Microsoft MS-102 Purview Sensitive Information Types Retention Labels And Retention Policies Practice Test

 

MS-102 skills 4.1 | 25 original questions

This MS-102 practice set focuses on purview sensitive information types retention labels and retention policies through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

Southridge Video has completed a pilot and must now choose the production administration approach. A post-incident action item requires the tenant to detect an organization-specific identifier that follows a stable pattern and requires contextual validation. The service desk has 29 related tickets from 9 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. Which control should the team use?

  1. Create a custom sensitive information type with a regular expression and supporting evidence
  2. Use policy tips when users should receive contextual guidance
  3. Use a keyword list as supporting evidence in the sensitive information type
  4. Use Activity explorer to review labeling actions
  5. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event

Correct answer: A

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

B: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q001: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 2

A quarterly control review at Trey Research identifies a gap that must be corrected before the next audit. The administrator is comparing native Microsoft controls after documenting a requirement to improve confidence that a pattern match represents the intended business data. The initial rollout covers 22 locations and approximately 460 managed identities or devices. The solution should use a native Microsoft control that matches the stated requirement. What is the most appropriate next step?

  1. Configure Endpoint DLP for the managed device scope
  2. Use a keyword list as supporting evidence in the sensitive information type
  3. Use a retention policy for broad location-based retention
  4. Use label reports for aggregate label adoption trends
  5. Investigate the DLP alert and correlated events in Microsoft Purview

Correct answer: B

Why: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

C: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q002: Use a keyword list as supporting evidence in the sensitive information type – Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences.

Question 3

An incident review at Humongous Insurance produces a single administrative requirement for the tenant administrator. A production change is approved only if it can detect an organization-specific identifier that follows a stable pattern and requires contextual validation. Existing workload settings should remain unchanged unless the requirement specifically depends on them. The affected scope contains 63 users across 12 administrative groups. Which administrative choice should be recommended?

  1. Configure Endpoint DLP actions for the risky device activity
  2. Use a retention label when individual items need distinct retention behavior
  3. Create a custom sensitive information type with a regular expression and supporting evidence
  4. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  5. Use DLP reports or Activity explorer to identify recurring policy-match patterns

Correct answer: C

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

D: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q003: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 4

Wingtip Services has completed a pilot and must now choose the production administration approach. The organization is replacing a manual process. The replacement must improve confidence that a pattern match represents the intended business data while remaining centrally manageable. The service desk has 80 related tickets from 2 business units, so the team wants a targeted fix. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?

  1. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  2. Publish the retention label with a retention label policy
  3. Use DLP policy test mode before full enforcement
  4. Use a keyword list as supporting evidence in the sensitive information type
  5. Tune the DLP rule only after confirming the alert is a consistent false positive

Correct answer: D

Why: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Option review:

A: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

E: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q004: Use a keyword list as supporting evidence in the sensitive information type – Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences.

Question 5

Margie Travel is preparing a change requested by the Microsoft 365 administrator. A controlled pilot must demonstrate how to detect an organization-specific identifier that follows a stable pattern and requires contextual validation. The change must be repeatable and supportable after the project team leaves. The affected scope contains 6 users across 15 administrative groups. Which control should the team use?

  1. Investigate the DLP alert and correlated events in Microsoft Purview
  2. Create a sensitivity label that applies encryption and content markings
  3. Use policy tips when users should receive contextual guidance
  4. Use a keyword list as supporting evidence in the sensitive information type
  5. Create a custom sensitive information type with a regular expression and supporting evidence

Correct answer: E

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Learning point: MS102-T19-Q005: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 6

A quarterly control review at Woodgrove Bank identifies a gap that must be corrected before the next audit. The project board will approve the next step only if it can improve confidence that a pattern match represents the intended business data. The service desk has 23 related tickets from 5 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which option best satisfies the requirement?

  1. Use a keyword list as supporting evidence in the sensitive information type
  2. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  3. Publish sensitivity labels through a sensitivity label policy
  4. Configure Endpoint DLP for the managed device scope
  5. Use a retention policy for broad location-based retention

Correct answer: A

Why: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Option review:

A: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

B: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q006: Use a keyword list as supporting evidence in the sensitive information type – Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences.

Question 7

Humongous Insurance is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to detect an organization-specific identifier that follows a stable pattern and requires contextual validation. The service desk has 40 related tickets from 18 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which option best satisfies the requirement?

  1. Tune the DLP rule only after confirming the alert is a consistent false positive
  2. Create a custom sensitive information type with a regular expression and supporting evidence
  3. Use Content explorer to review where labeled or classified content exists
  4. Configure Endpoint DLP actions for the risky device activity
  5. Use a retention label when individual items need distinct retention behavior

Correct answer: B

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

C: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q007: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 8

The tenant administrator at Wingtip Services is designing the next phase of the Microsoft 365 rollout. The next migration wave is blocked until the team can improve confidence that a pattern match represents the intended business data. The organization wants a reversible rollout with measurable verification before broad enforcement. The initial rollout covers 8 locations and approximately 570 managed identities or devices. Which option best satisfies the requirement?

  1. Create a custom sensitive information type with a regular expression and supporting evidence
  2. Use Activity explorer to review labeling actions
  3. Use a keyword list as supporting evidence in the sensitive information type
  4. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  5. Publish the retention label with a retention label policy

Correct answer: C

Why: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Option review:

A: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

D: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q008: Use a keyword list as supporting evidence in the sensitive information type – Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences.

Question 9

VanArsdel Media is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A production change is approved only if it can detect an organization-specific identifier that follows a stable pattern and requires contextual validation. The response must address the cause described in the scenario rather than simply suppressing the symptom. The team will validate the change with 21 pilot groups before expanding it to 74 users. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use a retention policy for broad location-based retention
  2. Use label reports for aggregate label adoption trends
  3. Investigate the DLP alert and correlated events in Microsoft Purview
  4. Create a custom sensitive information type with a regular expression and supporting evidence
  5. Create a sensitivity label that applies encryption and content markings

Correct answer: D

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

E: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q009: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 10

Northwind Traders is preparing a change requested by the compliance administrator. The next migration wave is blocked until the team can improve confidence that a pattern match represents the intended business data. The organization wants a reversible rollout with measurable verification before broad enforcement. The initial rollout covers 11 locations and approximately 910 managed identities or devices. What is the most appropriate next step?

  1. Use a retention label when individual items need distinct retention behavior
  2. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  3. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  4. Publish sensitivity labels through a sensitivity label policy
  5. Use a keyword list as supporting evidence in the sensitive information type

Correct answer: E

Why: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Option review:

A: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Learning point: MS102-T19-Q010: Use a keyword list as supporting evidence in the sensitive information type – Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences.

Question 11

An incident review at VanArsdel Media produces a single administrative requirement for the service desk lead. A post-incident action item requires the tenant to detect an organization-specific identifier that follows a stable pattern and requires contextual validation. The control owner requires a review after 17 days and evidence from 24 representative cases. The organization wants a reversible rollout with measurable verification before broad enforcement. Which control should the team use?

  1. Create a custom sensitive information type with a regular expression and supporting evidence
  2. Publish the retention label with a retention label policy
  3. Use DLP policy test mode before full enforcement
  4. Tune the DLP rule only after confirming the alert is a consistent false positive
  5. Use Content explorer to review where labeled or classified content exists

Correct answer: A

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

B: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q011: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 12

Fourth Coffee is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A controlled pilot must demonstrate how to improve confidence that a pattern match represents the intended business data. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 34 users across 14 administrative groups. Which control should the team use?

  1. Create a sensitivity label that applies encryption and content markings
  2. Use a keyword list as supporting evidence in the sensitive information type
  3. Use policy tips when users should receive contextual guidance
  4. Create a custom sensitive information type with a regular expression and supporting evidence
  5. Use Activity explorer to review labeling actions

Correct answer: B

Why: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

Option review:

A: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. It directly addresses the stated requirement.

C: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q012: Use a keyword list as supporting evidence in the sensitive information type – Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences.

Question 13

The operations team at Tailspin Toys needs to resolve an issue without granting broader permissions than necessary. A post-incident action item requires the tenant to detect an organization-specific identifier that follows a stable pattern and requires contextual validation. The initial rollout covers 4 locations and approximately 510 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which option best satisfies the requirement?

  1. Publish sensitivity labels through a sensitivity label policy
  2. Configure Endpoint DLP for the managed device scope
  3. Create a custom sensitive information type with a regular expression and supporting evidence
  4. Use a retention policy for broad location-based retention
  5. Use label reports for aggregate label adoption trends

Correct answer: C

Why: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

Option review:

A: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. It directly addresses the stated requirement.

D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q013: Create a custom sensitive information type with a regular expression and supporting evidence – Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches.

Question 14

Consolidated Messenger is preparing a change requested by the hybrid identity engineer. The existing configuration works for normal operations but fails the new requirement to apply the same retention behavior broadly across selected Microsoft 365 locations without requiring users to label individual items. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. The affected scope contains 68 users across 17 administrative groups. Which administrative choice should be recommended?

  1. Use Content explorer to review where labeled or classified content exists
  2. Configure Endpoint DLP actions for the risky device activity
  3. Use a retention label when individual items need distinct retention behavior
  4. Use a retention policy for broad location-based retention
  5. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations

Correct answer: D

Why: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

Option review:

A: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

E: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q014: Use a retention policy for broad location-based retention – Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements.

Question 15

  1. Datum Manufacturing is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The current workaround is too manual. The replacement should apply item-level retention classification that can differ from surrounding content. The service desk has 85 related tickets from 7 business units, so the team wants a targeted fix. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which option best satisfies the requirement?
  2. Use Activity explorer to review labeling actions
  3. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  4. Publish the retention label with a retention label policy
  5. Use DLP policy test mode before full enforcement
  6. Use a retention label when individual items need distinct retention behavior

Correct answer: E

Why: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

Option review:

A: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

Learning point: MS102-T19-Q015: Use a retention label when individual items need distinct retention behavior – Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment.

Question 16

An incident review at Proseware Logistics produces a single administrative requirement for the security operations analyst. A controlled pilot must demonstrate how to make a retention label available to the intended users or locations. The architecture board will reject a choice that solves a different problem from the one stated. The initial rollout covers 20 locations and approximately 110 managed identities or devices. Which control should the team use?

  1. Publish the retention label with a retention label policy
  2. Use label reports for aggregate label adoption trends
  3. Investigate the DLP alert and correlated events in Microsoft Purview
  4. Create a sensitivity label that applies encryption and content markings
  5. Use policy tips when users should receive contextual guidance

Correct answer: A

Why: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

Option review:

A: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

B: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q016: Publish the retention label with a retention label policy – Creating a retention label defines its settings, while a label policy controls where or to whom that label is published.

Question 17

An incident review at Trey Research produces a single administrative requirement for the tenant administrator. The support team has reproduced the issue and narrowed it to this requirement: apply the same retention behavior broadly across selected Microsoft 365 locations without requiring users to label individual items. The control owner requires a review after 28 days and evidence from 10 representative cases. The design should minimize manual per-user administration where a scoped central control exists. Which administrative choice should be recommended?

  1. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  2. Use a retention policy for broad location-based retention
  3. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  4. Publish sensitivity labels through a sensitivity label policy
  5. Configure Endpoint DLP for the managed device scope

Correct answer: B

Why: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

Option review:

A: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

C: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q017: Use a retention policy for broad location-based retention – Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements.

Question 18

Adventure Works is standardizing administration after several teams used inconsistent procedures. The change advisory board wants the smallest supported control that can apply item-level retention classification that can differ from surrounding content. The initial rollout covers 23 locations and approximately 450 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?

  1. Use DLP policy test mode before full enforcement
  2. Tune the DLP rule only after confirming the alert is a consistent false positive
  3. Use a retention label when individual items need distinct retention behavior
  4. Use Content explorer to review where labeled or classified content exists
  5. Configure Endpoint DLP actions for the risky device activity

Correct answer: C

Why: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

Option review:

A: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

D: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q018: Use a retention label when individual items need distinct retention behavior – Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment.

Question 19

Contoso Retail is migrating a business process to Microsoft 365 and wants the narrowest supported solution. A post-incident action item requires the tenant to make a retention label available to the intended users or locations. The control owner requires a review after 62 days and evidence from 13 representative cases. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?

  1. Use policy tips when users should receive contextual guidance
  2. Create a custom sensitive information type with a regular expression and supporting evidence
  3. Use Activity explorer to review labeling actions
  4. Publish the retention label with a retention label policy
  5. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event

Correct answer: D

Why: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

Option review:

A: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

E: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q019: Publish the retention label with a retention label policy – Creating a retention label defines its settings, while a label policy controls where or to whom that label is published.

Question 20

The security administrator at Northwind Traders is designing the next phase of the Microsoft 365 rollout. The change advisory board wants the smallest supported control that can apply the same retention behavior broadly across selected Microsoft 365 locations without requiring users to label individual items. The control owner requires a review after 79 days and evidence from 3 representative cases. The team must preserve a clear audit trail for the administrative decision. Which action should the administrator take?

  1. Configure Endpoint DLP for the managed device scope
  2. Use a keyword list as supporting evidence in the sensitive information type
  3. Use label reports for aggregate label adoption trends
  4. Investigate the DLP alert and correlated events in Microsoft Purview
  5. Use a retention policy for broad location-based retention

Correct answer: E

Why: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

Option review:

A: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

Learning point: MS102-T19-Q020: Use a retention policy for broad location-based retention – Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements.

Question 21

During a tenant review at Humongous Insurance, the security operations analyst identifies one unresolved requirement. The support team has reproduced the issue and narrowed it to this requirement: apply item-level retention classification that can differ from surrounding content. The initial rollout covers 16 locations and approximately 50 managed identities or devices. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which approach most directly addresses the requirement?

  1. Use a retention label when individual items need distinct retention behavior
  2. Configure Endpoint DLP actions for the risky device activity
  3. Use a retention policy for broad location-based retention
  4. Create a Microsoft Purview DLP policy and select the required Microsoft 365 locations
  5. Use DLP reports or Activity explorer to identify recurring policy-match patterns

Correct answer: A

Why: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

Option review:

A: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

B: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q021: Use a retention label when individual items need distinct retention behavior – Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment.

Question 22

The operations team at Proseware Logistics needs to resolve an issue without granting broader permissions than necessary. Administrators have confirmed the present design does not make a retention label available to the intended users or locations. The control owner requires a review after 22 days and evidence from 6 representative cases. The architecture board will reject a choice that solves a different problem from the one stated. Which approach most directly addresses the requirement?

  1. Verify the endpoint is onboarded and in scope before troubleshooting a missing Endpoint DLP event
  2. Publish the retention label with a retention label policy
  3. Use a retention label when individual items need distinct retention behavior
  4. Use DLP policy test mode before full enforcement
  5. Tune the DLP rule only after confirming the alert is a consistent false positive

Correct answer: B

Why: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

Option review:

A: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

C: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q022: Publish the retention label with a retention label policy – Creating a retention label defines its settings, while a label policy controls where or to whom that label is published.

Question 23

Humongous Insurance is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The implementation review is focused on one outcome: apply the same retention behavior broadly across selected Microsoft 365 locations without requiring users to label individual items. The control owner requires a review after 39 days and evidence from 19 representative cases. The team does not want to redesign unrelated workloads. Which approach most directly addresses the requirement?

  1. Investigate the DLP alert and correlated events in Microsoft Purview
  2. Create a sensitivity label that applies encryption and content markings
  3. Use a retention policy for broad location-based retention
  4. Use policy tips when users should receive contextual guidance
  5. Create a custom sensitive information type with a regular expression and supporting evidence

Correct answer: C

Why: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

Option review:

A: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. It directly addresses the stated requirement.

D: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q023: Use a retention policy for broad location-based retention – Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements.

Question 24

The governance lead at Wide World Importers is designing the next phase of the Microsoft 365 rollout. The current workaround is too manual. The replacement should apply item-level retention classification that can differ from surrounding content. The service desk has 56 related tickets from 9 business units, so the team wants a targeted fix. The design should minimize manual per-user administration where a scoped central control exists. Which option best satisfies the requirement?

  1. Use DLP reports or Activity explorer to identify recurring policy-match patterns
  2. Publish sensitivity labels through a sensitivity label policy
  3. Configure Endpoint DLP for the managed device scope
  4. Use a retention label when individual items need distinct retention behavior
  5. Use a keyword list as supporting evidence in the sensitive information type

Correct answer: D

Why: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

Option review:

A: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. It directly addresses the stated requirement.

E: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

Learning point: MS102-T19-Q024: Use a retention label when individual items need distinct retention behavior – Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment.

Question 25

The hybrid identity engineer at Tailspin Toys is designing the next phase of the Microsoft 365 rollout. The implementation review is focused on one outcome: make a retention label available to the intended users or locations. The affected scope contains 73 users across 22 administrative groups. The team does not want to redesign unrelated workloads. Which control should the team use?

  1. Tune the DLP rule only after confirming the alert is a consistent false positive
  2. Use Content explorer to review where labeled or classified content exists
  3. Configure Endpoint DLP actions for the risky device activity
  4. Use a retention policy for broad location-based retention
  5. Publish the retention label with a retention label policy

Correct answer: E

Why: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

Option review:

A: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

B: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

C: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.

E: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. It directly addresses the stated requirement.

Learning point: MS102-T19-Q025: Publish the retention label with a retention label policy – Creating a retention label defines its settings, while a label policy controls where or to whom that label is published.

Popular posts

img