for personally identifiable information (PII) to assign the 'Highly Confidential' label, and the encryption action ensures the document is protected with Rights Management Services (RMS) policies, preventing unauthorized access even if the email is forwarded.

Exam trap

The trap here is that candidates often confuse DLP policies with sensitivity labels, thinking that DLP's block action achieves the same result as classification and encryption, but DLP only prevents sharing without applying persistent protection or classification metadata.

How to eliminate wrong answers

Option B is wrong because retention labels are designed to manage data lifecycle and retention/disposition actions (e.g., delete or retain), not to classify or encrypt content based on sensitivity or personal data. Option C is wrong because information barrier policies restrict communication and collaboration between specific groups (e.g., preventing HR from chatting with Finance), but they do not classify documents or apply encryption based on content. Option D is wrong because a DLP policy with an action to block sharing can prevent the email from being sent, but it does not automatically classify the document as 'Highly Confidential' or encrypt it; DLP policies typically block or notify, not apply encryption or sensitivity labels.

96
MCQmedium

Your organization has a Microsoft 365 E5 subscription and uses Microsoft Teams. You need to prevent external users from being added to sensitive teams that contain financial data. What should you configure?

A.A sensitivity label for containers that blocks guest access.
B.Azure AD Conditional Access policy for guest users.
C.An information barrier policy between finance and external.
D.A DLP policy for Teams chat and channel messages.
AnswerA

A container sensitivity label enforces its protection settings on the connected Microsoft 365 group, so configuring it to block guest access prevents external users from being added to the team. This directly satisfies the requirement to keep guests out of sensitive teams holding financial data.

Why this answer

Sensitivity labels for containers (groups and sites) can be configured to block guest access, which directly prevents external users from being added to Teams that contain sensitive data. This is the most targeted and appropriate control because it enforces protection at the container level based on the label applied to the team. Conditional Access policies control access based on user, device, and location conditions but do not prevent guests from being added to a team.

Information barriers prevent specific users from communicating with each other but are not designed to block all external users from a team. DLP policies protect content but do not prevent membership additions.

Exam trap

MS-102 often tests the confusion between content protection (DLP) and container-level access controls; candidates might choose DLP or Conditional Access when the requirement is to prevent guests from being added to a team, which is specifically handled by sensitivity labels for containers.

How to eliminate wrong answers

Option B is wrong because Azure AD Conditional Access policies govern authentication and authorization for users accessing resources, but they do not control the membership of a Microsoft 365 group or team; a guest could still be added even if they cannot access due to Conditional Access. Option C is wrong because information barriers are used to restrict communication between specific segments of users within an organization, not to block external guests from being added to a team; they are for internal ethical walls. Option D is wrong because DLP policies for Teams chat and channel messages monitor and protect sensitive information in messages, but they do not prevent external users from being added to a team; they might block sharing of content but not membership.

97
MCQhard

A compliance officer needs to automatically identify and label content that is conceptually similar to existing sensitive documents, such as internal strategy memos or proprietary technical specifications, without relying on explicit keywords or recognized sensitive information types. Which Microsoft Purview solution should the officer use to achieve this?

A.trainable classifier
B.sensitive information type
C.An auto-labeling policy with a retention label
D.Data Loss Prevention (DLP) policy that blocks sharing
AnswerA

Trainable classifiers are designed to identify content based on examples and can learn to recognize documents that are conceptually similar, such as internal memos or proprietary specs, without needing exact keywords or predefined sensitive info types.

Why this answer

A trainable classifier uses machine learning to identify content based on patterns and context learned from sample documents, making it ideal for recognizing conceptually similar content without relying on explicit keywords or predefined sensitive information types. This allows the compliance officer to automatically label internal strategy memos or proprietary technical specifications that share conceptual similarity with existing sensitive documents.

Exam trap

The trap here is that candidates often confuse trainable classifiers with sensitive information types, assuming that keyword or regex-based patterns are sufficient for conceptual similarity, when in fact trainable classifiers are the only Microsoft Purview solution that uses machine learning to identify content based on learned patterns rather than explicit rules.

How to eliminate wrong answers

Option B is wrong because sensitive information types rely on predefined patterns (e.g., regex, keywords, checksums) and cannot identify conceptually similar content without explicit keywords or recognized types. Option C is wrong because an auto-labeling policy with a retention label applies labels based on conditions like sensitive info types or trainable classifiers, but the retention label itself does not perform conceptual identification; the labeling policy would still require a trainable classifier to trigger. Option D is wrong because a Data Loss Prevention (DLP) policy that blocks sharing can use classifiers or sensitive info types to enforce actions, but it is a protective control, not a labeling solution for automatic identification and labeling of conceptually similar content.

98
MCQeasy

You need to monitor which users have accessed a specific document stored in SharePoint Online over the last 90 days. What should you use?

A.Data Loss Prevention reports.
B.eDiscovery (Premium) case.
C.Content search in Microsoft Purview.
D.Audit log search in Microsoft Purview.
AnswerD

Audit log search in Microsoft Purview retains SharePoint Online file-access events for 90 days by default, letting you filter on the specific document and retrieve the users who opened it. This directly satisfies the 90-day historical access requirement, which standard SharePoint site analytics cannot provide.

Why this answer

Audit log search in Microsoft Purview is the correct tool because it queries the unified audit log, which records user activities such as file access, download, and sharing events across SharePoint Online and OneDrive for Business. The 'Accessed file' and 'FileAccessed' operations are captured with the user identity, timestamp, and item path, allowing you to filter by date range (up to 90 days by default, extendable to 1 year with the right license) and by the specific document URL. This directly answers the requirement to see *who* accessed a *specific document* over a defined period.

Exam trap

MS-102 often tests the confusion between content discovery tools (Content search, eDiscovery) that find *what* is in a file versus activity auditing tools (Audit log search) that reveal *who did what*—candidates incorrectly pick Content search because it also lives in Microsoft Purview and can target a specific document.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention reports surface policy match events (e.g., sensitive info types detected in content) and alert volumes, not a per-user access history of a specific file; DLP does not log every read of a document unless a policy explicitly triggers. Option B is wrong because an eDiscovery (Premium) case is designed for legal hold, custodial data collection, review sets, and analytics for litigation—it can search content but does not provide an access-audit trail of who opened a file and when. Option C is wrong because Content search in Microsoft Purview queries the content index (keywords, properties, sensitive info types) to find items, not to report user access events; it returns the documents themselves, not the activity log.

99
MCQmedium

Your organization uses Microsoft Purview to classify and protect data. You need to create a custom sensitive info type that detects employee IDs formatted as 'EMP-XXXXX' where X is a digit. Which approach should you use?

A.Create a custom sensitive info type using a regular expression.
B.Use a keyword dictionary for the pattern.
C.Use exact data match (EDM) based classification.
D.Use the built-in 'Employee ID' sensitive info type.
AnswerA

Creating a custom sensitive info type (SIT) with a regular expression is the correct approach when your organization's employee ID follows a specific, predictable pattern (e.g., a prefix like “EMP-” followed by digits). In Microsoft Purview, a custom SIT lets you define a regex-based pattern that directly matches that format, and you can further refine detection with corroborative keywords, character proximity, and confidence levels. This allows DLP policies to precisely identify the data without relying on an exhaustive list of known values.

Why this answer

A custom sensitive info type using a regular expression is the best way to define the pattern 'EMP-XXXXX' (where X is a digit). Option B is incorrect because a keyword dictionary is used for exact word matching, not pattern matching. Option C is incorrect because Exact Data Match (EDM) requires a source of exact data values, not a pattern.

Option D is incorrect because the built-in 'Employee ID' sensitive info type may not match this specific format.

100
MCQmedium

A legal hold is required for all emails in a user's mailbox related to a litigation case. The administrator needs to ensure that the mailbox content is preserved even if the user tries to delete emails. Which Microsoft Purview feature should be used?

A.Litigation Hold
B.eDiscovery (Standard) case hold
C.Retention policy
D.In-Place Hold
AnswerA

Litigation Hold is a dedicated hold feature in Exchange Online (under Microsoft Purview) that preserves an entire mailbox in-place, including all deleted and edited items, by maintaining copies in the Recoverable Items folder. It applies instantly and remains in effect until explicitly removed, making it the precise mechanism for legally requiring every email in a user's mailbox to be retained. Unlike policy-based deletion or case-scoped holds, Litigation Hold is designed for indefinite, mailbox-wide legal preservation without requiring a separate eDiscovery case.

Why this answer

Litigation Hold is the correct choice because it is a Microsoft Purview feature specifically designed to preserve all mailbox content, including deleted items and original versions of modified items, for legal or compliance purposes. When enabled, it places the user's entire mailbox on hold, preventing permanent deletion by the user or automated processes, and ensures that all data related to a litigation case is retained indefinitely until the hold is removed.

Exam trap

The trap here is that candidates often confuse Litigation Hold with eDiscovery case holds or retention policies, but Litigation Hold is the simplest and most direct feature for preserving an entire mailbox indefinitely for legal purposes, without needing to create a case or define retention rules.

How to eliminate wrong answers

Option B (eDiscovery (Standard) case hold) is wrong because it is used to preserve content for a specific eDiscovery case, but it requires creating an eDiscovery case and associating a hold with that case, which is more complex and not the simplest direct method for a single user's mailbox in a litigation scenario. Option C (Retention policy) is wrong because retention policies are designed for managing data lifecycle based on age or other criteria, not for indefinite preservation in response to a legal hold, and they can allow deletion after a specified period. Option D (In-Place Hold) is wrong because In-Place Hold is a legacy Exchange Online feature that has been deprecated in favor of Litigation Hold and eDiscovery holds; it is no longer available in modern Microsoft Purview deployments.

101
MCQhard

Your company is migrating from an on-premises file server to SharePoint Online. You need to ensure that files containing personally identifiable information (PII) are automatically detected and classified with a sensitivity label. What should you use?

A.A retention label auto-applied by a trainable classifier.
B.Microsoft Information Protection scanner.
C.A DLP policy to block sharing of PII.
D.Auto-labeling for sensitivity labels in Microsoft 365.
AnswerD

Auto-labeling can scan SharePoint sites and apply labels automatically.

Why this answer

Auto-labeling for sensitivity labels in Microsoft 365 uses the same sensitive information types (SITs) and trainable classifiers that power DLP, but its purpose is to apply a sensitivity label rather than block or retain content. When files are uploaded to SharePoint Online, the service-side auto-labeling policy evaluates them against the configured rules and stamps the matching label, which then drives encryption, watermarking, and access controls. This is the only option that both detects PII and applies a sensitivity label automatically.

Exam trap

MS-102 often tests the confusion between DLP policies, retention labels, and sensitivity labels, so candidates must remember that only auto-labeling for sensitivity labels actually applies a sensitivity label to content; DLP only enforces actions like block or notify.

How to eliminate wrong answers

Option A is wrong because a retention label controls how long content is kept or deleted, not how it is classified for protection; a trainable classifier can trigger a retention label, but that does not produce a sensitivity label. Option B is wrong because the Microsoft Information Protection scanner is an on-premises discovery and labeling tool for file shares and repositories, not for SharePoint Online, and it does not automatically label cloud content. Option C is wrong because a DLP policy detects PII and can block or warn on sharing, but it does not apply a sensitivity label to the file.

102
MCQhard

An administrator is creating a Microsoft Purview auto-labeling policy for documents containing personally identifiable information. Before turning the policy on automatically, what should the administrator do to reduce false positives?

A.Run the auto-labeling policy in simulation mode and review matches
B.Publish the label directly to all users and enable automatic application immediately
C.Create an eDiscovery hold for the SharePoint locations
D.Configure a retention policy before creating the sensitivity label
AnswerA

Running the auto-labeling policy in simulation mode is the essential first step because it executes the policy's detection logic against actual content without applying any labels, producing a match report that shows which items would have been labeled and which conditions triggered the match. Reviewing this output lets you validate whether the sensitive information types, conditions, and exclusions are correctly scoped, and tune them to reduce false positives. Only after simulation confirms accurate matches should the policy be switched to enforcement mode, preventing mass mislabeling at scale.

Why this answer

Running the auto-labeling policy in simulation mode allows the administrator to review which documents would be matched by the policy without actually applying labels. This enables analysis of the detection results to identify and reduce false positives before enabling automatic application, ensuring the policy accurately targets only documents containing the specified PII.

Exam trap

The trap here is that candidates may confuse simulation mode with other compliance features like eDiscovery or retention, or assume that immediate application is safe because the policy uses predefined PII types, but Microsoft explicitly recommends simulation mode to validate and reduce false positives before enabling automatic labeling.

How to eliminate wrong answers

Option B is wrong because publishing the label to all users and enabling automatic application immediately skips the validation step, leading to potential false positives and incorrect labeling across the tenant. Option C is wrong because an eDiscovery hold is used to preserve content for legal or investigative purposes, not to test or refine auto-labeling policy accuracy. Option D is wrong because configuring a retention policy before creating the sensitivity label does not address false positives; retention policies manage data lifecycle, not classification accuracy.

103
MCQmedium

You are the Microsoft 365 administrator for Fabrikam Inc. The compliance team needs to investigate a suspected data leak involving a former employee. They must preserve all mailbox content and SharePoint Online documents related to the employee for litigation. They also need to search for specific keywords across these locations. Which Microsoft Purview solution should they use?

A.Microsoft Purview Records Management with a retention label applied to the employee's content.
B.Microsoft Purview Data Loss Prevention (DLP) with a policy for the employee's mailbox.
C.Microsoft Purview eDiscovery (Standard) with a case hold and a search.
D.Microsoft Purview Communication Compliance with a policy monitoring the employee's communications.
AnswerC

eDiscovery (Standard) allows you to create a case, place a hold on Exchange mailboxes and SharePoint sites, and perform searches for keywords. It supports the required preservation and search capabilities for litigation. This is the appropriate solution for the described scenario.

Why this answer

The requirement is to preserve mailbox and SharePoint content and search for keywords as part of a litigation investigation. Microsoft Purview eDiscovery (Standard) provides case management, hold capabilities for Exchange and SharePoint, and search functionality. It is designed for legal investigations, unlike DLP, Records Management, or Communication Compliance, which serve different purposes.

Exam trap

The trap here is confusing retention or compliance monitoring tools with eDiscovery, which is specifically built for legal hold and investigative search.

104
MCQhard

Refer to the exhibit. You have two DLP compliance rules as shown. A user sends an email containing both PII and credit card numbers. Which rule will be applied?

A.Block PII rule only
B.Block Credit Cards rule only
C.Neither rule will apply because they conflict.
D.Both rules will be evaluated, and the most restrictive action will be applied.
AnswerD

This is correct because Microsoft 365 DLP evaluates all rules in a policy against the content and then applies the most restrictive action among those that match. Since both the Block PII rule and the Block Credit Cards rule include a Block action, the block is enforced for any matching content. This design ensures that layered protections do not weaken each other and that the highest severity action always wins.

Why this answer

When multiple DLP rules match the same email, Microsoft Purview evaluates all matching rules and applies the most restrictive action among them. In this case, both the PII rule and the Credit Cards rule match, so the action with the highest restriction (e.g., Block over Notify) is enforced. This ensures that sensitive data is protected even when multiple policies overlap.

Exam trap

The trap is assuming DLP rules conflict or that only the first matching rule applies — the exam tests whether you know that all matching rules are evaluated and the most restrictive action is enforced.

How to eliminate wrong answers

Option A is wrong because DLP does not stop evaluating after the first match — it evaluates all rules and takes the most restrictive outcome, so the PII rule alone is not the final decision. Option B is wrong for the same reason: the Credit Cards rule is not the only one applied; both are evaluated and the stricter action wins. Option C is wrong because DLP rules do not conflict in a way that disables enforcement — overlapping rules are resolved by taking the most restrictive action, not by ignoring both.

← PreviousPage 2 of 2 · 104 questions total

Ready to test yourself?

Try a timed practice session using only Manage compliance by using Microsoft Purview questions.