Microsoft SC-401 DLP Policy Design Roles Adaptive Protection And Cloud App Files Practice Test

 

Skill 2.1 • 63 original questions

This Microsoft SC-401 practice test focuses on dlp policy design roles adaptive protection and cloud app files through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

The collaboration services team at A. Datum has two competing proposals for engineering designs. Only one directly enables the tenant to interpret policy and rule precedence in data loss prevention. Which proposal should be chosen to support investigation evidence? The team wants the change to be reversible during pilot testing. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The team has 101 historical events available for validation before enabling broader enforcement.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  4. Create an Insider Risk Management case for every user in scope.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: A

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 2

The compliance team at Humongous Insurance has two competing proposals for email messages. Only one directly enables the tenant to interpret policy and rule precedence in data loss prevention. Which proposal should be chosen to keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The implementation will be tested against 138 representative files or events before sign-off.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: A

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 3

During an audit at Northwind Traders, reviewers ask how the tenant will create and manage data loss prevention policies. The implementation should reduce false positives. Which choice is most appropriate? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The implementation will be tested against 175 representative files or events before sign-off.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 4

A proof of concept at Graphic Design Institute will be accepted only if it can design data loss prevention policies based on an organization’s requirements for support tickets. The architect also wants to minimize administrative overhead. Which option should be selected? The team wants the change to be reversible during pilot testing. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. Administrators must be able to tune the configuration later without redesigning the entire protection model. A support team will observe the first 31 policy evaluations to confirm expected behavior.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create an Insider Risk Management case for every user in scope.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: D

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 5

The research group at Alpine Ski House is preparing a production rollout involving SharePoint documents. They specifically need to implement roles and permissions for data loss prevention. What should be configured first to avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 68 historical events available for validation before enabling broader enforcement.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: D

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 6

The research team at City Power & Light has two competing proposals for engineering designs. Only one directly enables the tenant to configure data loss prevention policies for Adaptive Protection. Which proposal should be chosen to support a phased rollout? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. Only the users and workloads named in the requirement should be affected during the first production phase. The design review compares outcomes for 105 representative samples before production enablement.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: C

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 7

A change request from Contoso’s collaboration services department affects SharePoint documents. The stated objective is to create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which administrative action is the strongest fit if the team must use the narrowest effective control? The control must work with the organization’s existing Microsoft 365 governance model. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Only the users and workloads named in the requirement should be affected during the first production phase. The pilot starts with 142 users and expands only after the security team signs off.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: B

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 8

During an audit at Proseware, reviewers ask how the tenant will design data loss prevention policies based on an organization’s requirements. The implementation should keep policy behavior predictable. Which choice is most appropriate? The team must be able to explain why the selected control addresses the stated risk. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The first phase affects 179 users across two business units and must preserve normal collaboration.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: B

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 9

An incident review at Margie’s Travel shows that the current process for regulated case records is incomplete. The team now needs to implement roles and permissions for data loss prevention. Which action most directly addresses that need while helping avoid changing unrelated workloads? The design should not depend on users remembering an optional manual step. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The implementation will be tested against 35 representative files or events before sign-off.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: D

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 10

The governance board at A. Datum approves a control for financial workbooks on the condition that administrators can create and manage data loss prevention policies. What should the team do to minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The change is tracked under control batch SC401-4-010 and will be reviewed after the first week.

  1. Create an Insider Risk Management case for every user in scope.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: E

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 11

A pilot at Northwind Traders involves cloud application files. The security lead asks for a configuration that will interpret policy and rule precedence in data loss prevention. Which approach best satisfies the requirement and helps keep policy behavior predictable? The security lead wants the configuration to align with the supported Microsoft workflow. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 109 representative samples before production enablement.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: E

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 12

The research group at Humongous Insurance is preparing a production rollout involving contract documents. They specifically need to create and manage data loss prevention policies. What should be configured first to reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-4-012 before widening scope.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: A

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

B: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 13

Wingtip Toys is replacing a manual process used by the engineering team for employee files. The replacement must create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which choice provides the most direct implementation while helping support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 183 policy evaluations to confirm expected behavior.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Create an Insider Risk Management case for every user in scope.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: D

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 14

At Wide World Importers, a review of contract documents found a gap. The administrator must implement roles and permissions for data loss prevention, while the project team wants to minimize administrative overhead. What is the best next step? The security lead wants the configuration to align with the supported Microsoft workflow. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. The pilot starts with 39 users and expands only after the security team signs off.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: D

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 15

Contoso is replacing a manual process used by the data governance team for email messages. The replacement must design data loss prevention policies based on an organization’s requirements. Which choice provides the most direct implementation while helping preserve least privilege? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The control owner must document the result for governance record SC401-4-015 before widening scope.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: D

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 16

The governance board at Contoso approves a control for financial workbooks on the condition that administrators can configure data loss prevention policies for Adaptive Protection. What should the team do to minimize administrative overhead? The pilot population is small today but the configuration must support a broader rollout. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The pilot starts with 113 users and expands only after the security team signs off.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: C

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 17

Graphic Design Institute expects the volume of engineering designs to increase significantly. The control must scale while allowing the team to create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which action best supports that objective and helps keep policy behavior predictable? The control must work with the organization’s existing Microsoft 365 governance model. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The initial scope covers 150 managed objects and must remain measurable during rollout.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  3. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: B

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

C: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 18

A production issue at City Power & Light affects the handling of employee files. The root requirement is to implement roles and permissions for data loss prevention. Which remediation best meets that requirement and helps keep policy behavior predictable? The team wants the change to be reversible during pilot testing. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 187 protected items have been processed.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  4. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

D: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 19

Alpine Ski House is standardizing protection for cloud application files. The design must implement roles and permissions for data loss prevention, and operations wants to support investigation evidence. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 43 policy evaluations to confirm expected behavior.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create an Insider Risk Management case for every user in scope.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: E

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 20

At A. Datum, a review of SharePoint documents found a gap. The administrator must interpret policy and rule precedence in data loss prevention, while the project team wants to use the narrowest effective control. What is the best next step? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The change is tracked under control batch SC401-4-020 and will be reviewed after the first week.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: E

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 21

Adventure Works is replacing a manual process used by the IT operations team for financial workbooks. The replacement must create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which choice provides the most direct implementation while helping use the narrowest effective control? The security lead wants the configuration to align with the supported Microsoft workflow. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The change is tracked under control batch SC401-4-021 and will be reviewed after the first week.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: C

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 22

Margie’s Travel is standardizing protection for engineering designs. The design must create file policies in Microsoft Defender for Cloud Apps by using a DLP policy, and operations wants to support a phased rollout. What should the information security administrator do? The implementation will be reviewed by both security and compliance stakeholders. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-4-022 and will be reviewed after the first week.

  1. Create an Insider Risk Management case for every user in scope.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: C

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 23

Following a policy review, Tailspin Toys changes how employee files is governed. The new requirement is to design data loss prevention policies based on an organization’s requirements. Which action is the best fit and will help avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 191 policy evaluations to confirm expected behavior.

  1. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 24

Fourth Coffee expects the volume of scanned forms to increase significantly. The control must scale while allowing the team to create and manage data loss prevention policies. Which action best supports that objective and helps avoid unnecessary user disruption? The pilot population is small today but the configuration must support a broader rollout. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The first phase affects 47 users across two business units and must preserve normal collaboration.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  3. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: D

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 25

For a new Microsoft 365 deployment at Contoso, the security operations team is responsible for email messages. They are required to implement roles and permissions for data loss prevention. Which implementation is correct if they also want to support investigation evidence? The requirement applies to production data rather than a one-time demonstration. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 84 policy evaluations to confirm expected behavior.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Create an Insider Risk Management case for every user in scope.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: A

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 26

Before enabling enforcement at Graphic Design Institute, administrators must demonstrate how they will configure data loss prevention policies for Adaptive Protection for email messages. Which configuration should they use to minimize administrative overhead? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The first phase affects 121 users across two business units and must preserve normal collaboration.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: B

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 27

A change request from Fabrikam’s human resources department affects contract documents. The stated objective is to design data loss prevention policies based on an organization’s requirements. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 158 managed objects and must remain measurable during rollout.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: D

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 28

A compliance exception at Fabrikam can be closed only after the tenant can create file policies in Microsoft Defender for Cloud Apps by using a DLP policy for regulated case records. What should the administrator implement if the goal is to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 195 managed objects and must remain measurable during rollout.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Create an Insider Risk Management case for every user in scope.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: D

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 29

For a new Microsoft 365 deployment at Alpine Ski House, the risk management team is responsible for employee files. They are required to create and manage data loss prevention policies. Which implementation is correct if they also want to keep the design auditable? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The implementation will be tested against 51 representative files or events before sign-off.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: B

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 30

Wide World Importers is replacing a manual process used by the finance team for scanned forms. The replacement must interpret policy and rule precedence in data loss prevention. Which choice provides the most direct implementation while helping avoid unnecessary user disruption? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The change is tracked under control batch SC401-4-030 and will be reviewed after the first week.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: C

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 31

Consolidated Messenger’s engineering team is updating controls for SharePoint documents. The requirement is to create and manage data loss prevention policies. The solution must also keep the design auditable. Which action should the administrator take? Administrators need evidence they can review after deployment. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The team has 125 historical events available for validation before enabling broader enforcement.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  4. Create an Insider Risk Management case for every user in scope.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: B

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

C: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 32

A change request from Wingtip Toys’s engineering department affects contract documents. The stated objective is to create and manage data loss prevention policies. Which administrative action is the strongest fit if the team must reduce false positives? The organization wants to avoid granting broader permissions than the task requires. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-4-032 before widening scope.

  1. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: D

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 33

The sales team at Wingtip Toys has two competing proposals for cloud application files. Only one directly enables the tenant to design data loss prevention policies based on an organization’s requirements. Which proposal should be chosen to preserve least privilege? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-4-033 and will be reviewed after the first week.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: E

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 34

For a new Microsoft 365 deployment at City Power & Light, the legal team is responsible for support tickets. They are required to create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which implementation is correct if they also want to support investigation evidence? The organization wants to avoid granting broader permissions than the task requires. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-4-034 and will be reviewed after the first week.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: D

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 35

A pilot at Wide World Importers involves financial workbooks. The security lead asks for a configuration that will implement roles and permissions for data loss prevention. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 92 historical events available for validation before enabling broader enforcement.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  3. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: C

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 36

Fabrikam’s finance team is updating controls for regulated case records. The requirement is to create and manage data loss prevention policies. The solution must also minimize administrative overhead. Which action should the administrator take? The design should not depend on users remembering an optional manual step. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The initial scope covers 129 managed objects and must remain measurable during rollout.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: C

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 37

At Proseware, a review of engineering designs found a gap. The administrator must implement roles and permissions for data loss prevention, while the project team wants to keep the design auditable. What is the best next step? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The first phase affects 166 users across two business units and must preserve normal collaboration.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Create an Insider Risk Management case for every user in scope.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: B

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 38

Contoso’s finance team is updating controls for scanned forms. The requirement is to design data loss prevention policies based on an organization’s requirements. The solution must also support investigation evidence. Which action should the administrator take? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. Only the users and workloads named in the requirement should be affected during the first production phase. The implementation will be tested against 22 representative files or events before sign-off.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: E

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 39

A change request from Litware’s engineering department affects contract documents. The stated objective is to design data loss prevention policies based on an organization’s requirements. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The initial scope covers 59 managed objects and must remain measurable during rollout.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: C

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 40

Margie’s Travel’s research team is updating controls for regulated case records. The requirement is to configure data loss prevention policies for Adaptive Protection. The solution must also minimize administrative overhead. Which action should the administrator take? The design should not depend on users remembering an optional manual step. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 96 protected items have been processed.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Create an Insider Risk Management case for every user in scope.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: E

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 41

Tailspin Toys’s IT operations team is updating controls for employee files. The requirement is to implement roles and permissions for data loss prevention. The solution must also avoid changing unrelated workloads. Which action should the administrator take? The implementation will be reviewed by both security and compliance stakeholders. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 133 historical events available for validation before enabling broader enforcement.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: A

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 42

Margie’s Travel is standardizing protection for email messages. The design must interpret policy and rule precedence in data loss prevention, and operations wants to keep policy behavior predictable. What should the information security administrator do? The team must be able to explain why the selected control addresses the stated risk. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The rollout plan requires a measurable checkpoint after 170 protected items have been processed.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: C

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 43

A proof of concept at Humongous Insurance will be accepted only if it can create file policies in Microsoft Defender for Cloud Apps by using a DLP policy for regulated case records. The architect also wants to avoid unnecessary user disruption. Which option should be selected? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The design review compares outcomes for 26 representative samples before production enablement.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create an Insider Risk Management case for every user in scope.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: E

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 44

A production issue at Northwind Traders affects the handling of contract documents. The root requirement is to create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which remediation best meets that requirement and helps avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The design review compares outcomes for 63 representative samples before production enablement.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: D

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 45

Before enabling enforcement at Northwind Traders, administrators must demonstrate how they will configure data loss prevention policies for Adaptive Protection for SharePoint documents. Which configuration should they use to reduce false positives? The organization wants to avoid granting broader permissions than the task requires. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The initial scope covers 100 managed objects and must remain measurable during rollout.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: A

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 46

A production issue at Consolidated Messenger affects the handling of email messages. The root requirement is to configure data loss prevention policies for Adaptive Protection. Which remediation best meets that requirement and helps keep the design auditable? The team wants the change to be reversible during pilot testing. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The change is tracked under control batch SC401-4-046 and will be reviewed after the first week.

  1. Create an Insider Risk Management case for every user in scope.
  2. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: D

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 47

A Microsoft 365 administrator at Margie’s Travel is asked to improve protection of financial workbooks. The success criterion is to configure data loss prevention policies for Adaptive Protection. What should be done if the implementation must keep the design auditable? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The team has 174 historical events available for validation before enabling broader enforcement.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: E

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 48

Margie’s Travel is standardizing protection for email messages. The design must configure data loss prevention policies for Adaptive Protection, and operations wants to keep policy behavior predictable. What should the information security administrator do? The organization wants to avoid granting broader permissions than the task requires. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-4-048 and will be reviewed after the first week.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: A

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 49

A pilot at Alpine Ski House involves regulated case records. The security lead asks for a configuration that will create file policies in Microsoft Defender for Cloud Apps by using a DLP policy. Which approach best satisfies the requirement and helps avoid changing unrelated workloads? The requirement applies to production data rather than a one-time demonstration. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The design review compares outcomes for 67 representative samples before production enablement.

  1. Create an Insider Risk Management case for every user in scope.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: D

Why: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This directly matches the requirement in the scenario.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Question 50

The risk management group at Wide World Importers is preparing a production rollout involving engineering designs. They specifically need to configure data loss prevention policies for Adaptive Protection. What should be configured first to reduce false positives? The team wants the change to be reversible during pilot testing. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The first phase affects 104 users across two business units and must preserve normal collaboration.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: D

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 51

The governance board at A. Datum approves a control for contract documents on the condition that administrators can implement roles and permissions for data loss prevention. What should the team do to keep policy behavior predictable? Administrators need evidence they can review after deployment. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The control owner must document the result for governance record SC401-4-051 before widening scope.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: B

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 52

A security design workshop at Fourth Coffee focuses on email messages. One mandatory capability is to interpret policy and rule precedence in data loss prevention. Which answer best aligns with Microsoft Purview while helping keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 178 users across two business units and must preserve normal collaboration.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Create an Insider Risk Management case for every user in scope.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Correct answer: C

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 53

A change request from Tailspin Toys’s legal department affects scanned forms. The stated objective is to implement roles and permissions for data loss prevention. Which administrative action is the strongest fit if the team must keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 34 protected items have been processed.

  1. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: D

Why: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

Option review:

A: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This directly matches the requirement in the scenario.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Question 54

For a new Microsoft 365 deployment at Wingtip Toys, the engineering team is responsible for SharePoint documents. They are required to design data loss prevention policies based on an organization’s requirements. Which implementation is correct if they also want to support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The control owner must document the result for governance record SC401-4-054 before widening scope.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: E

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 55

A change request from Margie’s Travel’s collaboration services department affects regulated case records. The stated objective is to interpret policy and rule precedence in data loss prevention. Which administrative action is the strongest fit if the team must support investigation evidence? The requirement applies to production data rather than a one-time demonstration. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The first phase affects 108 users across two business units and must preserve normal collaboration.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Create an Insider Risk Management case for every user in scope.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: D

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 56

Wingtip Toys’s collaboration services team is updating controls for support tickets. The requirement is to create and manage data loss prevention policies. The solution must also minimize administrative overhead. Which action should the administrator take? The team wants the change to be reversible during pilot testing. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The team has 145 historical events available for validation before enabling broader enforcement.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: E

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 57

A change request from Blue Yonder Airlines’s legal department affects engineering designs. The stated objective is to design data loss prevention policies based on an organization’s requirements. Which administrative action is the strongest fit if the team must keep policy behavior predictable? The team must be able to explain why the selected control addresses the stated risk. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The pilot starts with 182 users and expands only after the security team signs off.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: B

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 58

An incident review at Woodgrove Bank shows that the current process for email messages is incomplete. The team now needs to create and manage data loss prevention policies. Which action most directly addresses that need while helping reduce false positives? The organization wants to avoid granting broader permissions than the task requires. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The rollout plan requires a measurable checkpoint after 38 protected items have been processed.

  1. Create an Insider Risk Management case for every user in scope.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Question 59

Alpine Ski House is replacing a manual process used by the research team for regulated case records. The replacement must interpret policy and rule precedence in data loss prevention. Which choice provides the most direct implementation while helping support investigation evidence? The control must work with the organization’s existing Microsoft 365 governance model. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 75 protected items have been processed.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 60

The governance board at Proseware approves a control for employee files on the condition that administrators can configure data loss prevention policies for Adaptive Protection. What should the team do to avoid changing unrelated workloads? The design should not depend on users remembering an optional manual step. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The rollout plan requires a measurable checkpoint after 112 protected items have been processed.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: D

Why: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This directly matches the requirement in the scenario.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Question 61

During an audit at City Power & Light, reviewers ask how the tenant will interpret policy and rule precedence in data loss prevention. The implementation should keep policy behavior predictable. Which choice is most appropriate? The implementation will be reviewed by both security and compliance stakeholders. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The design review compares outcomes for 149 representative samples before production enablement.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: C

Why: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This directly matches the requirement in the scenario.

D: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Question 62

Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will design data loss prevention policies based on an organization’s requirements for regulated case records. Which configuration should they use to preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The first phase affects 186 users across two business units and must preserve normal collaboration.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: E

Why: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This directly matches the requirement in the scenario.

Learning point: Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Question 63

The research team at Fabrikam has two competing proposals for regulated case records. Only one directly enables the tenant to create and manage data loss prevention policies. Which proposal should be chosen to minimize administrative overhead? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 42 policy evaluations to confirm expected behavior.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: C

Why: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This directly matches the requirement in the scenario.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Popular posts

img