Microsoft MS-102 Purview Sensitivity Labels Content Explorer Activity Explorer And Label Reports Practice Test
MS-102 skills 4.1 | 25 original questions
This MS-102 practice set focuses on purview sensitivity labels content explorer activity explorer and label reports through original scenario-based questions aligned to Microsoft skills measured as of April 28, 2026. Use the full ExamSnap MS-102 collection for practice across all four current skill areas. For broader exam preparation, review the Microsoft MS-102 Exam Dumps page.
Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.
Question 1
A quarterly control review at Humongous Insurance identifies a gap that must be corrected before the next audit. The organization is replacing a manual process. The replacement must classify confidential content and enforce protection that travels with the labeled file or message while remaining centrally manageable. The affected scope contains 90 users across 12 administrative groups. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What should the administrator configure first?
Correct answer: A
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
B: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q001: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 2
A quarterly control review at Contoso Retail identifies a gap that must be corrected before the next audit. Audit evidence shows that the current process cannot reliably make the configured labels available to the intended users and workloads. The architecture board will reject a choice that solves a different problem from the one stated. The service desk has 16 related tickets from 2 business units, so the team wants a targeted fix. What should the administrator configure first?
Correct answer: B
Why: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Option review:
A: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
C: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q002: Publish sensitivity labels through a sensitivity label policy – Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior.
Question 3
During a tenant review at A. Datum Manufacturing, the security administrator identifies one unresolved requirement. The support team has reproduced the issue and narrowed it to this requirement: classify confidential content and enforce protection that travels with the labeled file or message. The service desk has 33 related tickets from 15 business units, so the team wants a targeted fix. Existing workload settings should remain unchanged unless the requirement specifically depends on them. What is the most appropriate next step?
Correct answer: C
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
D: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q003: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 4
Proseware Logistics is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. Administrators have confirmed the present design does not make the configured labels available to the intended users and workloads. The service desk has 50 related tickets from 5 business units, so the team wants a targeted fix. The solution should use a native Microsoft control that matches the stated requirement. What is the most appropriate next step?
Correct answer: D
Why: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Option review:
A: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
E: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q004: Publish sensitivity labels through a sensitivity label policy – Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior.
Question 5
Margie Travel is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The service owner wants a supportable design that will classify confidential content and enforce protection that travels with the labeled file or message. The team must preserve a clear audit trail for the administrative decision. The control owner requires a review after 67 days and evidence from 18 representative cases. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: E
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Learning point: MS102-T20-Q005: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 6
During a tenant review at Proseware Logistics, the security administrator identifies one unresolved requirement. The administrator is comparing native Microsoft controls after documenting a requirement to make the configured labels available to the intended users and workloads. The team will validate the change with 8 pilot groups before expanding it to 84 users. The organization wants a reversible rollout with measurable verification before broad enforcement. Which action should the administrator take?
Correct answer: A
Why: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Option review:
A: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
B: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q006: Publish sensitivity labels through a sensitivity label policy – Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior.
Question 7
During a tenant review at Coho Winery, the messaging administrator identifies one unresolved requirement. Before the tenant expands to another business unit, the administrator must classify confidential content and enforce protection that travels with the labeled file or message. The team will validate the change with 21 pilot groups before expanding it to 10 users. The team wants evidence from the Microsoft 365 or Microsoft Entra control plane rather than assumptions. Which option best satisfies the requirement?
Correct answer: B
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
C: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q007: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 8
The governance lead at A. Datum Manufacturing is designing the next phase of the Microsoft 365 rollout. The administrator is comparing native Microsoft controls after documenting a requirement to make the configured labels available to the intended users and workloads. The affected scope contains 27 users across 11 administrative groups. The response must address the cause described in the scenario rather than simply suppressing the symptom. What should the administrator configure first?
Correct answer: C
Why: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Option review:
A: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
D: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q008: Publish sensitivity labels through a sensitivity label policy – Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior.
Question 9
Adventure Works is standardizing administration after several teams used inconsistent procedures. An internal assessment finds the control technically functional but unable to classify confidential content and enforce protection that travels with the labeled file or message. The initial rollout covers 24 locations and approximately 440 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which control should the team use?
Correct answer: D
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
E: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q009: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 10
Consolidated Messenger has completed a pilot and must now choose the production administration approach. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to make the configured labels available to the intended users and workloads. The control owner requires a review after 61 days and evidence from 14 representative cases. The administrator must avoid granting unrelated tenant-wide privilege. What is the most appropriate next step?
Correct answer: E
Why: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Option review:
A: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Learning point: MS102-T20-Q010: Publish sensitivity labels through a sensitivity label policy – Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior.
Question 11
Southridge Video is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The current workaround is too manual. The replacement should classify confidential content and enforce protection that travels with the labeled file or message. The team will validate the change with 4 pilot groups before expanding it to 78 users. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
B: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q011: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 12
Datum Dynamics is preparing a change requested by the tenant administrator. The existing configuration works for normal operations but fails the new requirement to make the configured labels available to the intended users and workloads. The administrator must avoid granting unrelated tenant-wide privilege. The service desk has 95 related tickets from 17 business units, so the team wants a targeted fix. What should the administrator configure first?
Correct answer: B
Why: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
Option review:
A: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. It directly addresses the stated requirement.
C: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q012: Publish sensitivity labels through a sensitivity label policy – Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior.
Question 13
Datum Dynamics is migrating a business process to Microsoft 365 and wants the narrowest supported solution. The next migration wave is blocked until the team can classify confidential content and enforce protection that travels with the labeled file or message. The solution should use a native Microsoft control that matches the stated requirement. The service desk has 21 related tickets from 7 business units, so the team wants a targeted fix. What should the administrator configure first?
Correct answer: C
Why: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
Option review:
A: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. It directly addresses the stated requirement.
D: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q013: Create a sensitivity label that applies encryption and content markings – Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content.
Question 14
Datum Dynamics is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. The service owner wants a supportable design that will see a snapshot of items carrying sensitivity labels, retention labels, or sensitive information classifications. The team must preserve a clear audit trail for the administrative decision. The affected scope contains 38 users across 20 administrative groups. Which approach most directly addresses the requirement?
Correct answer: D
Why: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
Option review:
A: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
E: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q014: Use Content explorer to review where labeled or classified content exists – Content explorer is designed to browse and investigate classified content by location and label or information type.
Question 15
An incident review at Litware Financial produces a single administrative requirement for the compliance administrator. The current workaround is too manual. The replacement should investigate who applied, changed, removed, or otherwise interacted with labels. The initial rollout covers 10 locations and approximately 550 managed identities or devices. Existing workload settings should remain unchanged unless the requirement specifically depends on them. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: E
Why: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
Option review:
A: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
Learning point: MS102-T20-Q015: Use Activity explorer to review labeling actions – Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory.
Question 16
During a tenant review at Wingtip Services, the tenant administrator identifies one unresolved requirement. The administrator is comparing native Microsoft controls after documenting a requirement to monitor labeling usage and distribution at a reporting level without opening individual items. The service desk has 72 related tickets from 23 business units, so the team wants a targeted fix. The change must be repeatable and supportable after the project team leaves. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: A
Why: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
Option review:
A: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
B: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q016: Use label reports for aggregate label adoption trends – Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views.
Question 17
Coho Winery is preparing a change requested by the Microsoft 365 administrator. The change advisory board wants the smallest supported control that can see a snapshot of items carrying sensitivity labels, retention labels, or sensitive information classifications. The initial rollout covers 13 locations and approximately 890 managed identities or devices. The response must address the cause described in the scenario rather than simply suppressing the symptom. What should the administrator configure first?
Correct answer: B
Why: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
Option review:
A: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
C: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q017: Use Content explorer to review where labeled or classified content exists – Content explorer is designed to browse and investigate classified content by location and label or information type.
Question 18
Proseware Logistics is standardizing administration after several teams used inconsistent procedures. A post-incident action item requires the tenant to investigate who applied, changed, removed, or otherwise interacted with labels. The service desk has 15 related tickets from 3 business units, so the team wants a targeted fix. The architecture board will reject a choice that solves a different problem from the one stated. Which approach most directly addresses the requirement?
Correct answer: C
Why: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
Option review:
A: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
D: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q018: Use Activity explorer to review labeling actions – Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory.
Question 19
City Power & Light is preparing a change requested by the service desk lead. The change advisory board wants the smallest supported control that can monitor labeling usage and distribution at a reporting level without opening individual items. The service desk has 32 related tickets from 16 business units, so the team wants a targeted fix. The response must address the cause described in the scenario rather than simply suppressing the symptom. Which approach most directly addresses the requirement?
Correct answer: D
Why: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
Option review:
A: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
E: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q019: Use label reports for aggregate label adoption trends – Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views.
Question 20
The security administrator at Lucerne Publishing is designing the next phase of the Microsoft 365 rollout. The change advisory board wants the smallest supported control that can see a snapshot of items carrying sensitivity labels, retention labels, or sensitive information classifications. The control owner requires a review after 49 days and evidence from 6 representative cases. The change must be repeatable and supportable after the project team leaves. Which option best satisfies the requirement?
Correct answer: E
Why: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
Option review:
A: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Custom sensitive information types can combine regex patterns with supporting elements such as keywords and proximity to reduce false matches. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
Learning point: MS102-T20-Q020: Use Content explorer to review where labeled or classified content exists – Content explorer is designed to browse and investigate classified content by location and label or information type.
Question 21
The messaging administrator at Blue Yonder Airlines is designing the next phase of the Microsoft 365 rollout. Administrators have confirmed the present design does not investigate who applied, changed, removed, or otherwise interacted with labels. The initial rollout covers 19 locations and approximately 660 managed identities or devices. The change must be repeatable and supportable after the project team leaves. Which administrative choice should be recommended?
Correct answer: A
Why: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
Option review:
A: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
B: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Supporting keywords can provide context around a primary pattern and help distinguish meaningful sensitive data from coincidental character sequences. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q021: Use Activity explorer to review labeling actions – Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory.
Question 22
A quarterly control review at Consolidated Messenger identifies a gap that must be corrected before the next audit. A production change is approved only if it can monitor labeling usage and distribution at a reporting level without opening individual items. The design should minimize manual per-user administration where a scoped central control exists. The team will validate the change with 9 pilot groups before expanding it to 83 users. Which Microsoft 365 or Microsoft Entra capability is the best fit?
Correct answer: B
Why: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
Option review:
A: Testing a DLP policy helps validate detection conditions and expected actions while reducing the risk of an overly disruptive first deployment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
C: Rule tuning should be based on investigated evidence so changes improve precision without creating an unnecessary data-loss gap. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Retention policies apply retention settings at the location or container scope and are appropriate for broad retention requirements. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q022: Use label reports for aggregate label adoption trends – Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views.
Question 23
Correct answer: C
Why: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
Option review:
A: Policy tips provide in-context user feedback when DLP rules match and can support behavior change alongside enforcement actions. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Sensitivity labels can apply protection such as encryption and visual markings while embedding the classification with the content. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Content explorer is designed to browse and investigate classified content by location and label or information type. It directly addresses the stated requirement.
D: Retention labels travel with individual items and are appropriate when records or content types require item-specific retention treatment. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: A device outside the onboarding or policy scope will not behave like a properly managed Endpoint DLP endpoint, so scope should be checked first. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q023: Use Content explorer to review where labeled or classified content exists – Content explorer is designed to browse and investigate classified content by location and label or information type.
Question 24
Contoso Retail is troubleshooting a Microsoft 365 behavior that affects a limited but important user population. A root-cause review has ruled out licensing and connectivity problems; the remaining need is to investigate who applied, changed, removed, or otherwise interacted with labels. The initial rollout covers 12 locations and approximately 260 managed identities or devices. The organization wants a reversible rollout with measurable verification before broad enforcement. Which action should the administrator take?
Correct answer: D
Why: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
Option review:
A: Endpoint DLP extends Purview DLP controls to device activities such as copying, printing, browser upload, or transfer to removable media, depending on configured policy. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Label policies determine which users can see and use sensitivity labels and can configure related labeling behavior. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Creating a retention label defines its settings, while a label policy controls where or to whom that label is published. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory. It directly addresses the stated requirement.
E: DLP alerts and events provide the evidence needed to validate the policy match and decide whether remediation or tuning is required. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
Learning point: MS102-T20-Q024: Use Activity explorer to review labeling actions – Activity explorer is event-oriented and captures labeling and related compliance activities rather than only a static content inventory.
Question 25
Humongous Insurance is preparing a change requested by the Microsoft 365 administrator. Administrators have confirmed the present design does not monitor labeling usage and distribution at a reporting level without opening individual items. The team will validate the change with 2 pilot groups before expanding it to 43 users. The architecture board will reject a choice that solves a different problem from the one stated. Which action should the administrator take?
Correct answer: E
Why: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
Option review:
A: Endpoint DLP rules can apply actions to device activities rather than only monitoring cloud-service transfers. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
B: Content explorer is designed to browse and investigate classified content by location and label or information type. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
C: Purview DLP policies can target supported locations such as Exchange, SharePoint, OneDrive, Teams, Power BI, and Microsoft 365 Copilot as required by the policy design. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
D: DLP reporting and activity data help analysts see repeated matches and affected locations beyond a single alert. That capability can be valid in its own scenario, but it does not most directly satisfy the requirement stated here.
E: Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views. It directly addresses the stated requirement.
Learning point: MS102-T20-Q025: Use label reports for aggregate label adoption trends – Label reports provide aggregate monitoring that complements item-level Content explorer and event-level Activity explorer views.
Popular posts
Recent Posts
