Microsoft SC-401 Data Classification Sensitive Information Types And Classifiers Practice Test

 

Skill 1.1 • 80 original questions

This Microsoft SC-401 practice test focuses on data classification sensitive information types and classifiers through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

A compliance exception at Alpine Ski House can be closed only after the tenant can create and manage custom sensitive info types for regulated case records. What should the administrator implement if the goal is to keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The pilot starts with 68 users and expands only after the security team signs off.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: C

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 2

A pilot at Consolidated Messenger involves email messages. The security lead asks for a configuration that will create and manage trainable classifiers. Which approach best satisfies the requirement and helps keep policy behavior predictable? The security lead wants the configuration to align with the supported Microsoft workflow. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The initial scope covers 105 managed objects and must remain measurable during rollout.

  1. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  2. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  3. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  4. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: B

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

C: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 3

The engineering team at Fourth Coffee has two competing proposals for employee files. Only one directly enables the tenant to monitor data classification and label usage by using Data explorer and Content explorer. Which proposal should be chosen to preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The team has 142 historical events available for validation before enabling broader enforcement.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: A

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

B: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 4

For a new Microsoft 365 deployment at Litware, the collaboration services team is responsible for scanned forms. They are required to translate sensitive information requirements into built-in or custom sensitive info types. Which implementation is correct if they also want to reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The initial scope covers 179 managed objects and must remain measurable during rollout.

  1. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: D

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 5

A proof of concept at Wide World Importers will be accepted only if it can create and manage exact data match based sensitive information types (EDM) for regulated case records. The architect also wants to use the narrowest effective control. Which option should be selected? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 35 protected items have been processed.

  1. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  2. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Change the Microsoft Entra Conditional Access policy for all users.
  5. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Correct answer: E

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

E: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 6

A Microsoft 365 administrator at Adventure Works is asked to improve protection of customer records. The success criterion is to configure optical character recognition (OCR) support for sensitive info types. What should be done if the implementation must keep the design auditable? The implementation will be reviewed by both security and compliance stakeholders. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The initial scope covers 72 managed objects and must remain measurable during rollout.

  1. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: A

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 7

The collaboration services team at Contoso has two competing proposals for cloud application files. Only one directly enables the tenant to implement document fingerprinting. Which proposal should be chosen to reduce false positives? The team wants the change to be reversible during pilot testing. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Only the users and workloads named in the requirement should be affected during the first production phase. The rollout plan requires a measurable checkpoint after 109 protected items have been processed.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: E

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 8

The governance board at Adventure Works approves a control for contract documents on the condition that administrators can identify sensitive information requirements for an organization’s data. What should the team do to use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-1-008 and will be reviewed after the first week.

  1. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  2. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Correct answer: B

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 9

Graphic Design Institute’s security operations team is updating controls for engineering designs. The requirement is to translate sensitive information requirements into built-in or custom sensitive info types. The solution must also support investigation evidence. Which action should the administrator take? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The team has 183 historical events available for validation before enabling broader enforcement.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Correct answer: B

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

C: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 10

A production issue at Contoso affects the handling of employee files. The root requirement is to create and manage custom sensitive info types. Which remediation best meets that requirement and helps keep the design auditable? The implementation will be reviewed by both security and compliance stakeholders. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The pilot starts with 39 users and expands only after the security team signs off.

  1. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Correct answer: B

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 11

Before enabling enforcement at A. Datum, administrators must demonstrate how they will monitor data classification and label usage by using Data explorer and Content explorer for scanned forms. Which configuration should they use to avoid unnecessary user disruption? The control must work with the organization’s existing Microsoft 365 governance model. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Only the users and workloads named in the requirement should be affected during the first production phase. The implementation will be tested against 76 representative files or events before sign-off.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: D

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 12

The data governance group at Tailspin Toys is preparing a production rollout involving email messages. They specifically need to create and manage trainable classifiers. What should be configured first to avoid changing unrelated workloads? The organization wants to avoid granting broader permissions than the task requires. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-1-012 before widening scope.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  5. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Correct answer: B

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 13

Proseware is standardizing protection for employee files. The design must configure optical character recognition (OCR) support for sensitive info types, and operations wants to reduce false positives. What should the information security administrator do? The security lead wants the configuration to align with the supported Microsoft workflow. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 150 protected items have been processed.

  1. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  2. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: E

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 14

The legal team at Blue Yonder Airlines has two competing proposals for cloud application files. Only one directly enables the tenant to monitor data classification and label usage by using Data explorer and Content explorer. Which proposal should be chosen to preserve least privilege? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 187 representative samples before production enablement.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Change the Microsoft Entra Conditional Access policy for all users.
  5. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: B

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 15

Northwind Traders is standardizing protection for customer records. The design must create and manage custom sensitive info types, and operations wants to support investigation evidence. What should the information security administrator do? Administrators need evidence they can review after deployment. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The first phase affects 43 users across two business units and must preserve normal collaboration.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  5. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Correct answer: D

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

E: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 16

Woodgrove Bank expects the volume of cloud application files to increase significantly. The control must scale while allowing the team to translate sensitive information requirements into built-in or custom sensitive info types. Which action best supports that objective and helps support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The change is tracked under control batch SC401-1-016 and will be reviewed after the first week.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Correct answer: E

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 17

A security design workshop at Alpine Ski House focuses on cloud application files. One mandatory capability is to configure optical character recognition (OCR) support for sensitive info types. Which answer best aligns with Microsoft Purview while helping preserve least privilege? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The first phase affects 117 users across two business units and must preserve normal collaboration.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: B

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 18

A pilot at Wide World Importers involves contract documents. The security lead asks for a configuration that will translate sensitive information requirements into built-in or custom sensitive info types. Which approach best satisfies the requirement and helps preserve least privilege? Administrators need evidence they can review after deployment. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The pilot starts with 154 users and expands only after the security team signs off.

  1. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: A

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 19

The governance board at Fourth Coffee approves a control for cloud application files on the condition that administrators can create and manage custom sensitive info types. What should the team do to keep the design auditable? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 191 users across two business units and must preserve normal collaboration.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.

Correct answer: A

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 20

  1. Datum expects the volume of scanned forms to increase significantly. The control must scale while allowing the team to create and manage trainable classifiers. Which action best supports that objective and helps support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 47 users across two business units and must preserve normal collaboration.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Change the Microsoft Entra Conditional Access policy for all users.
  6. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: E

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 21

Following a policy review, Margie’s Travel changes how contract documents is governed. The new requirement is to create and manage trainable classifiers. Which action is the best fit and will help use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The first phase affects 84 users across two business units and must preserve normal collaboration.

  1. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  2. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Correct answer: A

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

B: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 22

A compliance exception at Fourth Coffee can be closed only after the tenant can create and manage custom sensitive info types for contract documents. What should the administrator implement if the goal is to keep policy behavior predictable? The design should not depend on users remembering an optional manual step. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The design review compares outcomes for 121 representative samples before production enablement.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.

Correct answer: A

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 23

A Microsoft 365 administrator at Alpine Ski House is asked to improve protection of customer records. The success criterion is to create and manage exact data match based sensitive information types (EDM). What should be done if the implementation must avoid unnecessary user disruption? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The rollout plan requires a measurable checkpoint after 158 protected items have been processed.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: C

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 24

A change request from Trey Research’s IT operations department affects regulated case records. The stated objective is to monitor data classification and label usage by using Data explorer and Content explorer. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The initial scope covers 195 managed objects and must remain measurable during rollout.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Correct answer: A

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 25

An incident review at Fourth Coffee shows that the current process for financial workbooks is incomplete. The team now needs to create and manage exact data match based sensitive information types (EDM). Which action most directly addresses that need while helping avoid unnecessary user disruption? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Only the users and workloads named in the requirement should be affected during the first production phase. The design review compares outcomes for 51 representative samples before production enablement.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  4. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: D

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 26

At Graphic Design Institute, a review of scanned forms found a gap. The administrator must create and manage trainable classifiers, while the project team wants to support a phased rollout. What is the best next step? The security lead wants the configuration to align with the supported Microsoft workflow. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 88 protected items have been processed.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: E

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 27

A proof of concept at Blue Yonder Airlines will be accepted only if it can implement document fingerprinting for financial workbooks. The architect also wants to avoid unnecessary user disruption. Which option should be selected? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 125 policy evaluations to confirm expected behavior.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: B

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 28

The governance board at Wingtip Toys approves a control for email messages on the condition that administrators can translate sensitive information requirements into built-in or custom sensitive info types. What should the team do to minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 162 historical events available for validation before enabling broader enforcement.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: C

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 29

During an audit at Wingtip Toys, reviewers ask how the tenant will create and manage custom sensitive info types. The implementation should support a phased rollout. Which choice is most appropriate? The requirement applies to production data rather than a one-time demonstration. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The implementation will be tested against 199 representative files or events before sign-off.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  4. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: A

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 30

Before enabling enforcement at Margie’s Travel, administrators must demonstrate how they will configure optical character recognition (OCR) support for sensitive info types for cloud application files. Which configuration should they use to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The change is tracked under control batch SC401-1-030 and will be reviewed after the first week.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Correct answer: B

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 31

The compliance group at A. Datum is preparing a production rollout involving scanned forms. They specifically need to configure optical character recognition (OCR) support for sensitive info types. What should be configured first to reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 92 protected items have been processed.

  1. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Correct answer: A

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 32

Margie’s Travel is standardizing protection for engineering designs. The design must create and manage exact data match based sensitive information types (EDM), and operations wants to avoid unnecessary user disruption. What should the information security administrator do? The team wants the change to be reversible during pilot testing. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 129 policy evaluations to confirm expected behavior.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: B

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

C: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 33

A change request from Tailspin Toys’s legal department affects employee files. The stated objective is to configure optical character recognition (OCR) support for sensitive info types. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-1-033 and will be reviewed after the first week.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: E

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 34

Litware is replacing a manual process used by the security operations team for Teams collaboration content. The replacement must create and manage exact data match based sensitive information types (EDM). Which choice provides the most direct implementation while helping preserve least privilege? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The initial scope covers 22 managed objects and must remain measurable during rollout.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: A

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 35

A security design workshop at Northwind Traders focuses on cloud application files. One mandatory capability is to create and manage trainable classifiers. Which answer best aligns with Microsoft Purview while helping minimize administrative overhead? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The initial scope covers 59 managed objects and must remain measurable during rollout.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  3. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  4. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: C

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

D: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 36

An incident review at Tailspin Toys shows that the current process for financial workbooks is incomplete. The team now needs to translate sensitive information requirements into built-in or custom sensitive info types. Which action most directly addresses that need while helping avoid unnecessary user disruption? The pilot population is small today but the configuration must support a broader rollout. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. A support team will observe the first 96 policy evaluations to confirm expected behavior.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: B

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 37

Northwind Traders’s risk management team is updating controls for engineering designs. The requirement is to identify sensitive information requirements for an organization’s data. The solution must also minimize administrative overhead. Which action should the administrator take? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The pilot starts with 133 users and expands only after the security team signs off.

  1. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: D

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 38

Consolidated Messenger expects the volume of customer records to increase significantly. The control must scale while allowing the team to create and manage trainable classifiers. Which action best supports that objective and helps avoid changing unrelated workloads? The security lead wants the configuration to align with the supported Microsoft workflow. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The design review compares outcomes for 170 representative samples before production enablement.

  1. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: C

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 39

An incident review at Fabrikam shows that the current process for regulated case records is incomplete. The team now needs to monitor data classification and label usage by using Data explorer and Content explorer. Which action most directly addresses that need while helping avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-1-039 and will be reviewed after the first week.

  1. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: B

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

C: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 40

At Graphic Design Institute, a review of scanned forms found a gap. The administrator must monitor data classification and label usage by using Data explorer and Content explorer, while the project team wants to preserve least privilege. What is the best next step? The control must work with the organization’s existing Microsoft 365 governance model. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The team has 63 historical events available for validation before enabling broader enforcement.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  3. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Correct answer: C

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 41

A Microsoft 365 administrator at Fabrikam is asked to improve protection of Teams collaboration content. The success criterion is to translate sensitive information requirements into built-in or custom sensitive info types. What should be done if the implementation must keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 100 protected items have been processed.

  1. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: A

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 42

A security design workshop at Wingtip Toys focuses on scanned forms. One mandatory capability is to implement document fingerprinting. Which answer best aligns with Microsoft Purview while helping use the narrowest effective control? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 137 protected items have been processed.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.

Correct answer: B

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 43

A production issue at Humongous Insurance affects the handling of regulated case records. The root requirement is to identify sensitive information requirements for an organization’s data. Which remediation best meets that requirement and helps support investigation evidence? The security lead wants the configuration to align with the supported Microsoft workflow. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. Only the users and workloads named in the requirement should be affected during the first production phase. The control owner must document the result for governance record SC401-1-043 before widening scope.

  1. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  2. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.

Correct answer: B

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 44

A proof of concept at Fourth Coffee will be accepted only if it can create and manage custom sensitive info types for financial workbooks. The architect also wants to avoid changing unrelated workloads. Which option should be selected? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-1-044 and will be reviewed after the first week.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: B

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 45

During an audit at Wingtip Toys, reviewers ask how the tenant will monitor data classification and label usage by using Data explorer and Content explorer. The implementation should reduce false positives. Which choice is most appropriate? The requirement applies to production data rather than a one-time demonstration. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The initial scope covers 67 managed objects and must remain measurable during rollout.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: A

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 46

A compliance exception at Wingtip Toys can be closed only after the tenant can translate sensitive information requirements into built-in or custom sensitive info types for email messages. What should the administrator implement if the goal is to keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 104 protected items have been processed.

  1. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: D

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 47

For a new Microsoft 365 deployment at Proseware, the data governance team is responsible for customer records. They are required to create and manage trainable classifiers. Which implementation is correct if they also want to keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 141 historical events available for validation before enabling broader enforcement.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: E

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 48

The governance board at Margie’s Travel approves a control for email messages on the condition that administrators can monitor data classification and label usage by using Data explorer and Content explorer. What should the team do to reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 178 users across two business units and must preserve normal collaboration.

  1. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: E

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 49

Before enabling enforcement at Wide World Importers, administrators must demonstrate how they will implement document fingerprinting for regulated case records. Which configuration should they use to minimize administrative overhead? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 34 protected items have been processed.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  5. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Correct answer: C

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

D: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 50

A compliance exception at Fourth Coffee can be closed only after the tenant can create and manage custom sensitive info types for email messages. What should the administrator implement if the goal is to preserve least privilege? The team wants the change to be reversible during pilot testing. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The team has 71 historical events available for validation before enabling broader enforcement.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: C

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 51

A security design workshop at Blue Yonder Airlines focuses on contract documents. One mandatory capability is to create and manage exact data match based sensitive information types (EDM). Which answer best aligns with Microsoft Purview while helping keep policy behavior predictable? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The team has 108 historical events available for validation before enabling broader enforcement.

  1. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Correct answer: E

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 52

Litware’s data governance team is updating controls for customer records. The requirement is to create and manage trainable classifiers. The solution must also reduce false positives. Which action should the administrator take? The team wants the change to be reversible during pilot testing. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-1-052 before widening scope.

  1. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  2. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  5. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.

Correct answer: D

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

E: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 53

The security operations group at Litware is preparing a production rollout involving financial workbooks. They specifically need to implement document fingerprinting. What should be configured first to support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The design review compares outcomes for 182 representative samples before production enablement.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  3. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: B

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 54

A Microsoft 365 administrator at Wide World Importers is asked to improve protection of scanned forms. The success criterion is to identify sensitive information requirements for an organization’s data. What should be done if the implementation must support a phased rollout? The design should not depend on users remembering an optional manual step. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 38 historical events available for validation before enabling broader enforcement.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: C

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

D: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 55

The collaboration services group at Northwind Traders is preparing a production rollout involving financial workbooks. They specifically need to create and manage exact data match based sensitive information types (EDM). What should be configured first to minimize administrative overhead? The organization wants to avoid granting broader permissions than the task requires. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The control owner must document the result for governance record SC401-1-055 before widening scope.

  1. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: C

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 56

For a new Microsoft 365 deployment at Wingtip Toys, the collaboration services team is responsible for scanned forms. They are required to identify sensitive information requirements for an organization’s data. Which implementation is correct if they also want to preserve least privilege? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. A support team will observe the first 112 policy evaluations to confirm expected behavior.

  1. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: A

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 57

Consolidated Messenger’s sales team is updating controls for engineering designs. The requirement is to implement document fingerprinting. The solution must also avoid changing unrelated workloads. Which action should the administrator take? The design should not depend on users remembering an optional manual step. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 149 protected items have been processed.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: E

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 58

Wide World Importers expects the volume of regulated case records to increase significantly. The control must scale while allowing the team to create and manage custom sensitive info types. Which action best supports that objective and helps avoid unnecessary user disruption? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 186 protected items have been processed.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  3. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: A

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

B: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 59

Fourth Coffee expects the volume of SharePoint documents to increase significantly. The control must scale while allowing the team to translate sensitive information requirements into built-in or custom sensitive info types. Which action best supports that objective and helps support a phased rollout? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Only the users and workloads named in the requirement should be affected during the first production phase. The first phase affects 42 users across two business units and must preserve normal collaboration.

  1. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  5. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Correct answer: E

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 60

Wide World Importers’s finance team is updating controls for Teams collaboration content. The requirement is to identify sensitive information requirements for an organization’s data. The solution must also avoid changing unrelated workloads. Which action should the administrator take? The organization wants to avoid granting broader permissions than the task requires. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-1-060 and will be reviewed after the first week.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: B

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 61

Adventure Works expects the volume of email messages to increase significantly. The control must scale while allowing the team to create and manage trainable classifiers. Which action best supports that objective and helps preserve least privilege? Administrators need evidence they can review after deployment. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The first phase affects 116 users across two business units and must preserve normal collaboration.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: D

Why: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This directly matches the requirement in the scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Question 62

Humongous Insurance expects the volume of regulated case records to increase significantly. The control must scale while allowing the team to identify sensitive information requirements for an organization’s data. Which action best supports that objective and helps support a phased rollout? The requirement applies to production data rather than a one-time demonstration. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The initial scope covers 153 managed objects and must remain measurable during rollout.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: C

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 63

At Proseware, a review of Teams collaboration content found a gap. The administrator must create and manage exact data match based sensitive information types (EDM), while the project team wants to support a phased rollout. What is the best next step? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 190 users and expands only after the security team signs off.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: B

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 64

During an audit at Humongous Insurance, reviewers ask how the tenant will create and manage custom sensitive info types. The implementation should avoid unnecessary user disruption. Which choice is most appropriate? The team must be able to explain why the selected control addresses the stated risk. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. A support team will observe the first 46 policy evaluations to confirm expected behavior.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Correct answer: A

Why: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This directly matches the requirement in the scenario.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Question 65

The governance board at Woodgrove Bank approves a control for support tickets on the condition that administrators can implement document fingerprinting. What should the team do to keep the design auditable? The design should not depend on users remembering an optional manual step. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 83 historical events available for validation before enabling broader enforcement.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  4. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: E

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 66

A compliance exception at Fabrikam can be closed only after the tenant can identify sensitive information requirements for an organization’s data for scanned forms. What should the administrator implement if the goal is to avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 120 representative samples before production enablement.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  5. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Correct answer: E

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 67

During an audit at Consolidated Messenger, reviewers ask how the tenant will identify sensitive information requirements for an organization’s data. The implementation should reduce false positives. Which choice is most appropriate? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-1-067 and will be reviewed after the first week.

  1. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  2. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: A

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

B: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 68

Before enabling enforcement at Proseware, administrators must demonstrate how they will configure optical character recognition (OCR) support for sensitive info types for support tickets. Which configuration should they use to reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The first phase affects 194 users across two business units and must preserve normal collaboration.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Change the Microsoft Entra Conditional Access policy for all users.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: B

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 69

A security design workshop at Fourth Coffee focuses on employee files. One mandatory capability is to implement document fingerprinting. Which answer best aligns with Microsoft Purview while helping keep the design auditable? Administrators need evidence they can review after deployment. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Only the users and workloads named in the requirement should be affected during the first production phase. The design review compares outcomes for 50 representative samples before production enablement.

  1. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: A

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 70

At City Power & Light, a review of employee files found a gap. The administrator must monitor data classification and label usage by using Data explorer and Content explorer, while the project team wants to avoid changing unrelated workloads. What is the best next step? The organization wants to avoid granting broader permissions than the task requires. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 87 managed objects and must remain measurable during rollout.

  1. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: E

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 71

The finance team at A. Datum has two competing proposals for regulated case records. Only one directly enables the tenant to monitor data classification and label usage by using Data explorer and Content explorer. Which proposal should be chosen to avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 124 protected items have been processed.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  4. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: E

Why: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This directly matches the requirement in the scenario.

Learning point: Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Question 72

Following a policy review, Tailspin Toys changes how customer records is governed. The new requirement is to implement document fingerprinting. Which action is the best fit and will help keep the design auditable? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The team has 161 historical events available for validation before enabling broader enforcement.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: E

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 73

A proof of concept at Consolidated Messenger will be accepted only if it can configure optical character recognition (OCR) support for sensitive info types for financial workbooks. The architect also wants to preserve least privilege. Which option should be selected? The security lead wants the configuration to align with the supported Microsoft workflow. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The implementation will be tested against 198 representative files or events before sign-off.

  1. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: B

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 74

Humongous Insurance is standardizing protection for support tickets. The design must create and manage exact data match based sensitive information types (EDM), and operations wants to keep the design auditable. What should the information security administrator do? The security lead wants the configuration to align with the supported Microsoft workflow. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-1-074 and will be reviewed after the first week.

  1. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: C

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 75

An incident review at Adventure Works shows that the current process for contract documents is incomplete. The team now needs to create and manage exact data match based sensitive information types (EDM). Which action most directly addresses that need while helping avoid changing unrelated workloads? Administrators need evidence they can review after deployment. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 91 users across two business units and must preserve normal collaboration.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.

Correct answer: A

Why: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This directly matches the requirement in the scenario.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.

Question 76

Following a policy review, Litware changes how SharePoint documents is governed. The new requirement is to identify sensitive information requirements for an organization’s data. Which action is the best fit and will help support a phased rollout? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 128 historical events available for validation before enabling broader enforcement.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  5. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Correct answer: E

Why: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This directly matches the requirement in the scenario.

Learning point: Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Question 77

An incident review at Consolidated Messenger shows that the current process for customer records is incomplete. The team now needs to configure optical character recognition (OCR) support for sensitive info types. Which action most directly addresses that need while helping reduce false positives? The team must be able to explain why the selected control addresses the stated risk. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The initial scope covers 165 managed objects and must remain measurable during rollout.

  1. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  2. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: A

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

B: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Question 78

A compliance exception at Wingtip Toys can be closed only after the tenant can implement document fingerprinting for scanned forms. What should the administrator implement if the goal is to preserve least privilege? Administrators need evidence they can review after deployment. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The initial scope covers 21 managed objects and must remain measurable during rollout.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: C

Why: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This directly matches the requirement in the scenario.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Question 79

  1. Datum is standardizing protection for scanned forms. The design must translate sensitive information requirements into built-in or custom sensitive info types, and operations wants to support investigation evidence. What should the information security administrator do? The pilot population is small today but the configuration must support a broader rollout. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The design review compares outcomes for 58 representative samples before production enablement.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Create a Microsoft Sentinel analytics rule for the activity.
  6. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: A

Why: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This directly matches the requirement in the scenario.

B: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Question 80

An incident review at Humongous Insurance shows that the current process for scanned forms is incomplete. The team now needs to configure optical character recognition (OCR) support for sensitive info types. Which action most directly addresses that need while helping minimize administrative overhead? The design should not depend on users remembering an optional manual step. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The implementation will be tested against 95 representative files or events before sign-off.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: B

Why: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This directly matches the requirement in the scenario.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Popular posts

img