Microsoft SC-401 Sensitivity Labels Publishing Auto Labeling And Cloud Apps Practice Test

 

Skill 1.2 • 70 original questions

This Microsoft SC-401 practice test focuses on sensitivity labels publishing auto labeling and cloud apps through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

Before enabling enforcement at Wingtip Toys, administrators must demonstrate how they will apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint for financial workbooks. Which configuration should they use to support a phased rollout? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The initial scope covers 79 managed objects and must remain measurable during rollout.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Correct answer: A

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 2

A change request from Litware’s compliance department affects cloud application files. The stated objective is to configure and manage auto-labeling policies for sensitivity labels. Which administrative action is the strongest fit if the team must support a phased rollout? The team wants the change to be reversible during pilot testing. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 116 representative files or events before sign-off.

  1. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  5. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Correct answer: E

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 3

A Microsoft 365 administrator at Consolidated Messenger is asked to improve protection of cloud application files. The success criterion is to configure and manage publishing policies for sensitivity labels. What should be done if the implementation must minimize administrative overhead? The design should not depend on users remembering an optional manual step. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The implementation will be tested against 153 representative files or events before sign-off.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  3. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  4. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: B

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

C: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 4

A change request from Consolidated Messenger’s IT operations department affects support tickets. The stated objective is to apply sensitivity labels by using Microsoft Defender for Cloud Apps. Which administrative action is the strongest fit if the team must minimize administrative overhead? Administrators need evidence they can review after deployment. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The design review compares outcomes for 190 representative samples before production enablement.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  4. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  5. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Correct answer: D

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

E: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 5

The finance group at Litware is preparing a production rollout involving contract documents. They specifically need to configure and manage auto-labeling policies for sensitivity labels. What should be configured first to keep the design auditable? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The change is tracked under control batch SC401-2-005 and will be reviewed after the first week.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: D

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 6

The legal team at Margie’s Travel has two competing proposals for employee files. Only one directly enables the tenant to configure protection settings and content marking for sensitivity labels. Which proposal should be chosen to support investigation evidence? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-2-006 and will be reviewed after the first week.

  1. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: D

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 7

Adventure Works expects the volume of email messages to increase significantly. The control must scale while allowing the team to configure protection settings and content marking for sensitivity labels. Which action best supports that objective and helps support a phased rollout? The team must be able to explain why the selected control addresses the stated risk. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The control owner must document the result for governance record SC401-2-007 before widening scope.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  5. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.

Correct answer: C

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

D: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 8

Alpine Ski House expects the volume of email messages to increase significantly. The control must scale while allowing the team to configure protection settings and content marking for sensitivity labels. Which action best supports that objective and helps support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 157 users and expands only after the security team signs off.

  1. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  2. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  5. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Correct answer: E

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 9

For a new Microsoft 365 deployment at Margie’s Travel, the data governance team is responsible for regulated case records. They are required to implement roles and permissions for administering sensitivity labels. Which implementation is correct if they also want to support a phased rollout? The requirement applies to production data rather than a one-time demonstration. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. Only the users and workloads named in the requirement should be affected during the first production phase. The design review compares outcomes for 194 representative samples before production enablement.

  1. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: D

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 10

A compliance exception at Proseware can be closed only after the tenant can implement roles and permissions for administering sensitivity labels for financial workbooks. What should the administrator implement if the goal is to minimize administrative overhead? The design should not depend on users remembering an optional manual step. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The pilot starts with 50 users and expands only after the security team signs off.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Correct answer: C

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 11

A change request from A. Datum’s security operations department affects SharePoint documents. The stated objective is to apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint. Which administrative action is the strongest fit if the team must keep policy behavior predictable? The design should not depend on users remembering an optional manual step. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Only the users and workloads named in the requirement should be affected during the first production phase. The pilot starts with 87 users and expands only after the security team signs off.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: A

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 12

Humongous Insurance’s research team is updating controls for employee files. The requirement is to define and create sensitivity labels for items and containers. The solution must also avoid changing unrelated workloads. Which action should the administrator take? The team must be able to explain why the selected control addresses the stated risk. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 124 historical events available for validation before enabling broader enforcement.

  1. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  2. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  3. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: C

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 13

Fourth Coffee is replacing a manual process used by the compliance team for cloud application files. The replacement must define and create sensitivity labels for items and containers. Which choice provides the most direct implementation while helping preserve least privilege? The control must work with the organization’s existing Microsoft 365 governance model. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The pilot starts with 161 users and expands only after the security team signs off.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: B

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

C: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 14

Litware is replacing a manual process used by the human resources team for cloud application files. The replacement must configure protection settings and content marking for sensitivity labels. Which choice provides the most direct implementation while helping use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. A support team will observe the first 198 policy evaluations to confirm expected behavior.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: B

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 15

A Microsoft 365 administrator at Consolidated Messenger is asked to improve protection of employee files. The success criterion is to configure and manage publishing policies for sensitivity labels. What should be done if the implementation must reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 54 representative files or events before sign-off.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.

Correct answer: B

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 16

The governance board at Graphic Design Institute approves a control for SharePoint documents on the condition that administrators can apply sensitivity labels by using Microsoft Defender for Cloud Apps. What should the team do to reduce false positives? The organization wants to avoid granting broader permissions than the task requires. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 91 protected items have been processed.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  3. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Correct answer: E

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 17

The human resources team at Trey Research has two competing proposals for financial workbooks. Only one directly enables the tenant to configure and manage publishing policies for sensitivity labels. Which proposal should be chosen to avoid unnecessary user disruption? The control must work with the organization’s existing Microsoft 365 governance model. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The control owner must document the result for governance record SC401-2-017 before widening scope.

  1. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  4. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: A

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 18

A security design workshop at Fourth Coffee focuses on financial workbooks. One mandatory capability is to configure and manage publishing policies for sensitivity labels. Which answer best aligns with Microsoft Purview while helping support a phased rollout? The implementation will be reviewed by both security and compliance stakeholders. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 165 protected items have been processed.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: C

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 19

At Woodgrove Bank, a review of customer records found a gap. The administrator must configure protection settings and content marking for sensitivity labels, while the project team wants to reduce false positives. What is the best next step? The pilot population is small today but the configuration must support a broader rollout. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The design review compares outcomes for 21 representative samples before production enablement.

  1. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  2. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.

Correct answer: C

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 20

During an audit at Alpine Ski House, reviewers ask how the tenant will implement roles and permissions for administering sensitivity labels. The implementation should support a phased rollout. Which choice is most appropriate? The pilot population is small today but the configuration must support a broader rollout. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Only the users and workloads named in the requirement should be affected during the first production phase. The change is tracked under control batch SC401-2-020 and will be reviewed after the first week.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: A

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 21

Before enabling enforcement at Proseware, administrators must demonstrate how they will apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint for financial workbooks. Which configuration should they use to avoid changing unrelated workloads? The requirement applies to production data rather than a one-time demonstration. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 95 policy evaluations to confirm expected behavior.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Correct answer: A

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 22

A security design workshop at Humongous Insurance focuses on email messages. One mandatory capability is to implement roles and permissions for administering sensitivity labels. Which answer best aligns with Microsoft Purview while helping support investigation evidence? The organization wants to avoid granting broader permissions than the task requires. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The initial scope covers 132 managed objects and must remain measurable during rollout.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  3. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: D

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 23

A change request from Tailspin Toys’s security operations department affects support tickets. The stated objective is to apply sensitivity labels by using Microsoft Defender for Cloud Apps. Which administrative action is the strongest fit if the team must support investigation evidence? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The rollout plan requires a measurable checkpoint after 169 protected items have been processed.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  5. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.

Correct answer: B

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 24

A production issue at Wide World Importers affects the handling of SharePoint documents. The root requirement is to implement roles and permissions for administering sensitivity labels. Which remediation best meets that requirement and helps avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The first phase affects 25 users across two business units and must preserve normal collaboration.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Correct answer: A

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 25

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of regulated case records. The success criterion is to apply sensitivity labels by using Microsoft Defender for Cloud Apps. What should be done if the implementation must support investigation evidence? The implementation will be reviewed by both security and compliance stakeholders. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The pilot starts with 62 users and expands only after the security team signs off.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: B

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 26

Before enabling enforcement at Humongous Insurance, administrators must demonstrate how they will apply sensitivity labels by using Microsoft Defender for Cloud Apps for scanned forms. Which configuration should they use to use the narrowest effective control? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The change is tracked under control batch SC401-2-026 and will be reviewed after the first week.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  5. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Correct answer: D

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

E: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 27

A Microsoft 365 administrator at Fabrikam is asked to improve protection of Teams collaboration content. The success criterion is to configure and manage auto-labeling policies for sensitivity labels. What should be done if the implementation must reduce false positives? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The rollout plan requires a measurable checkpoint after 136 protected items have been processed.

  1. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  2. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: B

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 28

The collaboration services group at Consolidated Messenger is preparing a production rollout involving Teams collaboration content. They specifically need to implement roles and permissions for administering sensitivity labels. What should be configured first to support a phased rollout? The control must work with the organization’s existing Microsoft 365 governance model. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The change is tracked under control batch SC401-2-028 and will be reviewed after the first week.

  1. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: D

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 29

Before enabling enforcement at Litware, administrators must demonstrate how they will apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint for cloud application files. Which configuration should they use to reduce false positives? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 29 representative files or events before sign-off.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  4. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: C

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

D: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 30

For a new Microsoft 365 deployment at Tailspin Toys, the data governance team is responsible for SharePoint documents. They are required to configure protection settings and content marking for sensitivity labels. Which implementation is correct if they also want to avoid changing unrelated workloads? The team must be able to explain why the selected control addresses the stated risk. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 66 policy evaluations to confirm expected behavior.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Correct answer: E

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 31

A proof of concept at Wingtip Toys will be accepted only if it can apply sensitivity labels by using Microsoft Defender for Cloud Apps for Teams collaboration content. The architect also wants to support a phased rollout. Which option should be selected? The design should not depend on users remembering an optional manual step. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The implementation will be tested against 103 representative files or events before sign-off.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Correct answer: E

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 32

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of engineering designs. The success criterion is to configure and manage publishing policies for sensitivity labels. What should be done if the implementation must minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The pilot starts with 140 users and expands only after the security team signs off.

  1. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: D

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 33

An incident review at Wingtip Toys shows that the current process for regulated case records is incomplete. The team now needs to implement roles and permissions for administering sensitivity labels. Which action most directly addresses that need while helping avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 177 historical events available for validation before enabling broader enforcement.

  1. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  2. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.

Correct answer: D

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

E: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 34

A compliance exception at Northwind Traders can be closed only after the tenant can apply sensitivity labels by using Microsoft Defender for Cloud Apps for contract documents. What should the administrator implement if the goal is to reduce false positives? The organization wants to avoid granting broader permissions than the task requires. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The pilot starts with 33 users and expands only after the security team signs off.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Create a Microsoft Sentinel analytics rule for the activity.
  5. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.

Correct answer: B

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

E: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 35

A production issue at Contoso affects the handling of scanned forms. The root requirement is to configure and manage auto-labeling policies for sensitivity labels. Which remediation best meets that requirement and helps support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The pilot starts with 70 users and expands only after the security team signs off.

  1. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  2. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  3. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  4. Change the Microsoft Entra Conditional Access policy for all users.
  5. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.

Correct answer: A

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

B: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

E: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 36

The security operations group at Northwind Traders is preparing a production rollout involving contract documents. They specifically need to apply sensitivity labels by using Microsoft Defender for Cloud Apps. What should be configured first to keep policy behavior predictable? The design should not depend on users remembering an optional manual step. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The team has 107 historical events available for validation before enabling broader enforcement.

  1. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  5. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.

Correct answer: B

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 37

The governance board at Proseware approves a control for Teams collaboration content on the condition that administrators can configure and manage auto-labeling policies for sensitivity labels. What should the team do to avoid changing unrelated workloads? The design should not depend on users remembering an optional manual step. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The initial scope covers 144 managed objects and must remain measurable during rollout.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: D

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 38

Woodgrove Bank’s sales team is updating controls for regulated case records. The requirement is to apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint. The solution must also preserve least privilege. Which action should the administrator take? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The implementation will be tested against 181 representative files or events before sign-off.

  1. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: E

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 39

Wingtip Toys is replacing a manual process used by the research team for Teams collaboration content. The replacement must configure protection settings and content marking for sensitivity labels. Which choice provides the most direct implementation while helping avoid changing unrelated workloads? The security lead wants the configuration to align with the supported Microsoft workflow. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The first phase affects 37 users across two business units and must preserve normal collaboration.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  3. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  4. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  5. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Correct answer: E

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 40

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of Teams collaboration content. The success criterion is to configure and manage publishing policies for sensitivity labels. What should be done if the implementation must support a phased rollout? The design should not depend on users remembering an optional manual step. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The design review compares outcomes for 74 representative samples before production enablement.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  4. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: D

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 41

Before enabling enforcement at Woodgrove Bank, administrators must demonstrate how they will define and create sensitivity labels for items and containers for regulated case records. Which configuration should they use to avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The rollout plan requires a measurable checkpoint after 111 protected items have been processed.

  1. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  5. Change the Microsoft Entra Conditional Access policy for all users.

Correct answer: B

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 42

Graphic Design Institute is standardizing protection for customer records. The design must apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint, and operations wants to keep the design auditable. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Administrators must be able to tune the configuration later without redesigning the entire protection model. A support team will observe the first 148 policy evaluations to confirm expected behavior.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  4. Use a broad tenant-wide retention policy to keep every item for the same period.
  5. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.

Correct answer: C

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

D: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

E: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 43

A pilot at Woodgrove Bank involves customer records. The security lead asks for a configuration that will configure and manage publishing policies for sensitivity labels. Which approach best satisfies the requirement and helps use the narrowest effective control? The team must be able to explain why the selected control addresses the stated risk. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 185 historical events available for validation before enabling broader enforcement.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Correct answer: E

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 44

A proof of concept at Fourth Coffee will be accepted only if it can configure and manage auto-labeling policies for sensitivity labels for Teams collaboration content. The architect also wants to use the narrowest effective control. Which option should be selected? The pilot population is small today but the configuration must support a broader rollout. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The first phase affects 41 users across two business units and must preserve normal collaboration.

  1. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  2. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  3. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  4. Change the Microsoft Entra Conditional Access policy for all users.
  5. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Correct answer: A

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

B: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

E: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 45

Northwind Traders is standardizing protection for Teams collaboration content. The design must apply sensitivity labels by using Microsoft Defender for Cloud Apps, and operations wants to preserve least privilege. What should the information security administrator do? The design should not depend on users remembering an optional manual step. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Administrators must be able to tune the configuration later without redesigning the entire protection model. A support team will observe the first 78 policy evaluations to confirm expected behavior.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  4. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: B

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

C: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 46

An incident review at Wide World Importers shows that the current process for cloud application files is incomplete. The team now needs to define and create sensitivity labels for items and containers. Which action most directly addresses that need while helping avoid unnecessary user disruption? The pilot population is small today but the configuration must support a broader rollout. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 115 policy evaluations to confirm expected behavior.

  1. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  2. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  3. Create a Microsoft Sentinel analytics rule for the activity.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.

Correct answer: D

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

E: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 47

For a new Microsoft 365 deployment at Wingtip Toys, the finance team is responsible for cloud application files. They are required to define and create sensitivity labels for items and containers. Which implementation is correct if they also want to avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The design review compares outcomes for 152 representative samples before production enablement.

  1. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  4. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  5. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.

Correct answer: A

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 48

The collaboration services team at Wingtip Toys has two competing proposals for employee files. Only one directly enables the tenant to define and create sensitivity labels for items and containers. Which proposal should be chosen to support investigation evidence? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The pilot starts with 189 users and expands only after the security team signs off.

  1. Use a broad tenant-wide retention policy to keep every item for the same period.
  2. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Correct answer: E

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

B: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 49

Northwind Traders’s data governance team is updating controls for contract documents. The requirement is to define and create sensitivity labels for items and containers. The solution must also preserve least privilege. Which action should the administrator take? Administrators need evidence they can review after deployment. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 45 users across two business units and must preserve normal collaboration.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.

Correct answer: C

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 50

At Consolidated Messenger, a review of cloud application files found a gap. The administrator must apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint, while the project team wants to support a phased rollout. What is the best next step? The organization wants to avoid granting broader permissions than the task requires. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 82 historical events available for validation before enabling broader enforcement.

  1. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  2. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.

Correct answer: D

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

E: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 51

A pilot at Fabrikam involves financial workbooks. The security lead asks for a configuration that will configure protection settings and content marking for sensitivity labels. Which approach best satisfies the requirement and helps support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 119 protected items have been processed.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.

Correct answer: A

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 52

A security design workshop at Northwind Traders focuses on email messages. One mandatory capability is to define and create sensitivity labels for items and containers. Which answer best aligns with Microsoft Purview while helping support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-2-052 before widening scope.

  1. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  2. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.
  3. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: D

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 53

For a new Microsoft 365 deployment at Trey Research, the engineering team is responsible for email messages. They are required to implement roles and permissions for administering sensitivity labels. Which implementation is correct if they also want to reduce false positives? The design should not depend on users remembering an optional manual step. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-2-053 before widening scope.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Correct answer: C

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 54

Following a policy review, Proseware changes how email messages is governed. The new requirement is to define and create sensitivity labels for items and containers. Which action is the best fit and will help reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The first phase affects 49 users across two business units and must preserve normal collaboration.

  1. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Use a broad tenant-wide retention policy to keep every item for the same period.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: A

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 55

The human resources team at Fabrikam has two competing proposals for employee files. Only one directly enables the tenant to configure and manage publishing policies for sensitivity labels. Which proposal should be chosen to support investigation evidence? The control must work with the organization’s existing Microsoft 365 governance model. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The rollout plan requires a measurable checkpoint after 86 protected items have been processed.

  1. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.
  2. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  3. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  4. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: D

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 56

A pilot at Blue Yonder Airlines involves cloud application files. The security lead asks for a configuration that will configure and manage auto-labeling policies for sensitivity labels. Which approach best satisfies the requirement and helps reduce false positives? The team wants the change to be reversible during pilot testing. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 123 policy evaluations to confirm expected behavior.

  1. Change the Microsoft Entra Conditional Access policy for all users.
  2. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  3. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: D

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

B: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 57

A security design workshop at Trey Research focuses on cloud application files. One mandatory capability is to apply sensitivity labels by using Microsoft Defender for Cloud Apps. Which answer best aligns with Microsoft Purview while helping reduce false positives? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 160 historical events available for validation before enabling broader enforcement.

  1. Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.
  2. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: A

Why: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

Option review:

A: Defender for Cloud Apps can inspect connected cloud files and apply Purview sensitivity labels as governance actions when the integration, app connection, and label prerequisites are satisfied. This directly matches the requirement in the scenario.

B: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Enable the Purview information-protection integration in Defender for Cloud Apps and use an appropriate file policy or governance action to apply a published sensitivity label to supported cloud files.

Question 58

A production issue at Trey Research affects the handling of cloud application files. The root requirement is to configure and manage publishing policies for sensitivity labels. Which remediation best meets that requirement and helps support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 197 users across two business units and must preserve normal collaboration.

  1. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Use a trainable classifier for content that is best recognized by its semantic meaning, and train it with representative positive and negative examples before publishing it for policy use.

Correct answer: C

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Trainable classifiers are suited to categories such as contracts or source code where meaning and context matter more than a fixed identifier pattern; representative examples improve the classifier. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Question 59

A compliance exception at Graphic Design Institute can be closed only after the tenant can apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint for customer records. What should the administrator implement if the goal is to avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 53 users and expands only after the security team signs off.

  1. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  4. Use sensitivity-label encryption or Exchange mail-flow rules with Microsoft Purview Message Encryption to protect messages that meet the organization’s external-sharing requirements.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: C

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

D: Purview Message Encryption can be invoked through labeling and mail-flow conditions so sensitive mail is encrypted before delivery while authorized recipients can access it through supported experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 60

The security operations group at Humongous Insurance is preparing a production rollout involving financial workbooks. They specifically need to configure and manage auto-labeling policies for sensitivity labels. What should be configured first to reduce false positives? The organization wants to avoid granting broader permissions than the task requires. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 90 protected items have been processed.

  1. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  2. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  3. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: A

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

B: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 61

Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will configure protection settings and content marking for sensitivity labels for SharePoint documents. Which configuration should they use to support a phased rollout? The team must be able to explain why the selected control addresses the stated risk. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-2-061 and will be reviewed after the first week.

  1. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  2. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: A

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

B: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 62

A pilot at A. Datum involves SharePoint documents. The security lead asks for a configuration that will apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint. Which approach best satisfies the requirement and helps reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The team has 164 historical events available for validation before enabling broader enforcement.

  1. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  2. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  3. Change the Microsoft Entra Conditional Access policy for all users.
  4. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  5. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.

Correct answer: D

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

D: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

E: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 63

For a new Microsoft 365 deployment at Wingtip Toys, the human resources team is responsible for regulated case records. They are required to define and create sensitivity labels for items and containers. Which implementation is correct if they also want to avoid unnecessary user disruption? The implementation will be reviewed by both security and compliance stakeholders. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The design review compares outcomes for 20 representative samples before production enablement.

  1. Use Advanced Message Encryption when external encrypted mail needs controls such as custom branding, portal access tracking, expiration, or administrator revocation.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Create a custom sensitive information type with the required pattern, supporting evidence, confidence levels, and test data, then validate it before broad policy use.
  4. Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.
  5. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.

Correct answer: D

Why: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

Option review:

A: Advanced Message Encryption adds flexible controls for externally shared encrypted email, including multiple branding templates and portal-based expiration or revocation for supported messages. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: A reliable custom sensitive information type combines the primary match logic with supporting evidence and confidence settings so false positives can be controlled and the definition can be tested before enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Label scope determines which settings are available: item labels can drive content protection, while container labels govern supported settings for Teams, groups, sites, and other scoped assets. This directly matches the requirement in the scenario.

E: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create sensitivity labels with the correct scope for files and emails, containers, or supported data assets so the label exposes settings that match the object being protected.

Question 64

At Consolidated Messenger, a review of Teams collaboration content found a gap. The administrator must apply a sensitivity label to containers such as Teams Microsoft 365 Groups Power BI and SharePoint, while the project team wants to keep policy behavior predictable. What is the best next step? The control must work with the organization’s existing Microsoft 365 governance model. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. Administrators must be able to tune the configuration later without redesigning the entire protection model. The first phase affects 57 users across two business units and must preserve normal collaboration.

  1. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.
  2. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Create a Microsoft Sentinel analytics rule for the activity.

Correct answer: A

Why: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

Option review:

A: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This directly matches the requirement in the scenario.

B: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

Learning point: Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Question 65

A security design workshop at Graphic Design Institute focuses on email messages. One mandatory capability is to implement roles and permissions for administering sensitivity labels. Which answer best aligns with Microsoft Purview while helping keep policy behavior predictable? The control must work with the organization’s existing Microsoft 365 governance model. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 94 historical events available for validation before enabling broader enforcement.

  1. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.
  5. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: A

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 66

A proof of concept at Northwind Traders will be accepted only if it can configure protection settings and content marking for sensitivity labels for Teams collaboration content. The architect also wants to avoid unnecessary user disruption. Which option should be selected? The security lead wants the configuration to align with the supported Microsoft workflow. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The control owner must document the result for governance record SC401-2-066 before widening scope.

  1. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  2. Use a broad tenant-wide retention policy to keep every item for the same period.
  3. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  4. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.
  5. Use the Purview Information Protection client to classify, label, protect, or inspect supported files according to the user’s rights and the organization’s label configuration.

Correct answer: C

Why: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

Option review:

A: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

C: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This directly matches the requirement in the scenario.

D: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The client exposes file-level information-protection actions in supported Windows scenarios, allowing authorized users or administrators to apply and manage labels and protection. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.

Question 67

A compliance exception at Litware can be closed only after the tenant can configure and manage auto-labeling policies for sensitivity labels for employee files. What should the administrator implement if the goal is to avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The first phase affects 168 users across two business units and must preserve normal collaboration.

  1. Create a Microsoft Sentinel analytics rule for the activity.
  2. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  3. Map each requirement to a built-in sensitive information type when it fits, and use a custom sensitive information type when the built-in definitions do not represent the required pattern.
  4. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  5. Deploy and configure the Purview Information Protection scanner, define repositories and a content scan job, and use the scanner to discover and classify supported on-premises files at scale.

Correct answer: D

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

B: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Built-in sensitive information types reduce custom maintenance, while custom types are appropriate when the organization has identifiers or evidence rules that Microsoft does not provide out of the box. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

E: The scanner is the appropriate bulk mechanism for supported on-premises repositories because it can inspect configured locations and apply classification or protection centrally. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 68

The finance group at Tailspin Toys is preparing a production rollout involving regulated case records. They specifically need to implement roles and permissions for administering sensitivity labels. What should be configured first to minimize administrative overhead? The team must be able to explain why the selected control addresses the stated risk. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The initial scope covers 24 managed objects and must remain measurable during rollout.

  1. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  2. Change the Microsoft Entra Conditional Access policy for all users.
  3. Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.
  4. Use Data Explorer for aggregated classification and labeling trends, and use Content Explorer with the required viewer permissions when item-level inspection is needed.
  5. Use a container-scoped sensitivity label to enforce the supported governance settings for Teams, Microsoft 365 Groups, SharePoint sites, or Power BI items instead of relying on a file-only label.

Correct answer: C

Why: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

Option review:

A: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Conditional Access controls sign-in and session access but does not implement the requested Purview classification, labeling, or encryption function.

C: Purview uses role-based access control; dedicated information-protection roles let administrators manage labels while preserving least privilege. This directly matches the requirement in the scenario.

D: Data Explorer summarizes detected sensitive information and labels, while Content Explorer provides item-level visibility subject to additional content-viewing permissions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Container-aware labels are designed to govern collaboration containers and supported service assets; their scope and settings differ from labels that protect the content of individual files and emails. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged Purview information-protection role or role group needed to create and manage sensitivity labels instead of assigning broad tenant administrator rights.

Question 69

A Microsoft 365 administrator at Fourth Coffee is asked to improve protection of customer records. The success criterion is to configure and manage auto-labeling policies for sensitivity labels. What should be done if the implementation must use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The pilot starts with 61 users and expands only after the security team signs off.

  1. Deploy the Microsoft Purview Information Protection client to supported Windows endpoints that need File Explorer labeling or protection capabilities and configure it for the organization’s information-protection workflow.
  2. Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.
  3. Create a document fingerprint from the standard form or template so Purview can recognize completed documents that preserve the template structure.
  4. Configure the label with the required encryption permissions and any headers, footers, or watermarks so protection and user-visible marking are applied consistently.
  5. Use a broad tenant-wide retention policy to keep every item for the same period.

Correct answer: B

Why: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

Option review:

A: The client extends information-protection actions to supported Windows and file-management scenarios that require local classification and protection experiences. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Simulation provides a safer way to validate auto-labeling conditions and estimated impact before labels are automatically applied at scale. This directly matches the requirement in the scenario.

C: Document fingerprinting is designed for forms and standardized templates; Purview derives a fingerprint from the template and detects documents that contain the same characteristic structure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels can combine encryption with content marking; the settings should reflect the required access controls and the organization’s visual handling requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention does not classify sensitive information or configure information-protection behavior; it addresses lifecycle requirements instead.

Learning point: Create an auto-labeling policy with the required content conditions, run it in simulation to review matches, and enable automatic application only after the results are acceptable.

Question 70

Tailspin Toys is replacing a manual process used by the IT operations team for regulated case records. The replacement must configure and manage publishing policies for sensitivity labels. Which choice provides the most direct implementation while helping avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-2-070 and will be reviewed after the first week.

  1. Use Exact Data Match with a schema and hashed source data when policy decisions must match exact values from an authoritative data set rather than generic patterns.
  2. Create a Microsoft Sentinel analytics rule for the activity.
  3. Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.
  4. Enable and scope OCR so Purview can extract text from supported images or scanned content and evaluate that extracted text with sensitive information types.
  5. Inventory the data, its locations, business sensitivity, and regulatory requirements before choosing a classifier or protection control.

Correct answer: C

Why: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

Option review:

A: EDM reduces false positives for known records by matching protected content against hashed values from a defined source table and schema instead of relying only on pattern recognition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A Sentinel analytics rule is a security detection control and does not implement the Purview information-protection requirement in this scenario.

C: Creating a label does not make it available to users by itself; a publishing policy targets the labels and policy behavior to the appropriate population. This directly matches the requirement in the scenario.

D: OCR extends classification beyond machine-readable text by extracting text from supported image content before sensitive information type evaluation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Classification design starts with what data exists, where it resides, who uses it, and which legal or business rules make it sensitive; controls are selected only after those requirements are understood. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish the required labels to the intended users or groups with a sensitivity label policy, and configure policy settings such as default labeling or mandatory labeling as needed.

Popular posts

img