Free SC-900 Microsoft Purview Data Loss Prevention Questions and Answers — Questions and Answers
Question 1: What is the primary goal of a Microsoft Purview Data Loss Prevention (DLP) policy?
- To encrypt all data at rest
- To prevent the unintentional sharing of sensitive information (Correct answer)
- To classify documents based on their content
- To detect and respond to malware attacks
Correct answer: To prevent the unintentional sharing of sensitive information
DLP policies are designed to identify, monitor, and automatically protect sensitive information across Microsoft 365 services. Their main purpose is to prevent the accidental or inappropriate sharing of this data with people who shouldn't have it, both inside and outside the organization.
Question 2: A DLP policy is configured to detect credit card numbers in emails. What component of the DLP policy identifies the pattern for a credit card number?
- A Sensitive Information Type (SIT) (Correct answer)
- A Retention Label
- A Conditional Access Policy
- An eDiscovery Case
Correct answer: A Sensitive Information Type (SIT)
Sensitive Information Types (SITs) are pattern-based classifiers that detect sensitive information like financial data, PII, and health information. DLP policies use SITs as a condition to identify content that needs to be protected.
Question 3: When creating a DLP policy, you must specify where it applies. Which of the following are valid locations for a DLP policy?
- Azure Virtual Machines only
- Azure Storage Accounts only
- Exchange Online, SharePoint Online, and Microsoft Teams (Correct answer)
- Azure Active Directory user profiles only
Correct answer: Exchange Online, SharePoint Online, and Microsoft Teams
DLP policies can be scoped to protect data across various Microsoft 365 services. This includes Exchange Online for emails, SharePoint Online and OneDrive for Business for files, and Microsoft Teams for chats and channel messages.
Question 4: A user tries to send an email containing sensitive data, and a 'policy tip' appears warning them of a potential policy violation. What part of the DLP policy is responsible for this?
- The policy location setting
- The sensitive information type
- The user notifications and policy tips setting (Correct answer)
- The incident report generation setting
Correct answer: The user notifications and policy tips setting
DLP policies consist of conditions, actions, and user notifications. Policy tips are a form of user notification designed to educate users about compliance policies in real-time and help them avoid violations before they happen.
Question 5: An administrator wants to implement a new DLP policy but wants to evaluate its impact before enforcing it. Which mode should they use?
- Turn it on right away
- Test it out with policy tips (Correct answer)
- Keep it off
- Delete the policy
Correct answer: Test it out with policy tips
DLP policies can be run in different modes. 'Test it out first' or 'Test it out with policy tips' allows the policy to run and generate audit logs and alerts without actually blocking any user actions, enabling administrators to fine-tune the policy before full enforcement.
Question 6: What is a key difference between a DLP policy and a sensitivity label?
- DLP policies apply encryption, while sensitivity labels do not.
- Sensitivity labels are for containers only, while DLP is for files.
- DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself. (Correct answer)
- There is no difference; they are two names for the same feature.
Correct answer: DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself.
While both are part of information protection, their focus is different. Sensitivity labels classify and apply persistent protection (like encryption) to the data itself, wherever it goes. DLP policies focus on the context of data sharing, preventing data exfiltration from specific locations like email or Teams based on rules.
What is the primary goal of a Microsoft Purview Data Loss Prevention (DLP) policy?