Microsoft SC-401 Endpoint DLP Device Requirements Advanced Rules JIT And Monitoring Practice Test

 

Skill 2.2 • 53 original questions

This Microsoft SC-401 practice test focuses on endpoint dlp device requirements advanced rules jit and monitoring through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

A production issue at Woodgrove Bank affects the handling of SharePoint documents. The root requirement is to configure advanced DLP rules for devices in DLP policies. Which remediation best meets that requirement and helps reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The implementation will be tested against 112 representative files or events before sign-off.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Create an Insider Risk Management case for every user in scope.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: E

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 2

A security design workshop at Woodgrove Bank focuses on email messages. One mandatory capability is to specify device requirements for Endpoint DLP including extensions. Which answer best aligns with Microsoft Purview while helping minimize administrative overhead? The design should not depend on users remembering an optional manual step. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The implementation will be tested against 149 representative files or events before sign-off.

  1. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: E

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 3

A compliance exception at Woodgrove Bank can be closed only after the tenant can monitor endpoint activities for customer records. What should the administrator implement if the goal is to avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 186 protected items have been processed.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: D

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 4

A pilot at Adventure Works involves employee files. The security lead asks for a configuration that will specify device requirements for Endpoint DLP including extensions. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-5-004 before widening scope.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Create an Insider Risk Management case for every user in scope.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: C

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 5

The compliance group at Humongous Insurance is preparing a production rollout involving cloud application files. They specifically need to monitor endpoint activities. What should be configured first to support investigation evidence? The team wants the change to be reversible during pilot testing. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-5-005 before widening scope.

  1. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: B

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

C: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 6

A pilot at Fourth Coffee involves regulated case records. The security lead asks for a configuration that will configure advanced DLP rules for devices in DLP policies. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The implementation will be tested against 116 representative files or events before sign-off.

  1. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: D

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 7

The governance board at A. Datum approves a control for regulated case records on the condition that administrators can monitor endpoint activities. What should the team do to minimize administrative overhead? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The implementation will be tested against 153 representative files or events before sign-off.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: B

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 8

A proof of concept at Adventure Works will be accepted only if it can configure advanced DLP rules for devices in DLP policies for email messages. The architect also wants to keep policy behavior predictable. Which option should be selected? The pilot population is small today but the configuration must support a broader rollout. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-5-008 before widening scope.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: B

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 9

The compliance team at Alpine Ski House has two competing proposals for contract documents. Only one directly enables the tenant to configure just-in-time protection. Which proposal should be chosen to support a phased rollout? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Only the users and workloads named in the requirement should be affected during the first production phase. The design review compares outcomes for 46 representative samples before production enablement.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: C

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 10

A compliance exception at Trey Research can be closed only after the tenant can configure just-in-time protection for SharePoint documents. What should the administrator implement if the goal is to reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. Administrators must be able to tune the configuration later without redesigning the entire protection model. The implementation will be tested against 83 representative files or events before sign-off.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Create an Insider Risk Management case for every user in scope.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Correct answer: A

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 11

A security design workshop at Graphic Design Institute focuses on financial workbooks. One mandatory capability is to configure Endpoint DLP settings. Which answer best aligns with Microsoft Purview while helping use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The implementation will be tested against 120 representative files or events before sign-off.

  1. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: D

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 12

A proof of concept at Trey Research will be accepted only if it can monitor endpoint activities for Teams collaboration content. The architect also wants to minimize administrative overhead. Which option should be selected? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. Only the users and workloads named in the requirement should be affected during the first production phase. The first phase affects 157 users across two business units and must preserve normal collaboration.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: E

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 13

A change request from Blue Yonder Airlines’s human resources department affects engineering designs. The stated objective is to configure just-in-time protection. Which administrative action is the strongest fit if the team must keep the design auditable? The team wants the change to be reversible during pilot testing. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-5-013 before widening scope.

  1. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  2. Create an Insider Risk Management case for every user in scope.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: D

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 14

A pilot at Humongous Insurance involves support tickets. The security lead asks for a configuration that will configure Endpoint DLP settings. Which approach best satisfies the requirement and helps preserve least privilege? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 50 users across two business units and must preserve normal collaboration.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: C

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 15

A change request from Adventure Works’s collaboration services department affects financial workbooks. The stated objective is to configure just-in-time protection. Which administrative action is the strongest fit if the team must reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-5-015 before widening scope.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: B

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 16

Following a policy review, Contoso changes how Teams collaboration content is governed. The new requirement is to configure Endpoint DLP settings. Which action is the best fit and will help keep policy behavior predictable? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The implementation will be tested against 124 representative files or events before sign-off.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Create an Insider Risk Management case for every user in scope.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 17

During an audit at Margie’s Travel, reviewers ask how the tenant will configure advanced DLP rules for devices in DLP policies. The implementation should avoid changing unrelated workloads. Which choice is most appropriate? Administrators need evidence they can review after deployment. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-5-017 before widening scope.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: B

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 18

At Litware, a review of employee files found a gap. The administrator must configure advanced DLP rules for devices in DLP policies, while the project team wants to keep the design auditable. What is the best next step? The implementation will be reviewed by both security and compliance stakeholders. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-5-018 and will be reviewed after the first week.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: C

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 19

A pilot at Contoso involves cloud application files. The security lead asks for a configuration that will configure Endpoint DLP settings. Which approach best satisfies the requirement and helps support a phased rollout? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The control owner must document the result for governance record SC401-5-019 before widening scope.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Create an Insider Risk Management case for every user in scope.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: C

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 20

An incident review at Margie’s Travel shows that the current process for cloud application files is incomplete. The team now needs to configure Endpoint DLP settings. Which action most directly addresses that need while helping keep policy behavior predictable? Administrators need evidence they can review after deployment. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-5-020 and will be reviewed after the first week.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: C

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 21

The research group at Woodgrove Bank is preparing a production rollout involving customer records. They specifically need to configure advanced DLP rules for devices in DLP policies. What should be configured first to support a phased rollout? The security lead wants the configuration to align with the supported Microsoft workflow. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The pilot starts with 128 users and expands only after the security team signs off.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: A

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 22

Alpine Ski House expects the volume of scanned forms to increase significantly. The control must scale while allowing the team to monitor endpoint activities. Which action best supports that objective and helps support a phased rollout? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The rollout plan requires a measurable checkpoint after 165 protected items have been processed.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Create an Insider Risk Management case for every user in scope.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: D

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 23

Before enabling enforcement at Margie’s Travel, administrators must demonstrate how they will configure just-in-time protection for support tickets. Which configuration should they use to use the narrowest effective control? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The initial scope covers 21 managed objects and must remain measurable during rollout.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: B

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 24

A security design workshop at A. Datum focuses on scanned forms. One mandatory capability is to configure Endpoint DLP settings. Which answer best aligns with Microsoft Purview while helping use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-5-024 before widening scope.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: A

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 25

Woodgrove Bank expects the volume of employee files to increase significantly. The control must scale while allowing the team to monitor endpoint activities. Which action best supports that objective and helps avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The change is tracked under control batch SC401-5-025 and will be reviewed after the first week.

  1. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Create an Insider Risk Management case for every user in scope.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: B

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 26

For a new Microsoft 365 deployment at Fabrikam, the compliance team is responsible for email messages. They are required to configure just-in-time protection. Which implementation is correct if they also want to support a phased rollout? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The rollout plan requires a measurable checkpoint after 132 protected items have been processed.

  1. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  2. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  3. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: B

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

C: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 27

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of customer records. The success criterion is to monitor endpoint activities. What should be done if the implementation must reduce false positives? The team must be able to explain why the selected control addresses the stated risk. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-5-027 and will be reviewed after the first week.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: E

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 28

A proof of concept at Proseware will be accepted only if it can configure just-in-time protection for employee files. The architect also wants to reduce false positives. Which option should be selected? The implementation will be reviewed by both security and compliance stakeholders. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The implementation will be tested against 25 representative files or events before sign-off.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: E

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 29

A production issue at Proseware affects the handling of financial workbooks. The root requirement is to configure advanced DLP rules for devices in DLP policies. Which remediation best meets that requirement and helps minimize administrative overhead? The implementation will be reviewed by both security and compliance stakeholders. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 62 historical events available for validation before enabling broader enforcement.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: B

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 30

During an audit at Trey Research, reviewers ask how the tenant will specify device requirements for Endpoint DLP including extensions. The implementation should use the narrowest effective control. Which choice is most appropriate? The pilot population is small today but the configuration must support a broader rollout. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The team has 99 historical events available for validation before enabling broader enforcement.

  1. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: A

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 31

An incident review at Tailspin Toys shows that the current process for financial workbooks is incomplete. The team now needs to specify device requirements for Endpoint DLP including extensions. Which action most directly addresses that need while helping reduce false positives? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 136 managed objects and must remain measurable during rollout.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Create an Insider Risk Management case for every user in scope.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: E

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 32

A Microsoft 365 administrator at Litware is asked to improve protection of support tickets. The success criterion is to configure just-in-time protection. What should be done if the implementation must reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 173 historical events available for validation before enabling broader enforcement.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: A

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 33

For a new Microsoft 365 deployment at Fourth Coffee, the engineering team is responsible for cloud application files. They are required to specify device requirements for Endpoint DLP including extensions. Which implementation is correct if they also want to minimize administrative overhead? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 29 managed objects and must remain measurable during rollout.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: B

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 34

An incident review at Contoso shows that the current process for cloud application files is incomplete. The team now needs to monitor endpoint activities. Which action most directly addresses that need while helping avoid unnecessary user disruption? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Only the users and workloads named in the requirement should be affected during the first production phase. The change is tracked under control batch SC401-5-034 and will be reviewed after the first week.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Create an Insider Risk Management case for every user in scope.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: A

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 35

The legal group at Wingtip Toys is preparing a production rollout involving Teams collaboration content. They specifically need to configure Endpoint DLP settings. What should be configured first to reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The initial scope covers 103 managed objects and must remain measurable during rollout.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 36

Contoso’s engineering team is updating controls for Teams collaboration content. The requirement is to configure just-in-time protection. The solution must also avoid changing unrelated workloads. Which action should the administrator take? The security lead wants the configuration to align with the supported Microsoft workflow. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 140 protected items have been processed.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: D

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 37

A pilot at Contoso involves support tickets. The security lead asks for a configuration that will configure just-in-time protection. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. A support team will observe the first 177 policy evaluations to confirm expected behavior.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: C

Why: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This directly matches the requirement in the scenario.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Question 38

Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will specify device requirements for Endpoint DLP including extensions for financial workbooks. Which configuration should they use to use the narrowest effective control? The control must work with the organization’s existing Microsoft 365 governance model. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The design review compares outcomes for 33 representative samples before production enablement.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: C

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 39

The data governance group at Woodgrove Bank is preparing a production rollout involving email messages. They specifically need to configure Endpoint DLP settings. What should be configured first to use the narrowest effective control? The team wants the change to be reversible during pilot testing. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The implementation will be tested against 70 representative files or events before sign-off.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: A

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 40

A change request from Blue Yonder Airlines’s compliance department affects Teams collaboration content. The stated objective is to configure Endpoint DLP settings. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The initial scope covers 107 managed objects and must remain measurable during rollout.

  1. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Create an Insider Risk Management case for every user in scope.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: E

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 41

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of regulated case records. The success criterion is to configure advanced DLP rules for devices in DLP policies. What should be done if the implementation must minimize administrative overhead? The security lead wants the configuration to align with the supported Microsoft workflow. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The implementation will be tested against 144 representative files or events before sign-off.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: C

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 42

Wide World Importers’s collaboration services team is updating controls for regulated case records. The requirement is to configure advanced DLP rules for devices in DLP policies. The solution must also keep policy behavior predictable. Which action should the administrator take? The implementation will be reviewed by both security and compliance stakeholders. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The initial scope covers 181 managed objects and must remain measurable during rollout.

  1. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: B

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 43

A production issue at Alpine Ski House affects the handling of customer records. The root requirement is to configure Endpoint DLP settings. Which remediation best meets that requirement and helps reduce false positives? Administrators need evidence they can review after deployment. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. A support team will observe the first 37 policy evaluations to confirm expected behavior.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Create an Insider Risk Management case for every user in scope.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: B

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 44

City Power & Light is standardizing protection for support tickets. The design must specify device requirements for Endpoint DLP including extensions, and operations wants to reduce false positives. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The implementation will be tested against 74 representative files or events before sign-off.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: D

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 45

The governance board at Wingtip Toys approves a control for support tickets on the condition that administrators can configure Endpoint DLP settings. What should the team do to avoid unnecessary user disruption? The design should not depend on users remembering an optional manual step. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 111 representative samples before production enablement.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This directly matches the requirement in the scenario.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Question 46

The governance board at Litware approves a control for email messages on the condition that administrators can monitor endpoint activities. What should the team do to avoid unnecessary user disruption? The control must work with the organization’s existing Microsoft 365 governance model. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The initial scope covers 148 managed objects and must remain measurable during rollout.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: C

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 47

During an audit at A. Datum, reviewers ask how the tenant will specify device requirements for Endpoint DLP including extensions. The implementation should keep policy behavior predictable. Which choice is most appropriate? The team must be able to explain why the selected control addresses the stated risk. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-5-047 and will be reviewed after the first week.

  1. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 48

The engineering group at City Power & Light is preparing a production rollout involving cloud application files. They specifically need to configure advanced DLP rules for devices in DLP policies. What should be configured first to support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The pilot starts with 41 users and expands only after the security team signs off.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: C

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 49

Before enabling enforcement at Contoso, administrators must demonstrate how they will configure advanced DLP rules for devices in DLP policies for engineering designs. Which configuration should they use to use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. A support team will observe the first 78 policy evaluations to confirm expected behavior.

  1. Create an Insider Risk Management case for every user in scope.
  2. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: E

Why: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This directly matches the requirement in the scenario.

Learning point: Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Question 50

An incident review at Margie’s Travel shows that the current process for contract documents is incomplete. The team now needs to monitor endpoint activities. Which action most directly addresses that need while helping avoid unnecessary user disruption? The team wants the change to be reversible during pilot testing. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The pilot starts with 115 users and expands only after the security team signs off.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This directly matches the requirement in the scenario.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Question 51

A change request from Consolidated Messenger’s engineering department affects regulated case records. The stated objective is to specify device requirements for Endpoint DLP including extensions. Which administrative action is the strongest fit if the team must support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The first phase affects 152 users across two business units and must preserve normal collaboration.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: C

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 52

A change request from Consolidated Messenger’s legal department affects customer records. The stated objective is to specify device requirements for Endpoint DLP including extensions. Which administrative action is the strongest fit if the team must preserve least privilege? Administrators need evidence they can review after deployment. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. Administrators must be able to tune the configuration later without redesigning the entire protection model. The pilot starts with 189 users and expands only after the security team signs off.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Create an Insider Risk Management case for every user in scope.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: E

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Question 53

A production issue at Litware affects the handling of cloud application files. The root requirement is to specify device requirements for Endpoint DLP including extensions. Which remediation best meets that requirement and helps keep the design auditable? The implementation will be reviewed by both security and compliance stakeholders. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-5-053 and will be reviewed after the first week.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: B

Why: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This directly matches the requirement in the scenario.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Popular posts

img