MS-102 Microsoft 365 Administrator Expert Configuring Information Protection 2 — Questions and Answers
Question 1: An administrator needs to prevent users from sending emails containing credit card numbers to external recipients. Which Microsoft 365 feature should be configured?
- Azure Information Protection scanner
- Data Loss Prevention policy (Correct answer)
- Microsoft Defender for Cloud Apps policy
- Communication compliance policy
Correct answer: Data Loss Prevention policy
Data Loss Prevention (DLP) policies detect and block sensitive information like credit card numbers from being shared externally via email.
Question 2: A company wants to classify documents as 'Confidential' and automatically apply a watermark when they are opened. Which component of Microsoft Purview handles this?
- Retention labels
- Sensitivity labels (Correct answer)
- eDiscovery holds
- Insider risk policies
Correct answer: Sensitivity labels
Sensitivity labels in Microsoft Purview can apply visual markings such as watermarks, headers, and footers to classified documents.
Question 3: Which Microsoft Purview feature allows administrators to automatically move emails older than 2 years to an archive mailbox?
- Retention policies (Correct answer)
- DLP policies
- Sensitivity labels
- Information barriers
Correct answer: Retention policies
Retention policies in Microsoft Purview can automatically move content to archive storage or delete it after a specified period.
Question 4: A user attempts to share a file labeled 'Highly Confidential' via SharePoint with an external guest. The sensitivity label blocks this action. What label setting enforces this restriction?
- Content marking
- Auto-labeling
- Encryption with access restrictions
- External sharing controls embedded in the label (Correct answer)
Correct answer: External sharing controls embedded in the label
Sensitivity labels can include site and group settings that restrict external sharing for SharePoint sites hosting labeled content.
Question 5: Which PowerShell module is used to manage Microsoft Purview sensitivity labels and DLP policies?
- MSOnline
- AzureAD
- ExchangeOnlineManagement (Security & Compliance cmdlets) (Correct answer)
- MicrosoftTeams
Correct answer: ExchangeOnlineManagement (Security & Compliance cmdlets)
The Security & Compliance PowerShell cmdlets, accessed via the ExchangeOnlineManagement module, are used to manage Purview sensitivity labels and DLP policies.
Question 6: An organization wants to ensure that documents labeled 'Internal Only' cannot be opened by users outside the Azure AD tenant, even if the file is emailed externally. Which label configuration achieves this?
- Apply a header marking to the document
- Configure label encryption using Azure Rights Management with tenant-only permissions (Correct answer)
- Enable auto-labeling based on content
- Set label priority to highest
Correct answer: Configure label encryption using Azure Rights Management with tenant-only permissions
Applying Azure Rights Management encryption restricted to the tenant ensures only users within the organization can decrypt and open the file.
Question 7: A compliance administrator needs to review all Teams messages that contain the phrase 'confidential project.' Which Microsoft Purview solution is best suited?
- eDiscovery (Premium)
- Communication compliance (Correct answer)
- Insider risk management
- Audit log search
Correct answer: Communication compliance
Communication compliance policies in Microsoft Purview scan Teams, Exchange, and other channels for specified keywords and flag matching content for review.
An administrator needs to prevent users from sending emails containing credit card numbers to external recipients.
Which Microsoft 365 feature should be configured?