Microsoft SC-401 Retention Labels Adaptive Scopes Policy Precedence And Recovery Practice Test

 

Skill 2.3 • 84 original questions

This Microsoft SC-401 practice test focuses on retention labels adaptive scopes policy precedence and recovery through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

City Power & Light is standardizing protection for employee files. The design must recover retained content in Microsoft 365, and operations wants to preserve least privilege. What should the information security administrator do? The design should not depend on users remembering an optional manual step. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The pilot starts with 123 users and expands only after the security team signs off.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: D

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 2

A security design workshop at Litware focuses on contract documents. One mandatory capability is to interpret the results of policy precedence including using Policy lookup. Which answer best aligns with Microsoft Purview while helping reduce false positives? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 160 protected items have been processed.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: D

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 3

Wide World Importers is standardizing protection for cloud application files. The design must create configure and manage adaptive policy scopes, and operations wants to support investigation evidence. What should the information security administrator do? The team wants the change to be reversible during pilot testing. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 197 protected items have been processed.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: D

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 4

For a new Microsoft 365 deployment at Fourth Coffee, the risk management team is responsible for customer records. They are required to create configure and manage adaptive policy scopes. Which implementation is correct if they also want to avoid unnecessary user disruption? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The initial scope covers 53 managed objects and must remain measurable during rollout.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Create an Insider Risk Management case for every user in scope.

Correct answer: C

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 5

During an audit at City Power & Light, reviewers ask how the tenant will create retention labels for data lifecycle management. The implementation should minimize administrative overhead. Which choice is most appropriate? The organization wants to avoid granting broader permissions than the task requires. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-6-005 and will be reviewed after the first week.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 6

The legal team at Wide World Importers has two competing proposals for customer records. Only one directly enables the tenant to create retention labels for data lifecycle management. Which proposal should be chosen to keep the design auditable? The control must work with the organization’s existing Microsoft 365 governance model. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-6-006 before widening scope.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: C

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 7

A Microsoft 365 administrator at A. Datum is asked to improve protection of support tickets. The success criterion is to plan for information retention and disposition by using retention labels. What should be done if the implementation must use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-6-007 before widening scope.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Create an Insider Risk Management case for every user in scope.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: B

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 8

The governance board at Wingtip Toys approves a control for SharePoint documents on the condition that administrators can configure a retention label policy to publish labels. What should the team do to keep the design auditable? The security lead wants the configuration to align with the supported Microsoft workflow. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The team has 20 historical events available for validation before enabling broader enforcement.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: B

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 9

During an audit at Alpine Ski House, reviewers ask how the tenant will configure a retention label policy to auto-apply labels. The implementation should minimize administrative overhead. Which choice is most appropriate? The organization wants to avoid granting broader permissions than the task requires. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The rollout plan requires a measurable checkpoint after 57 protected items have been processed.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: C

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 10

Fourth Coffee is replacing a manual process used by the sales team for contract documents. The replacement must recover retained content in Microsoft 365. Which choice provides the most direct implementation while helping keep policy behavior predictable? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. A support team will observe the first 94 policy evaluations to confirm expected behavior.

  1. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Create an Insider Risk Management case for every user in scope.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: A

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 11

A pilot at Blue Yonder Airlines involves email messages. The security lead asks for a configuration that will interpret the results of policy precedence including using Policy lookup. Which approach best satisfies the requirement and helps keep policy behavior predictable? The team must be able to explain why the selected control addresses the stated risk. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 131 representative samples before production enablement.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: B

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 12

A production issue at Adventure Works affects the handling of email messages. The root requirement is to create and configure retention policies. Which remediation best meets that requirement and helps keep policy behavior predictable? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The initial scope covers 168 managed objects and must remain measurable during rollout.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  3. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: C

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 13

The governance board at Tailspin Toys approves a control for cloud application files on the condition that administrators can configure a retention label policy to publish labels. What should the team do to minimize administrative overhead? The organization wants to avoid granting broader permissions than the task requires. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The change is tracked under control batch SC401-6-013 and will be reviewed after the first week.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Create an Insider Risk Management case for every user in scope.
  4. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: A

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 14

A production issue at City Power & Light affects the handling of regulated case records. The root requirement is to plan for information retention and disposition by using retention labels. Which remediation best meets that requirement and helps keep the design auditable? The requirement applies to production data rather than a one-time demonstration. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 61 historical events available for validation before enabling broader enforcement.

  1. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: E

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 15

Before enabling enforcement at A. Datum, administrators must demonstrate how they will create and configure retention policies for support tickets. Which configuration should they use to avoid changing unrelated workloads? The design should not depend on users remembering an optional manual step. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 98 representative samples before production enablement.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: A

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 16

Graphic Design Institute is standardizing protection for customer records. The design must recover retained content in Microsoft 365, and operations wants to support a phased rollout. What should the information security administrator do? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 135 protected items have been processed.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Create an Insider Risk Management case for every user in scope.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: C

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 17

The collaboration services team at Wide World Importers has two competing proposals for customer records. Only one directly enables the tenant to create and configure retention policies. Which proposal should be chosen to keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-6-017 before widening scope.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: E

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 18

A compliance exception at Wingtip Toys can be closed only after the tenant can recover retained content in Microsoft 365 for cloud application files. What should the administrator implement if the goal is to reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The change is tracked under control batch SC401-6-018 and will be reviewed after the first week.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: D

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 19

A pilot at Alpine Ski House involves financial workbooks. The security lead asks for a configuration that will configure a retention label policy to auto-apply labels. Which approach best satisfies the requirement and helps support investigation evidence? The control must work with the organization’s existing Microsoft 365 governance model. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-6-019 and will be reviewed after the first week.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Create an Insider Risk Management case for every user in scope.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: C

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 20

A pilot at Graphic Design Institute involves support tickets. The security lead asks for a configuration that will interpret the results of policy precedence including using Policy lookup. Which approach best satisfies the requirement and helps preserve least privilege? The implementation will be reviewed by both security and compliance stakeholders. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The control owner must document the result for governance record SC401-6-020 before widening scope.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: C

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 21

An incident review at Fabrikam shows that the current process for email messages is incomplete. The team now needs to interpret the results of policy precedence including using Policy lookup. Which action most directly addresses that need while helping keep the design auditable? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 139 users across two business units and must preserve normal collaboration.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: E

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 22

Before enabling enforcement at Wide World Importers, administrators must demonstrate how they will interpret the results of policy precedence including using Policy lookup for SharePoint documents. Which configuration should they use to keep policy behavior predictable? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The team has 176 historical events available for validation before enabling broader enforcement.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Create an Insider Risk Management case for every user in scope.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: D

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 23

At Margie’s Travel, a review of engineering designs found a gap. The administrator must recover retained content in Microsoft 365, while the project team wants to avoid changing unrelated workloads. What is the best next step? The control must work with the organization’s existing Microsoft 365 governance model. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 32 protected items have been processed.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: D

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 24

Before enabling enforcement at A. Datum, administrators must demonstrate how they will configure a retention label policy to auto-apply labels for employee files. Which configuration should they use to keep the design auditable? The pilot population is small today but the configuration must support a broader rollout. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 69 protected items have been processed.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: E

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 25

The governance board at Contoso approves a control for financial workbooks on the condition that administrators can configure a retention label policy to auto-apply labels. What should the team do to support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. Administrators must be able to tune the configuration later without redesigning the entire protection model. A support team will observe the first 106 policy evaluations to confirm expected behavior.

  1. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: D

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 26

Adventure Works’s sales team is updating controls for support tickets. The requirement is to plan for information retention and disposition by using retention labels. The solution must also keep the design auditable. Which action should the administrator take? The team wants the change to be reversible during pilot testing. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 143 protected items have been processed.

  1. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  2. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

B: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 27

An incident review at A. Datum shows that the current process for customer records is incomplete. The team now needs to create and configure retention policies. Which action most directly addresses that need while helping keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The team has 180 historical events available for validation before enabling broader enforcement.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: E

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 28

A proof of concept at Northwind Traders will be accepted only if it can configure a retention label policy to publish labels for SharePoint documents. The architect also wants to support a phased rollout. Which option should be selected? The team must be able to explain why the selected control addresses the stated risk. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 36 historical events available for validation before enabling broader enforcement.

  1. Create an Insider Risk Management case for every user in scope.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: E

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 29

At Fabrikam, a review of customer records found a gap. The administrator must interpret the results of policy precedence including using Policy lookup, while the project team wants to support a phased rollout. What is the best next step? The team must be able to explain why the selected control addresses the stated risk. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 73 users and expands only after the security team signs off.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: D

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 30

The engineering group at Proseware is preparing a production rollout involving financial workbooks. They specifically need to create configure and manage adaptive policy scopes. What should be configured first to reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 110 protected items have been processed.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: D

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 31

A security design workshop at Northwind Traders focuses on support tickets. One mandatory capability is to create and configure retention policies. Which answer best aligns with Microsoft Purview while helping use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 147 users across two business units and must preserve normal collaboration.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Create an Insider Risk Management case for every user in scope.
  5. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.

Correct answer: A

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 32

A production issue at Proseware affects the handling of email messages. The root requirement is to configure a retention label policy to auto-apply labels. Which remediation best meets that requirement and helps minimize administrative overhead? The organization wants to avoid granting broader permissions than the task requires. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The control owner must document the result for governance record SC401-6-032 before widening scope.

  1. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: A

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 33

A proof of concept at Trey Research will be accepted only if it can create retention labels for data lifecycle management for financial workbooks. The architect also wants to support investigation evidence. Which option should be selected? The security lead wants the configuration to align with the supported Microsoft workflow. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The design review compares outcomes for 40 representative samples before production enablement.

  1. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.

Correct answer: D

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

E: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 34

A change request from Proseware’s human resources department affects engineering designs. The stated objective is to configure a retention label policy to publish labels. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The design review compares outcomes for 77 representative samples before production enablement.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  3. Create an Insider Risk Management case for every user in scope.
  4. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  5. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.

Correct answer: D

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

E: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 35

Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will configure a retention label policy to auto-apply labels for customer records. Which configuration should they use to reduce false positives? Administrators need evidence they can review after deployment. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The initial scope covers 114 managed objects and must remain measurable during rollout.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: C

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 36

Northwind Traders is standardizing protection for cloud application files. The design must configure a retention label policy to publish labels, and operations wants to avoid unnecessary user disruption. What should the information security administrator do? Administrators need evidence they can review after deployment. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The pilot starts with 151 users and expands only after the security team signs off.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: E

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 37

A change request from Woodgrove Bank’s sales department affects employee files. The stated objective is to plan for information retention and disposition by using retention labels. Which administrative action is the strongest fit if the team must minimize administrative overhead? The implementation will be reviewed by both security and compliance stakeholders. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 188 protected items have been processed.

  1. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  2. Create an Insider Risk Management case for every user in scope.
  3. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: A

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 38

Wingtip Toys’s data governance team is updating controls for Teams collaboration content. The requirement is to create configure and manage adaptive policy scopes. The solution must also avoid changing unrelated workloads. Which action should the administrator take? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Only the users and workloads named in the requirement should be affected during the first production phase. The control owner must document the result for governance record SC401-6-038 before widening scope.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Correct answer: E

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 39

Following a policy review, Graphic Design Institute changes how email messages is governed. The new requirement is to configure a retention label policy to publish labels. Which action is the best fit and will help keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-6-039 before widening scope.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.

Correct answer: C

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 40

The governance board at Northwind Traders approves a control for SharePoint documents on the condition that administrators can configure a retention label policy to auto-apply labels. What should the team do to use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. Administrators must be able to tune the configuration later without redesigning the entire protection model. The implementation will be tested against 118 representative files or events before sign-off.

  1. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Create an Insider Risk Management case for every user in scope.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: B

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 41

Margie’s Travel’s engineering team is updating controls for support tickets. The requirement is to create retention labels for data lifecycle management. The solution must also support investigation evidence. Which action should the administrator take? The organization wants to avoid granting broader permissions than the task requires. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The control owner must document the result for governance record SC401-6-041 before widening scope.

  1. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: E

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 42

Following a policy review, Contoso changes how customer records is governed. The new requirement is to create configure and manage adaptive policy scopes. Which action is the best fit and will help support a phased rollout? The team must be able to explain why the selected control addresses the stated risk. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 192 users across two business units and must preserve normal collaboration.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: D

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 43

Following a policy review, Margie’s Travel changes how Teams collaboration content is governed. The new requirement is to plan for information retention and disposition by using retention labels. Which action is the best fit and will help avoid unnecessary user disruption? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The change is tracked under control batch SC401-6-043 and will be reviewed after the first week.

  1. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  2. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Create an Insider Risk Management case for every user in scope.
  5. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Correct answer: A

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

B: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

E: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 44

At Adventure Works, a review of Teams collaboration content found a gap. The administrator must create configure and manage adaptive policy scopes, while the project team wants to avoid unnecessary user disruption. What is the best next step? The team must be able to explain why the selected control addresses the stated risk. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-6-044 and will be reviewed after the first week.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: B

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 45

The data governance group at Tailspin Toys is preparing a production rollout involving financial workbooks. They specifically need to configure a retention label policy to auto-apply labels. What should be configured first to use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The first phase affects 122 users across two business units and must preserve normal collaboration.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: C

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 46

For a new Microsoft 365 deployment at Margie’s Travel, the research team is responsible for cloud application files. They are required to create and configure retention policies. Which implementation is correct if they also want to preserve least privilege? The organization wants to avoid granting broader permissions than the task requires. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. A support team will observe the first 159 policy evaluations to confirm expected behavior.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  3. Create an Insider Risk Management case for every user in scope.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: A

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

B: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 47

An incident review at Proseware shows that the current process for Teams collaboration content is incomplete. The team now needs to recover retained content in Microsoft 365. Which action most directly addresses that need while helping support a phased rollout? The team wants the change to be reversible during pilot testing. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-6-047 and will be reviewed after the first week.

  1. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: A

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 48

Proseware is standardizing protection for employee files. The design must recover retained content in Microsoft 365, and operations wants to minimize administrative overhead. What should the information security administrator do? The control must work with the organization’s existing Microsoft 365 governance model. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 52 policy evaluations to confirm expected behavior.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: D

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 49

During an audit at Contoso, reviewers ask how the tenant will configure a retention label policy to auto-apply labels. The implementation should avoid unnecessary user disruption. Which choice is most appropriate? The security lead wants the configuration to align with the supported Microsoft workflow. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Administrators must be able to tune the configuration later without redesigning the entire protection model. The implementation will be tested against 89 representative files or events before sign-off.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create an Insider Risk Management case for every user in scope.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.

Correct answer: B

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Question 50

For a new Microsoft 365 deployment at Woodgrove Bank, the legal team is responsible for SharePoint documents. They are required to create retention labels for data lifecycle management. Which implementation is correct if they also want to minimize administrative overhead? Administrators need evidence they can review after deployment. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The initial scope covers 126 managed objects and must remain measurable during rollout.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Use Microsoft Defender XDR device isolation as the standard response.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: C

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

D: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 51

A Microsoft 365 administrator at Fourth Coffee is asked to improve protection of regulated case records. The success criterion is to plan for information retention and disposition by using retention labels. What should be done if the implementation must support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 163 representative samples before production enablement.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: E

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 52

The governance board at A. Datum approves a control for financial workbooks on the condition that administrators can configure a retention label policy to publish labels. What should the team do to use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-6-052 and will be reviewed after the first week.

  1. Create an Insider Risk Management case for every user in scope.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: C

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

D: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 53

Tailspin Toys is replacing a manual process used by the finance team for customer records. The replacement must interpret the results of policy precedence including using Policy lookup. Which choice provides the most direct implementation while helping preserve least privilege? The requirement applies to production data rather than a one-time demonstration. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The change is tracked under control batch SC401-6-053 and will be reviewed after the first week.

  1. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: B

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 54

Northwind Traders is replacing a manual process used by the research team for contract documents. The replacement must interpret the results of policy precedence including using Policy lookup. Which choice provides the most direct implementation while helping avoid changing unrelated workloads? The organization wants to avoid granting broader permissions than the task requires. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 93 historical events available for validation before enabling broader enforcement.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: C

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 55

City Power & Light is standardizing protection for email messages. The design must create retention labels for data lifecycle management, and operations wants to use the narrowest effective control. What should the information security administrator do? The team must be able to explain why the selected control addresses the stated risk. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 130 protected items have been processed.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: A

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 56

Following a policy review, Woodgrove Bank changes how email messages is governed. The new requirement is to create retention labels for data lifecycle management. Which action is the best fit and will help preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The initial scope covers 167 managed objects and must remain measurable during rollout.

  1. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: D

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 57

Before enabling enforcement at Litware, administrators must demonstrate how they will plan for information retention and disposition by using retention labels for SharePoint documents. Which configuration should they use to support investigation evidence? The design should not depend on users remembering an optional manual step. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-6-057 and will be reviewed after the first week.

  1. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Correct answer: D

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

E: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 58

At Blue Yonder Airlines, a review of employee files found a gap. The administrator must create retention labels for data lifecycle management, while the project team wants to avoid changing unrelated workloads. What is the best next step? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 60 historical events available for validation before enabling broader enforcement.

  1. Create an Insider Risk Management case for every user in scope.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: C

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 59

For a new Microsoft 365 deployment at Humongous Insurance, the engineering team is responsible for employee files. They are required to interpret the results of policy precedence including using Policy lookup. Which implementation is correct if they also want to preserve least privilege? The design should not depend on users remembering an optional manual step. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 97 historical events available for validation before enabling broader enforcement.

  1. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: E

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 60

A change request from Graphic Design Institute’s data governance department affects support tickets. The stated objective is to create and configure retention policies. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The design review compares outcomes for 134 representative samples before production enablement.

  1. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  2. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  3. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.

Correct answer: A

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

B: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 61

The human resources team at A. Datum has two competing proposals for cloud application files. Only one directly enables the tenant to plan for information retention and disposition by using retention labels. Which proposal should be chosen to support a phased rollout? The team wants the change to be reversible during pilot testing. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The implementation will be tested against 171 representative files or events before sign-off.

  1. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.
  2. Create an Insider Risk Management case for every user in scope.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: E

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 62

Before enabling enforcement at Proseware, administrators must demonstrate how they will create configure and manage adaptive policy scopes for contract documents. Which configuration should they use to minimize administrative overhead? The implementation will be reviewed by both security and compliance stakeholders. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 27 protected items have been processed.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  3. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Use device conditions and endpoint actions to control egress paths such as removable media, printing, clipboard, network shares, or browser and cloud-service uploads according to the business requirement.

Correct answer: C

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced Endpoint DLP rules add device-specific conditions and restrictions so sensitive files remain governed after they reach a managed endpoint. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 63

The compliance group at Alpine Ski House is preparing a production rollout involving engineering designs. They specifically need to recover retained content in Microsoft 365. What should be configured first to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 64 representative files or events before sign-off.

  1. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  4. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  5. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Correct answer: E

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 64

For a new Microsoft 365 deployment at Northwind Traders, the human resources team is responsible for financial workbooks. They are required to create and configure retention policies. Which implementation is correct if they also want to keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. A support team will observe the first 101 policy evaluations to confirm expected behavior.

  1. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  2. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  3. Create an Insider Risk Management case for every user in scope.
  4. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: E

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 65

A change request from Contoso’s legal department affects email messages. The stated objective is to create and configure retention policies. Which administrative action is the strongest fit if the team must avoid changing unrelated workloads? The security lead wants the configuration to align with the supported Microsoft workflow. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Only the users and workloads named in the requirement should be affected during the first production phase. The control owner must document the result for governance record SC401-6-065 before widening scope.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: C

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 66

Following a policy review, City Power & Light changes how contract documents is governed. The new requirement is to create retention labels for data lifecycle management. Which action is the best fit and will help avoid changing unrelated workloads? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 175 users across two business units and must preserve normal collaboration.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  5. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Correct answer: B

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 67

Before enabling enforcement at Woodgrove Bank, administrators must demonstrate how they will configure a retention label policy to publish labels for contract documents. Which configuration should they use to support investigation evidence? The organization wants to avoid granting broader permissions than the task requires. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 31 policy evaluations to confirm expected behavior.

  1. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Create an Insider Risk Management case for every user in scope.
  4. Confirm supported and properly onboarded Windows or macOS devices, required licensing and client prerequisites, and deploy the supported browser extension where the protected browser scenario requires it.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: B

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

C: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

D: Endpoint DLP depends on supported onboarded devices and required client components; browser-specific controls can also require the supported extension. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 68

Fabrikam expects the volume of contract documents to increase significantly. The control must scale while allowing the team to plan for information retention and disposition by using retention labels. Which action best supports that objective and helps preserve least privilege? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The control owner must document the result for governance record SC401-6-068 before widening scope.

  1. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  2. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  3. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Use Microsoft Defender XDR device isolation as the standard response.

Correct answer: B

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

C: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 69

The sales group at Proseware is preparing a production rollout involving cloud application files. They specifically need to configure a retention label policy to publish labels. What should be configured first to minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-6-069 before widening scope.

  1. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  2. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  3. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  4. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: D

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 70

Margie’s Travel is replacing a manual process used by the human resources team for email messages. The replacement must configure a retention label policy to publish labels. Which choice provides the most direct implementation while helping support a phased rollout? The team wants the change to be reversible during pilot testing. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 142 historical events available for validation before enabling broader enforcement.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: A

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 71

A production issue at Consolidated Messenger affects the handling of contract documents. The root requirement is to create configure and manage adaptive policy scopes. Which remediation best meets that requirement and helps use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 179 users across two business units and must preserve normal collaboration.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Use Microsoft Defender XDR device isolation as the standard response.
  3. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  4. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: D

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

C: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 72

An incident review at Blue Yonder Airlines shows that the current process for Teams collaboration content is incomplete. The team now needs to configure a retention label policy to publish labels. Which action most directly addresses that need while helping avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 35 historical events available for validation before enabling broader enforcement.

  1. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Apply a sensitivity label manually to every existing file and stop using DLP.

Correct answer: B

Why: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

Option review:

A: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This directly matches the requirement in the scenario.

C: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

Learning point: Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Question 73

A compliance exception at Wide World Importers can be closed only after the tenant can recover retained content in Microsoft 365 for support tickets. What should the administrator implement if the goal is to preserve least privilege? The design should not depend on users remembering an optional manual step. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The pilot starts with 72 users and expands only after the security team signs off.

  1. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  2. Create an Insider Risk Management case for every user in scope.
  3. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  4. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.
  5. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Correct answer: C

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

D: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 74

Contoso is standardizing protection for contract documents. The design must create retention labels for data lifecycle management, and operations wants to minimize administrative overhead. What should the information security administrator do? The organization wants to avoid granting broader permissions than the task requires. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The design review compares outcomes for 109 representative samples before production enablement.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Create the DLP policy from a template or custom design, scope it to the required locations and users, validate it in simulation or test mode, then enable enforcement with alerts and user guidance as required.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: C

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

D: Testing before enforcement lets administrators measure matches and tune exceptions, while policy tips, alerts, and restrictions provide the intended production response. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 75

Humongous Insurance is standardizing protection for Teams collaboration content. The design must create and configure retention policies, and operations wants to use the narrowest effective control. What should the information security administrator do? The pilot population is small today but the configuration must support a broader rollout. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-6-075 and will be reviewed after the first week.

  1. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.
  2. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Apply a sensitivity label manually to every existing file and stop using DLP.
  5. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.

Correct answer: B

Why: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

Option review:

A: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This directly matches the requirement in the scenario.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

E: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.

Question 76

During an audit at Contoso, reviewers ask how the tenant will plan for information retention and disposition by using retention labels. The implementation should avoid changing unrelated workloads. Which choice is most appropriate? The team wants the change to be reversible during pilot testing. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The support team needs clear evidence of what matched, which control acted, and what the user experienced. A support team will observe the first 183 policy evaluations to confirm expected behavior.

  1. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  2. Create an Insider Risk Management case for every user in scope.
  3. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  4. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.
  5. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.

Correct answer: D

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

C: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

E: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 77

For a new Microsoft 365 deployment at City Power & Light, the compliance team is responsible for employee files. They are required to create configure and manage adaptive policy scopes. Which implementation is correct if they also want to preserve least privilege? The control must work with the organization’s existing Microsoft 365 governance model. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The rollout plan requires a measurable checkpoint after 39 protected items have been processed.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Use a retention policy for broad location-based retention or deletion, scope it to the required Microsoft 365 locations, and configure the retention duration and disposition behavior.
  3. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.
  4. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  5. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Correct answer: E

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: Retention policies apply at the location level and are appropriate when content in selected services should share a common retain or delete requirement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 78

Before enabling enforcement at Northwind Traders, administrators must demonstrate how they will create configure and manage adaptive policy scopes for financial workbooks. Which configuration should they use to keep the design auditable? Administrators need evidence they can review after deployment. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-6-078 and will be reviewed after the first week.

  1. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  2. Apply a sensitivity label manually to every existing file and stop using DLP.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Correct answer: A

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

B: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 79

During an audit at Margie’s Travel, reviewers ask how the tenant will create retention labels for data lifecycle management. The implementation should support investigation evidence. Which choice is most appropriate? The design should not depend on users remembering an optional manual step. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The first phase affects 113 users across two business units and must preserve normal collaboration.

  1. Create an Insider Risk Management case for every user in scope.
  2. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: C

Why: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

B: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This directly matches the requirement in the scenario.

D: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.

Question 80

Margie’s Travel expects the volume of engineering designs to increase significantly. The control must scale while allowing the team to create configure and manage adaptive policy scopes. Which action best supports that objective and helps keep the design auditable? The design should not depend on users remembering an optional manual step. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 150 users and expands only after the security team signs off.

  1. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  2. Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.
  3. Use Microsoft Defender XDR device isolation as the standard response.
  4. Assign the least-privileged Purview DLP role or role group required for policy administration or investigation rather than granting broad compliance or global administrator permissions.
  5. Create a Defender for Cloud Apps file policy that inspects connected-app files with the required DLP classification method and applies the appropriate alert or governance action.

Correct answer: B

Why: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive policy scopes recalculate membership from attributes, reducing the need to maintain static inclusion lists as people and sites change. This directly matches the requirement in the scenario.

C: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

D: DLP administration and investigation can be delegated through Purview role groups, which supports separation of duties and least privilege. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policies can continuously inspect supported cloud files using content and context conditions and can trigger alerts or governance actions when sensitive content is detected. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an adaptive scope whose query-based membership reflects the required users, groups, or sites so retention policies can follow changing organizational attributes automatically.

Question 81

A pilot at Consolidated Messenger involves SharePoint documents. The security lead asks for a configuration that will plan for information retention and disposition by using retention labels. Which approach best satisfies the requirement and helps reduce false positives? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. Only the users and workloads named in the requirement should be affected during the first production phase. The implementation will be tested against 187 representative files or events before sign-off.

  1. Apply a sensitivity label manually to every existing file and stop using DLP.
  2. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  3. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  4. Use Adaptive Protection so DLP enforcement can respond dynamically to a user’s current insider-risk level instead of applying the same restriction to every user.
  5. Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Correct answer: E

Why: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Option review:

A: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

B: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection connects insider-risk levels with DLP controls, enabling stronger or different actions for users whose current risk level meets the configured condition. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Retention labels provide item-level lifecycle controls and can support records, events, and disposition workflows that are more granular than a broad retention policy. This directly matches the requirement in the scenario.

Learning point: Use retention labels when retention or disposition must follow the item and may require event-based retention, record behavior, or disposition review rather than only location-wide retention.

Question 82

  1. Datum is replacing a manual process used by the collaboration services team for Teams collaboration content. The replacement must interpret the results of policy precedence including using Policy lookup. Which choice provides the most direct implementation while helping keep the design auditable? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. A support team will observe the first 43 policy evaluations to confirm expected behavior.
  2. Publish retention labels to the required locations and users with a retention label publishing policy when users or apps must be able to apply those labels.
  3. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  4. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  5. Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.
  6. Create an Insider Risk Management case for every user in scope.

Correct answer: D

Why: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

Option review:

A: A publishing policy makes selected retention labels available in the chosen locations without automatically labeling every matching item. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Retention outcomes can involve multiple policies and labels; Policy lookup helps administrators see applicable policies so the effective retention behavior can be explained. This directly matches the requirement in the scenario.

E: Insider Risk Management cases are investigation artifacts and do not implement the requested DLP or retention configuration.

Learning point: Use Policy lookup and the retention principles to identify which retention settings apply to a specific location or item when multiple retention policies and labels overlap.

Question 83

Before enabling enforcement at Fabrikam, administrators must demonstrate how they will recover retained content in Microsoft 365 for cloud application files. Which configuration should they use to keep policy behavior predictable? The team wants the change to be reversible during pilot testing. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The change is tracked under control batch SC401-6-083 and will be reviewed after the first week.

  1. Use Microsoft Defender XDR device isolation as the standard response.
  2. Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.
  3. Review both policy priority and rule order, then evaluate the effective result of all applicable matching controls instead of assuming the newest policy or rule automatically wins.
  4. Translate the business requirement into DLP locations, sensitive data conditions, users or groups, exceptions, actions, notifications, and rollout mode before building the policy.
  5. Enable Endpoint DLP just-in-time protection for the intended device scope so egress can be blocked while a new or stale file is being evaluated, and choose a carefully tested fallback action for classification failure.

Correct answer: B

Why: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

Option review:

A: Device isolation is an incident-response action and is not the correct mechanism for normal DLP or retention policy enforcement.

B: When retention applies, Microsoft 365 preserves content in service-specific hidden or recoverable locations so authorized administrators can retrieve the retained version as required. This directly matches the requirement in the scenario.

C: DLP behavior depends on how matching policies and rules are prioritized and combined; administrators should use the configured ordering and effective-action logic to explain the final result. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A good DLP design starts from the data, location, actors, allowed business process, exceptions, and desired response; these become the policy conditions and actions. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: JIT protection is designed to cover the evaluation gap by detecting and blocking egress on monitored files until policy evaluation completes; its fallback behavior should be staged to avoid unnecessary disruption. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Recover retained content from the service-specific preservation or recovery experience that holds the retained copy, instead of assuming a user-deleted item is permanently gone.

Question 84

A compliance exception at Blue Yonder Airlines can be closed only after the tenant can configure a retention label policy to auto-apply labels for regulated case records. What should the administrator implement if the goal is to reduce false positives? The requirement applies to production data rather than a one-time demonstration. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The design review compares outcomes for 117 representative samples before production enablement.

  1. Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.
  2. Create a retention label with the required retention period, trigger, action at the end of the period, and record or disposition behavior for the targeted content.
  3. Apply a sensitivity label manually to every existing file and stop using DLP.
  4. Use Purview Activity Explorer and Endpoint DLP diagnostics or alerts to review device events, policy matches, destinations, and enforcement outcomes, then tune policies from that telemetry.
  5. Configure tenant-level Endpoint DLP settings such as restricted apps, service domains, printer or device groups, browser behavior, and exclusions before relying on those settings in device-scoped DLP rules.

Correct answer: A

Why: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

Option review:

A: Auto-apply policies evaluate content against conditions and label matching items without requiring a user to choose the retention label. This directly matches the requirement in the scenario.

B: The retention label defines the item-level lifecycle, including how long content is retained and what happens when the retention period ends. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Sensitivity labels and DLP solve different problems; manual labeling does not replace the requested DLP or retention control.

D: Endpoint DLP generates activity telemetry that shows what users attempted, which rule matched, and what action occurred, providing the evidence needed for monitoring and policy tuning. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Endpoint settings define reusable groups, destinations, and exceptions that device-scoped DLP rules reference during enforcement. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an auto-apply retention label policy with the required content, metadata, sensitive-information, or classifier conditions when matching items should receive the label automatically.

Popular posts

img