MS-102 Microsoft 365 Administrator Expert Configuring Information Protection 5 — Questions and Answers
Question 1: An organization wants to protect sensitive documents shared via SharePoint so that only authenticated users from the tenant can access them, even via a shared link. Which label setting achieves this?
- Apply visual markings to the document
- Set label encryption with permissions limited to the organization's domain (Correct answer)
- Configure a DLP policy to block anonymous links
- Enable sensitivity label for containers (sites and groups)
Correct answer: Set label encryption with permissions limited to the organization's domain
Configuring encryption on the sensitivity label restricted to the organization's domain ensures that only authenticated internal users can open the document regardless of the sharing method.
Question 2: A Microsoft 365 administrator reviews a DLP alert and notices a user justified overriding a block by providing a business reason. Where is this justification stored?
- The Audit log in the Microsoft Purview compliance portal (Correct answer)
- The user's mailbox sent items
- Azure AD sign-in logs
- Microsoft Defender Incidents queue
Correct answer: The Audit log in the Microsoft Purview compliance portal
User override justifications for DLP policy matches are recorded as audit events in the Microsoft Purview Audit log.
Question 3: Which Microsoft Purview feature uses machine learning to detect unusual data exfiltration patterns, such as a user downloading and emailing large volumes of files before resignation?
- Communication compliance
- Insider risk management (Correct answer)
- Endpoint DLP
- Advanced eDiscovery
Correct answer: Insider risk management
Insider risk management uses machine learning and behavioral signals to detect potentially risky activity such as data theft around employee departure.
Question 4: A sensitivity label policy has a default label configured. What happens when a user creates a new blank Word document and saves it without selecting a label?
- The document is saved without any label
- The default label is automatically applied to the document (Correct answer)
- The user is prompted to select a label before saving
- The document is blocked from saving
Correct answer: The default label is automatically applied to the document
When a default label is configured in the label policy, it is automatically applied to new documents created by users covered by that policy.
Question 5: An administrator configures Exact Data Match (EDM) in Microsoft Purview. What is the primary benefit of EDM over standard sensitive information types?
- EDM uses regex for faster processing
- EDM matches against an organization's specific database of sensitive values rather than generic patterns (Correct answer)
- EDM applies sensitivity labels automatically
- EDM does not require any schema configuration
Correct answer: EDM matches against an organization's specific database of sensitive values rather than generic patterns
Exact Data Match allows organizations to define sensitive information types based on actual data in a custom database, reducing false positives compared to generic pattern-based types.
Question 6: A label with encryption is applied to a file shared via OneDrive. The encryption uses Azure Rights Management. If the Rights Management service is disabled for the tenant, what happens to the encrypted file?
- The file becomes unencrypted automatically
- Authorized users can no longer open or access the encrypted file (Correct answer)
- The file is deleted from OneDrive
- The label is removed and the file is saved in plaintext
Correct answer: Authorized users can no longer open or access the encrypted file
Azure Rights Management encryption requires the service to be active; if disabled, users cannot obtain the licenses needed to decrypt and open protected files.
Question 7: An administrator configures a retention label with 'Trigger retention based on an event.' Which scenario best represents an event-based retention use case?
- Retain all emails for 7 years from the date they are created
- Retain employee HR records for 5 years from the employee's termination date (Correct answer)
- Delete all files in a SharePoint library older than 3 years
- Archive all Teams messages after 1 year
Correct answer: Retain employee HR records for 5 years from the employee's termination date
Event-based retention starts the retention clock when a specific business event occurs, such as employee termination, making it ideal for HR records tied to lifecycle events.
An organization wants to protect sensitive documents shared via SharePoint so that only authenticated users from the tenant can access them, even via a shared link.
Which label setting achieves this?