MS-102 Microsoft 365 Administrator Expert Implementing Data Loss Prevention 3 — Questions and Answers
Question 1: Which role is required to create and manage DLP policies in the Microsoft Purview compliance portal?
- DLP Compliance Management (Correct answer)
- Security Reader
- Global Reader
- Compliance Data Administrator
Correct answer: DLP Compliance Management
The DLP Compliance Management role grants permissions to create, edit, and manage DLP policies in the Microsoft Purview compliance portal.
Question 2: A company must prevent users from printing documents labeled 'Highly Confidential' on unmanaged devices. Which DLP capability addresses this scenario?
- Endpoint DLP print restriction (Correct answer)
- Exchange transport rule
- SharePoint IRM
- Conditional Access policy
Correct answer: Endpoint DLP print restriction
Endpoint DLP can restrict print actions on managed Windows devices when sensitive content or specific sensitivity labels are detected.
Question 3: When configuring a DLP policy for Exchange Online, which action can you take against emails that contain sensitive information?
- Encrypt the message automatically (Correct answer)
- Delete the sender's mailbox
- Convert the email to a Teams message
- Archive the email to a hold mailbox
Correct answer: Encrypt the message automatically
DLP policies for Exchange can trigger automatic encryption of messages containing sensitive information to protect content in transit.
Question 4: What is the purpose of the 'confidence level' setting in a DLP sensitive information type rule?
- It sets the minimum pattern-match accuracy required to trigger the rule (Correct answer)
- It defines how many users must approve a match
- It controls the policy's enforcement priority
- It determines how long match evidence is retained
Correct answer: It sets the minimum pattern-match accuracy required to trigger the rule
The confidence level (Low, Medium, High) specifies the required accuracy of pattern matching before a sensitive information type is considered detected.
Question 5: A DLP policy targeting OneDrive must exclude files in a specific site collection used by the legal team. How should you configure this exclusion?
- Add the site URL to the policy's excluded locations (Correct answer)
- Remove OneDrive from the policy workloads entirely
- Create a separate policy with a higher priority for the legal team
- Apply a retention label to exclude legal team files
Correct answer: Add the site URL to the policy's excluded locations
DLP policies allow specific SharePoint site URLs or OneDrive accounts to be excluded from the policy scope without disabling the workload.
Question 6: Which report in the Microsoft Purview compliance portal shows the number of DLP policy matches over time across all workloads?
- DLP policy matches report (Correct answer)
- Content explorer
- Activity explorer
- Audit log search
Correct answer: DLP policy matches report
The DLP policy matches report provides a trend view of how many times DLP rules matched content across Exchange, SharePoint, OneDrive, and Teams.
Question 7: You need to ensure DLP policies are applied to content in Microsoft Teams private channels. Which configuration step is required?
- Include Teams channel messages in the DLP policy locations (Correct answer)
- Enable Teams DLP via PowerShell only
- Apply a sensitivity label to the private channel
- Configure a Teams compliance policy separately
Correct answer: Include Teams channel messages in the DLP policy locations
To protect Teams private channel messages, you must explicitly select 'Teams channel messages and chats' as a location when creating or editing the DLP policy.
Which role is required to create and manage DLP policies in the Microsoft Purview compliance portal?