MS-100 Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: Under the EU-U.S. Data Privacy Framework, what must a US organization do before transferring personal data from the EU?
- Sign Standard Contractual Clauses with each EU data subject
- Self-certify with the US Department of Commerce under the framework (Correct answer)
- Obtain explicit consent from each EU data subject individually
- Apply GDPR sensitivity labels to all transferred data
Correct answer: Self-certify with the US Department of Commerce under the framework
US organizations must self-certify their adherence to the EU-U.S. Data Privacy Framework principles with the US Department of Commerce to lawfully receive EU personal data.
Question 2: Which Microsoft Purview feature allows an organization to declare a document as an immutable record that cannot be edited or deleted before a specified retention period expires?
- Retention labels configured as regulatory records (Correct answer)
- Litigation Hold on the document library
- DLP policy blocking delete operations
- Sensitivity label with Do Not Forward restriction
Correct answer: Retention labels configured as regulatory records
Retention labels configured as 'regulatory record' declare content immutable, preventing editing and deletion until the retention period ends, satisfying strict records management requirements.
Question 3: An organization's legal team needs to review only Teams messages containing the phrase 'off the record' for potential compliance violations. Which tool provides this targeted review capability?
- eDiscovery keyword search exported to review set
- Communication Compliance policy with custom keyword condition (Correct answer)
- Audit log search filtered by Teams message activity
- Insider Risk Management content explorer
Correct answer: Communication Compliance policy with custom keyword condition
Communication Compliance policies can target specific keywords like 'off the record' in Teams messages and route matching content to reviewers for investigation.
Question 4: A multinational company must comply with Brazil's LGPD data protection law. Which Microsoft Purview capability helps discover where Brazilian citizen data is stored across Microsoft 365?
- Compliance Manager LGPD assessment only
- Content Search with sensitive information types for Brazilian data (Correct answer)
- Azure AD user attribute reports
- Microsoft Defender for Cloud Apps OAuth app inventory
Correct answer: Content Search with sensitive information types for Brazilian data
Content Search using Brazil-specific sensitive information types (like CPF numbers) identifies where Brazilian personal data resides across Exchange, SharePoint, and Teams.
Question 5: Which Microsoft 365 feature generates a Customer Lockbox request when Microsoft support engineers need to access customer content to resolve a service issue?
- Privileged Access Management approval workflow
- Customer Lockbox in the Microsoft 365 admin center (Correct answer)
- eDiscovery case access controls
- Azure AD Privileged Identity Management
Correct answer: Customer Lockbox in the Microsoft 365 admin center
Customer Lockbox requires explicit customer approval before Microsoft support engineers can access Exchange Online, SharePoint Online, or Teams content during support operations.
Question 6: An organization must demonstrate that no single administrator can independently approve their own privileged access to sensitive Exchange Online tasks. Which feature enforces this four-eyes principle?
- Conditional Access policy requiring MFA for admin roles
- Privileged Access Management with approval workflow (Correct answer)
- Azure AD Privileged Identity Management just-in-time access
- Information Barriers preventing admin self-approval
Correct answer: Privileged Access Management with approval workflow
Privileged Access Management in Microsoft 365 requires a separate approver to authorize privileged tasks in Exchange Online, enforcing segregation of duties.
Question 7: Which Microsoft Purview compliance feature uses machine learning to identify documents that look like resumes, financial statements, or source code—without requiring keyword lists or regex patterns?
- Built-in sensitive information types
- Trainable classifiers (Correct answer)
- Exact Data Match (EDM)
- Named entity recognition
Correct answer: Trainable classifiers
Trainable classifiers use machine learning models trained on sample content to recognize document categories by context and structure rather than specific patterns.
Under the EU-U.S.
Data Privacy Framework, what must a US organization do before transferring personal data from the EU?