MS-102 Microsoft 365 Administrator Expert Implementing Data Loss Prevention 2 — Questions and Answers
Question 1: A DLP policy is configured to detect credit card numbers in SharePoint. Users report legitimate business documents are being blocked. Which setting should you adjust to reduce false positives without disabling the policy?
- Increase the instance count threshold before triggering the policy (Correct answer)
- Remove the credit card sensitive information type entirely
- Set the policy to audit mode permanently
- Disable the policy for the SharePoint workload
Correct answer: Increase the instance count threshold before triggering the policy
Increasing the instance count threshold requires more occurrences of sensitive data before triggering a policy action, reducing false positives on documents with occasional credit card references.
Question 2: Which Microsoft 365 compliance feature allows you to test a DLP policy's impact before enforcing it in production?
- Simulation mode
- Audit mode (Correct answer)
- Block mode with override
- Enforce mode
Correct answer: Audit mode
Audit mode logs policy matches and generates alerts without blocking users, allowing administrators to assess impact before enforcement.
Question 3: You need to prevent users from sharing files containing SSNs via Teams chat but allow sharing within the same department. Which DLP condition should you configure?
- Content contains sensitive info type: U.S. Social Security Number
- Content is shared with people outside the organization (Correct answer)
- Sender domain is internal
- Recipient is not a member of a distribution group
Correct answer: Content is shared with people outside the organization
The 'Content is shared with people outside the organization' condition scopes the DLP rule to external sharing only, allowing internal departmental sharing to proceed.
Question 4: An administrator needs to allow a specific user to override a DLP block when sharing financial reports externally. Which action configuration enables this?
- Allow override with business justification (Correct answer)
- Exclude the user from the policy scope
- Set policy priority to low
- Create a sensitivity label exclusion
Correct answer: Allow override with business justification
Configuring 'Allow override with business justification' lets users bypass the DLP block by entering a reason, which is logged for auditing.
Question 5: Which endpoint DLP setting controls whether users can copy sensitive content detected on a managed device to a USB drive?
- Restricted app and browser group
- Unallowed removable storage device (Correct answer)
- Sensitive service domain restriction
- Endpoint DLP audit activity
Correct answer: Unallowed removable storage device
The 'Unallowed removable storage device' setting in endpoint DLP blocks or audits attempts to copy sensitive content to USB or other removable media.
Question 6: A DLP alert is triggered but no notification email was received by the compliance officer. Where in the Microsoft Purview compliance portal should you verify alert delivery configuration?
- DLP policy > Edit policy > Alerts (Correct answer)
- Compliance Manager > Assessments
- Information Protection > Labels
- Audit > Search
Correct answer: DLP policy > Edit policy > Alerts
Alert notification settings, including recipient email addresses, are configured within the DLP policy's Alerts section in the Microsoft Purview compliance portal.
Question 7: You want to apply different DLP rules based on whether a document's sensitivity label is 'Confidential' or 'Public'. Which DLP condition supports this?
- Content contains sensitivity label (Correct answer)
- Document property matches
- Content contains sensitive info type
- Sender has specific permissions
Correct answer: Content contains sensitivity label
The 'Content contains sensitivity label' condition allows DLP rules to be scoped based on labels applied by Microsoft Purview Information Protection.
A DLP policy is configured to detect credit card numbers in SharePoint.
Users report legitimate business documents are being blocked.
Which setting should you adjust to reduce false positives without disabling the policy?