MS-102 Microsoft 365 Administrator Expert Configuring Information Protection 4 — Questions and Answers
Question 1: Endpoint DLP is deployed on Windows devices. Which prerequisite must be met for Endpoint DLP to function on a device?
- Microsoft Defender for Endpoint must be onboarded on the device (Correct answer)
- The device must run Windows 7 SP2 or later
- Azure AD Premium P1 license is sufficient
- The device must be joined to an on-premises Active Directory only
Correct answer: Microsoft Defender for Endpoint must be onboarded on the device
Endpoint DLP requires devices to be onboarded into Microsoft Defender for Endpoint, as it relies on that agent to monitor and enforce policies on the device.
Question 2: A sensitivity label is configured with 'Do Not Forward' protection. What does this prevent in Outlook?
- Recipients from replying to the email
- Recipients from forwarding, printing, or copying the email content (Correct answer)
- The email from being delivered to external recipients
- Attachments from being opened
Correct answer: Recipients from forwarding, printing, or copying the email content
'Do Not Forward' is an Azure Rights Management protection that prevents recipients from forwarding, printing, or copying the protected email.
Question 3: Which Microsoft Purview solution helps organizations calculate their compliance posture against frameworks like NIST and ISO 27001?
- Compliance Manager (Correct answer)
- eDiscovery
- Insider risk management
- Audit (Premium)
Correct answer: Compliance Manager
Microsoft Purview Compliance Manager provides a compliance score and improvement actions mapped to regulatory frameworks like NIST, ISO 27001, and GDPR.
Question 4: An administrator wants to apply a sensitivity label automatically to all Office documents containing the term 'Classified – Internal' in the header. Which configuration supports this scenario?
- Trainable classifier
- Exact data match (EDM)
- Auto-labeling policy with a keyword sensitive information type (Correct answer)
- Manual label recommendation
Correct answer: Auto-labeling policy with a keyword sensitive information type
An auto-labeling policy using a custom keyword as a sensitive information type will automatically classify documents containing that specific term.
Question 5: A Microsoft 365 administrator needs to place a legal hold on all mailbox content for a specific user involved in litigation. Which feature is used?
- Retention label with delete action
- eDiscovery hold (litigation hold) (Correct answer)
- DLP policy with block action
- Sensitivity label with encryption
Correct answer: eDiscovery hold (litigation hold)
An eDiscovery hold (or litigation hold) preserves all mailbox content for a user, preventing deletion regardless of user or retention policy actions.
Question 6: When configuring a DLP policy, an administrator sets the 'instance count' minimum to 5 for credit card numbers. What does this mean?
- The policy applies only when at least 5 DLP policies match the same content
- The policy triggers only when 5 or more distinct credit card numbers are found in a single item (Correct answer)
- The policy blocks content after 5 user overrides
- The policy requires 5 approvals before activation
Correct answer: The policy triggers only when 5 or more distinct credit card numbers are found in a single item
The instance count threshold specifies the minimum number of sensitive information type occurrences in an item before the DLP rule triggers.
Question 7: Which feature in Microsoft Purview allows administrators to see how a sensitivity label was applied to a document — whether manually, by default, or automatically?
- Content explorer
- Activity explorer (Correct answer)
- eDiscovery search
- Audit log
Correct answer: Activity explorer
Activity explorer in Microsoft Purview shows label activity events including how and when a label was applied, changed, or removed on content.
Endpoint DLP is deployed on Windows devices.
Which prerequisite must be met for Endpoint DLP to function on a device?