Microsoft MS-102 Purview DLP Across Microsoft 365 Endpoint DLP And DLP Investigations Practice Test

 

MS-102 skills 4.2 | 25 original questions

This MS-102 practice set focuses on purview dlp across microsoft 365 endpoint dlp and dlp investigations through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

City Power & Light is preparing a change requested by the tenant administrator. The existing configuration works for normal operations but fails the new requirement to apply one data-loss prevention rule set across the workloads that handle the sensitive information. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The affected scope contains 60 users across 15 administrative groups. Which option best satisfies the requirement?

  1. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  2. Configure Endpoint DLP actions for the risky device activity
  3. Use a retention policy for broad location-based retention
  4. Use label reports for aggregate label adoption trends
  5. Use DLP reports or Activity explorer to identify recurring policy-match patterns

Correct answer: A

Why: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. It directly addresses the stated requirement.

Option review:

A: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. It directly addresses the stated requirement.

B: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q001: Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations – Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design.

Question 2

The security administrator at Fourth Coffee is designing the next phase of the Microsoft 365 rollout. The current workaround is too manual. The replacement should evaluate matches and user impact before blocking business activity broadly. The affected scope contains 77 users across 5 administrative groups. The team must preserve a clear audit trail for the administrative decision. Which control should the team use?

  1. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  2. Use DLP policy test mode before full enforcement
  3. Use a retention label when individual items need distinct retention behavior
  4. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  5. Tune the DLP rule only after confirming the alert is a consistent false positive

Correct answer: B

Why: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. It directly addresses the stated requirement.

Option review:

A: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. It directly addresses the stated requirement.

C: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q002: Use DLP policy test mode before full enforcement – Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment.

Question 3

The operations team at Northwind Traders needs to resolve an issue without granting broader permissions than necessary. The support team has reproduced the issue and narrowed it to this requirement: warn users during risky sharing or handling while preserving the designed DLP workflow. The team will validate the change with 18 pilot groups before expanding it to 94 users. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?

  1. Investigate the DLP alert and correlated events in Microsoft Purview
  2. Publish the retention label with a retention label policy
  3. Use policy tips when users should receive contextual guidance
  4. Use DLP policy test mode before full enforcement
  5. Create a custom sensitive information type with a regular expression and supporting evidence

Correct answer: C

Why: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. It directly addresses the stated requirement.

Option review:

A: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. It directly addresses the stated requirement.

D: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q003: Use policy tips when users should receive contextual guidance – Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions.

Question 4

A quarterly control review at Northwind Traders identifies a gap that must be corrected before the next audit. Audit evidence shows that the current process cannot reliably apply one data-loss prevention rule set across the workloads that handle the sensitive information. The team must preserve a clear audit trail for the administrative decision. The control owner requires a review after 20 days and evidence from 8 representative cases. Which control should the team use?

  1. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  2. Create a sensitivity label that applies encryption and content markings
  3. Configure Endpoint DLP for the managed device scope
  4. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  5. Use a keyword list as supporting evidence in the sensitive information type

Correct answer: D

Why: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. It directly addresses the stated requirement.

Option review:

A: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. It directly addresses the stated requirement.

E: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q004: Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations – Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design.

Question 5

During a tenant review at City Power & Light, the identity administrator identifies one unresolved requirement. A controlled pilot must demonstrate how to evaluate matches and user impact before blocking business activity broadly. The solution should use a native Microsoft control that matches the stated requirement. The affected scope contains 37 users across 21 administrative groups. Which approach most directly addresses the requirement?

  1. Tune the DLP rule only after confirming the alert is a consistent false positive
  2. Publish sensitivity labels through a sensitivity label policy
  3. Configure Endpoint DLP actions for the risky device activity
  4. Use a retention policy for broad location-based retention
  5. Use DLP policy test mode before full enforcement

Correct answer: E

Why: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. It directly addresses the stated requirement.

Option review:

A: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. It directly addresses the stated requirement.

Learning point: MS102-T21-Q005: Use DLP policy test mode before full enforcement – Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment.

Question 6

Graphic Design Institute is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The existing configuration works for normal operations but fails the new requirement to warn users during risky sharing or handling while preserving the designed DLP workflow. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 54 related tickets from 11 business units, so the team wants a targeted fix. Which control should the team use?

  1. Use policy tips when users should receive contextual guidance
  2. Create a custom sensitive information type with a regular expression and supporting evidence
  3. Use Content explorer to review where labeled or classified content exists
  4. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  5. Use a retention label when individual items need distinct retention behavior

Correct answer: A

Why: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. It directly addresses the stated requirement.

Option review:

A: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. It directly addresses the stated requirement.

B: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q006: Use policy tips when users should receive contextual guidance – Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions.

Question 7

Datum Dynamics is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The current workaround is too manual. The replacement should apply one data-loss prevention rule set across the workloads that handle the sensitive information. The initial rollout covers 24 locations and approximately 710 managed identities or devices. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use a keyword list as supporting evidence in the sensitive information type
  2. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  3. Use Activity explorer to review labeling actions
  4. Investigate the DLP alert and correlated events in Microsoft Purview
  5. Publish the retention label with a retention label policy

Correct answer: B

Why: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. It directly addresses the stated requirement.

Option review:

A: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. It directly addresses the stated requirement.

C: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q007: Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations – Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design.

Question 8

An incident review at Wingtip Services produces a single administrative requirement for the hybrid identity engineer. A post-incident action item requires the tenant to evaluate matches and user impact before blocking business activity broadly. The initial rollout covers 14 locations and approximately 880 managed identities or devices. The administrator must avoid granting unrelated tenant-wide privilege. Which control should the team use?

  1. Use a retention policy for broad location-based retention
  2. Use label reports for aggregate label adoption trends
  3. Use DLP policy test mode before full enforcement
  4. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  5. Create a sensitivity label that applies encryption and content markings

Correct answer: C

Why: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. It directly addresses the stated requirement.

Option review:

A: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. It directly addresses the stated requirement.

D: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q008: Use DLP policy test mode before full enforcement – Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment.

Question 9

Wide World Importers is preparing a change requested by the governance lead. The implementation review is focused on one outcome: warn users during risky sharing or handling while preserving the designed DLP workflow. The control owner requires a review after 14 days and evidence from 4 representative cases. The team does not want to redesign unrelated workloads. Which control should the team use?

  1. Use a retention label when individual items need distinct retention behavior
  2. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  3. Tune the DLP rule only after confirming the alert is a consistent false positive
  4. Use policy tips when users should receive contextual guidance
  5. Publish sensitivity labels through a sensitivity label policy

Correct answer: D

Why: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. It directly addresses the stated requirement.

Option review:

A: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. It directly addresses the stated requirement.

E: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q009: Use policy tips when users should receive contextual guidance – Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions.

Question 10

Lucerne Publishing is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The project board will approve the next step only if it can apply data-use restrictions to sensitive files on onboarded Windows endpoints. The control owner requires a review after 31 days and evidence from 17 representative cases. The team must preserve a clear audit trail for the administrative decision. Which option best satisfies the requirement?

  1. Publish the retention label with a retention label policy
  2. Use DLP policy test mode before full enforcement
  3. Create a custom sensitive information type with a regular expression and supporting evidence
  4. Use Content explorer to review where labeled or classified content exists
  5. Configure Endpoint DLP for the managed device scope

Correct answer: E

Why: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. It directly addresses the stated requirement.

Option review:

A: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. It directly addresses the stated requirement.

Learning point: MS102-T21-Q010: Configure Endpoint DLP for the managed device scope – Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy.

Question 11

Wide World Importers is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The support team has reproduced the issue and narrowed it to this requirement: audit, warn, or block the specific endpoint action that could exfiltrate sensitive data. The affected scope contains 48 users across 7 administrative groups. The organization wants a reversible rollout with measurable verification before broad enforcement. Which control should the team use?

  1. Configure Endpoint DLP actions for the risky device activity
  2. Create a sensitivity label that applies encryption and content markings
  3. Use policy tips when users should receive contextual guidance
  4. Use a keyword list as supporting evidence in the sensitive information type
  5. Use Activity explorer to review labeling actions

Correct answer: A

Why: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. It directly addresses the stated requirement.

B: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q011: Configure Endpoint DLP actions for the risky device activity – Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers.

Question 12

Humongous Insurance is migrating a business process to Microsoft 365 and wants the narrowest supported solution. An internal assessment finds the control technically functional but unable to confirm the device can generate the telemetry required for Endpoint DLP enforcement and reporting. The initial rollout covers 20 locations and approximately 650 managed identities or devices. The design should minimize manual per-user administration where a scoped central control exists. What is the most appropriate next step?

  1. Publish sensitivity labels through a sensitivity label policy
  2. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  3. Configure Endpoint DLP for the managed device scope
  4. Use a retention policy for broad location-based retention
  5. Use label reports for aggregate label adoption trends

Correct answer: B

Why: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. It directly addresses the stated requirement.

Option review:

A: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. It directly addresses the stated requirement.

C: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q012: Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event – A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first.

Question 13

Northwind Traders is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Before the tenant expands to another business unit, the administrator must apply data-use restrictions to sensitive files on onboarded Windows endpoints. The initial rollout covers 10 locations and approximately 820 managed identities or devices. The team must preserve a clear audit trail for the administrative decision. Which approach most directly addresses the requirement?

  1. Use Content explorer to review where labeled or classified content exists
  2. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  3. Configure Endpoint DLP for the managed device scope
  4. Use a retention label when individual items need distinct retention behavior
  5. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations

Correct answer: C

Why: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. It directly addresses the stated requirement.

Option review:

A: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. It directly addresses the stated requirement.

D: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q013: Configure Endpoint DLP for the managed device scope – Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy.

Question 14

Woodgrove Bank is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A production change is approved only if it can audit, warn, or block the specific endpoint action that could exfiltrate sensitive data. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The initial rollout covers 23 locations and approximately 80 managed identities or devices. Which control should the team use?

  1. Use Activity explorer to review labeling actions
  2. Investigate the DLP alert and correlated events in Microsoft Purview
  3. Publish the retention label with a retention label policy
  4. Configure Endpoint DLP actions for the risky device activity
  5. Use DLP policy test mode before full enforcement

Correct answer: D

Why: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. It directly addresses the stated requirement.

Option review:

A: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. It directly addresses the stated requirement.

E: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q014: Configure Endpoint DLP actions for the risky device activity – Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers.

Question 15

  1. Datum Manufacturing is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to confirm the device can generate the telemetry required for Endpoint DLP enforcement and reporting. The service desk has 25 related tickets from 13 business units, so the team wants a targeted fix. The organization wants a reversible rollout with measurable verification before broad enforcement. Which approach most directly addresses the requirement?
  2. Use label reports for aggregate label adoption trends
  3. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  4. Create a sensitivity label that applies encryption and content markings
  5. Use policy tips when users should receive contextual guidance
  6. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event

Correct answer: E

Why: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. It directly addresses the stated requirement.

Option review:

A: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. It directly addresses the stated requirement.

Learning point: MS102-T21-Q015: Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event – A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first.

Question 16

Trey Research is preparing a change requested by the messaging administrator. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to apply data-use restrictions to sensitive files on onboarded Windows endpoints. The administrator must avoid granting unrelated tenant-wide privilege. The control owner requires a review after 42 days and evidence from 3 representative cases. What should the administrator configure first?

  1. Configure Endpoint DLP for the managed device scope
  2. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  3. Tune the DLP rule only after confirming the alert is a consistent false positive
  4. Publish sensitivity labels through a sensitivity label policy
  5. Configure Endpoint DLP actions for the risky device activity

Correct answer: A

Why: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. It directly addresses the stated requirement.

B: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q016: Configure Endpoint DLP for the managed device scope – Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy.

Question 17

Blue Yonder Airlines is preparing a change requested by the hybrid identity engineer. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to audit, warn, or block the specific endpoint action that could exfiltrate sensitive data. The initial rollout covers 16 locations and approximately 590 managed identities or devices. The organization wants a reversible rollout with measurable verification before broad enforcement. What is the most appropriate next step?

  1. Use DLP policy test mode before full enforcement
  2. Configure Endpoint DLP actions for the risky device activity
  3. Create a custom sensitive information type with a regular expression and supporting evidence
  4. Use Content explorer to review where labeled or classified content exists
  5. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event

Correct answer: B

Why: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. It directly addresses the stated requirement.

Option review:

A: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. It directly addresses the stated requirement.

C: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q017: Configure Endpoint DLP actions for the risky device activity – Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers.

Question 18

A quarterly control review at Graphic Design Institute identifies a gap that must be corrected before the next audit. Security and operations teams agree on the target state: determine what content, user action, rule, and location caused a DLP alert. The response must address the cause described in the scenario rather than simply suppressing the symptom. The service desk has 76 related tickets from 6 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use policy tips when users should receive contextual guidance
  2. Use a keyword list as supporting evidence in the sensitive information type
  3. Investigate the DLP alert and correlated events in Microsoft Purview
  4. Use Activity explorer to review labeling actions
  5. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event

Correct answer: C

Why: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. It directly addresses the stated requirement.

Option review:

A: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. It directly addresses the stated requirement.

D: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q018: Investigate the DLP alert and correlated events in Microsoft Purview – DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required.

Question 19

The security administrator at Datum Dynamics is designing the next phase of the Microsoft 365 rollout. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to determine whether an alert represents an isolated mistake or a broader behavior trend. The design should minimize manual per-user administration where a scoped central control exists. The service desk has 93 related tickets from 19 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Configure Endpoint DLP for the managed device scope
  2. Use a retention policy for broad location-based retention
  3. Use label reports for aggregate label adoption trends
  4. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  5. Investigate the DLP alert and correlated events in Microsoft Purview

Correct answer: D

Why: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. It directly addresses the stated requirement.

E: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q019: Use DLP reports or Activity explorer to identify recurring policy-match patterns – DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert.

Question 20

An incident review at Trey Research produces a single administrative requirement for the tenant administrator. The organization is replacing a manual process. The replacement must reduce noisy DLP matches without weakening protection for real sensitive-data events while remaining centrally manageable. The initial rollout covers 9 locations and approximately 190 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which option best satisfies the requirement?

  1. Configure Endpoint DLP actions for the risky device activity
  2. Use a retention label when individual items need distinct retention behavior
  3. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  4. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  5. Tune the DLP rule only after confirming the alert is a consistent false positive

Correct answer: E

Why: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. It directly addresses the stated requirement.

Learning point: MS102-T21-Q020: Tune the DLP rule only after confirming the alert is a consistent false positive – Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap.

Question 21

Coho Winery has completed a pilot and must now choose the production administration approach. The administrator must choose between several Microsoft 365 controls. Only one directly meets the documented need to determine what content, user action, rule, and location caused a DLP alert. The change must be repeatable and supportable after the project team leaves. The service desk has 36 related tickets from 22 business units, so the team wants a targeted fix. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Investigate the DLP alert and correlated events in Microsoft Purview
  2. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  3. Publish the retention label with a retention label policy
  4. Use DLP policy test mode before full enforcement
  5. Create a custom sensitive information type with a regular expression and supporting evidence

Correct answer: A

Why: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. It directly addresses the stated requirement.

Option review:

A: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. It directly addresses the stated requirement.

B: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q021: Investigate the DLP alert and correlated events in Microsoft Purview – DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required.

Question 22

A quarterly control review at Margie Travel identifies a gap that must be corrected before the next audit. The implementation review is focused on one outcome: determine whether an alert represents an isolated mistake or a broader behavior trend. The control owner requires a review after 53 days and evidence from 12 representative cases. The team does not want to redesign unrelated workloads. What should the administrator configure first?

  1. Investigate the DLP alert and correlated events in Microsoft Purview
  2. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  3. Create a sensitivity label that applies encryption and content markings
  4. Use policy tips when users should receive contextual guidance
  5. Use a keyword list as supporting evidence in the sensitive information type

Correct answer: B

Why: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. It directly addresses the stated requirement.

Option review:

A: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. It directly addresses the stated requirement.

C: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q022: Use DLP reports or Activity explorer to identify recurring policy-match patterns – DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert.

Question 23

Southridge Video is migrating a business process to Microsoft 365 and wants the narrowest supported solution. Administrators have confirmed the present design does not reduce noisy DLP matches without weakening protection for real sensitive-data events. The service desk has 70 related tickets from 2 business units, so the team wants a targeted fix. The architecture board will reject a choice that solves a different problem from the one stated. Which option best satisfies the requirement?

  1. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  2. Publish sensitivity labels through a sensitivity label policy
  3. Tune the DLP rule only after confirming the alert is a consistent false positive
  4. Configure Endpoint DLP for the managed device scope
  5. Use a retention policy for broad location-based retention

Correct answer: C

Why: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. It directly addresses the stated requirement.

Option review:

A: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. It directly addresses the stated requirement.

D: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q023: Tune the DLP rule only after confirming the alert is a consistent false positive – Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap.

Question 24

Fabrikam Health is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The next migration wave is blocked until the team can determine what content, user action, rule, and location caused a DLP alert. The team must preserve a clear audit trail for the administrative decision. The affected scope contains 87 users across 15 administrative groups. Which approach most directly addresses the requirement?

  1. Create a custom sensitive information type with a regular expression and supporting evidence
  2. Use Content explorer to review where labeled or classified content exists
  3. Configure Endpoint DLP actions for the risky device activity
  4. Investigate the DLP alert and correlated events in Microsoft Purview
  5. Use a retention label when individual items need distinct retention behavior

Correct answer: D

Why: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. It directly addresses the stated requirement.

Option review:

A: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. It directly addresses the stated requirement.

E: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T21-Q024: Investigate the DLP alert and correlated events in Microsoft Purview – DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required.

Question 25

Trey Research is standardizing administration after several teams used inconsistent procedures. The organization is replacing a manual process. The replacement must determine whether an alert represents an isolated mistake or a broader behavior trend while remaining centrally manageable. The team will validate the change with 5 pilot groups before expanding it to 13 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use a keyword list as supporting evidence in the sensitive information type
  2. Use Activity explorer to review labeling actions
  3. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  4. Publish the retention label with a retention label policy
  5. Use DLP reports or Activity explorer to identify recurring policy-match patterns

Correct answer: E

Why: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. It directly addresses the stated requirement.

Option review:

A: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. It directly addresses the stated requirement.

Learning point: MS102-T21-Q025: Use DLP reports or Activity explorer to identify recurring policy-match patterns – DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert.

Popular posts

img