MS-100 Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: An organization subject to PCI DSS must prevent credit card numbers from being emailed externally. Which Microsoft 365 DLP action best satisfies this requirement?
- Apply sensitivity label to detected emails
- Block the email and notify the sender (Correct answer)
- Encrypt the email with S/MIME automatically
- Route the email to a compliance review queue
Correct answer: Block the email and notify the sender
A DLP policy action that blocks the email and sends a policy tip to the sender prevents cardholder data from leaving the organization via email.
Question 2: Under GDPR, what is the maximum fine for the most serious violations, such as failure to obtain valid consent for data processing?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 10% of global annual turnover
- £17.5 million or 4% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR Article 83(5) sets the maximum fine for the most serious violations at €20 million or 4% of the total worldwide annual turnover, whichever is higher.
Question 3: A company needs to place a legal hold on all content related to a lawsuit without alerting the custodians. Which Microsoft Purview feature supports this?
- Retention policy applied to all mailboxes
- eDiscovery hold applied silently to specific custodians (Correct answer)
- Litigation Hold on all mailboxes
- DLP policy with incident reports only
Correct answer: eDiscovery hold applied silently to specific custodians
eDiscovery holds can be scoped to specific custodians and data sources in a case without sending notifications, preserving evidence while maintaining confidentiality.
Question 4: Which Microsoft 365 compliance report shows which sensitivity labels are most applied to documents across SharePoint and OneDrive?
- Audit log filtered by label activity
- Label activity explorer in Microsoft Purview (Correct answer)
- Microsoft Secure Score improvement actions
- Compliance Manager assessment progress
Correct answer: Label activity explorer in Microsoft Purview
Activity Explorer in Microsoft Purview shows label application activity across Microsoft 365 services, including which labels are most frequently applied.
Question 5: An organization using Microsoft 365 E5 wants to automatically apply a retention label to all contracts stored in SharePoint. Which feature enables this without user intervention?
- Manually published retention labels
- Auto-apply retention labels based on sensitive info types or trainable classifiers (Correct answer)
- Records management file plan import
- Retention policies applied to the SharePoint site
Correct answer: Auto-apply retention labels based on sensitive info types or trainable classifiers
Auto-apply retention label policies scan content and automatically apply labels based on conditions like sensitive information types or trainable classifiers.
Question 6: Your organization must comply with ISO 27001 and wants to track control implementation progress in Microsoft 365. Which tool provides pre-built ISO 27001 controls and improvement actions?
- Microsoft Secure Score with ISO filters
- Compliance Manager with ISO 27001 assessment template (Correct answer)
- Azure Policy with ISO 27001 initiative
- Microsoft Defender for Cloud regulatory compliance
Correct answer: Compliance Manager with ISO 27001 assessment template
Compliance Manager includes a pre-built ISO 27001 assessment template that maps Microsoft managed controls and customer improvement actions to ISO requirements.
Question 7: A US federal agency requires that Microsoft 365 data residency be limited to US soil and that the environment meet DoD Impact Level 5. Which Microsoft 365 environment satisfies this?
- Microsoft 365 Government GCC
- Microsoft 365 Government GCC High with DoD tenant (Correct answer)
- Microsoft 365 E5 with Advanced Compliance add-on
- Microsoft 365 E5 Government
Correct answer: Microsoft 365 Government GCC High with DoD tenant
Microsoft 365 GCC High/DoD is specifically built for DoD Impact Level 4/5 data, with physically separated US-only infrastructure meeting DoD security requirements.
An organization subject to PCI DSS must prevent credit card numbers from being emailed externally.
Which Microsoft 365 DLP action best satisfies this requirement?