MS-102 Microsoft 365 Administrator Expert Implementing Data Loss Prevention 5 — Questions and Answers
Question 1: An organization needs to prevent external sharing of files containing health information only when confidence is high. Which DLP rule configuration achieves this?
- Set SIT confidence to High and action to block external sharing (Correct answer)
- Set SIT instance count to 1 and notify only
- Enable audit mode with high confidence
- Apply a retention policy to health information files
Correct answer: Set SIT confidence to High and action to block external sharing
Setting the sensitive information type confidence level to High and configuring a block action for external sharing ensures only high-confidence detections trigger enforcement.
Question 2: Which location must be included in a DLP policy to protect sensitive content shared in Microsoft Teams meetings and calls?
- Teams channel messages and chats (Correct answer)
- SharePoint sites
- Exchange email
- OneDrive accounts
Correct answer: Teams channel messages and chats
Teams meeting and call transcripts are protected by DLP when 'Teams channel messages and chats' is selected as a policy location.
Question 3: A user receives a policy tip when uploading a file to SharePoint but the file is not blocked. What DLP action is most likely configured?
- Notify users with policy tips only (Correct answer)
- Block with override allowed
- Block without override
- Quarantine the file
Correct answer: Notify users with policy tips only
The 'Notify users with policy tips' action displays a warning to the user but does not prevent the upload or sharing action.
Question 4: Which Microsoft Purview tool allows an administrator to view the sensitive content detected in a specific file without opening it from SharePoint?
- Content explorer (Correct answer)
- Activity explorer
- DLP policy matches report
- Audit log
Correct answer: Content explorer
Content explorer in Microsoft Purview lets administrators view files and emails that contain sensitive data classified by DLP and information protection policies.
Question 5: You must ensure that DLP policies apply to Windows 10/11 devices used by remote workers who are not always connected to the corporate network. Which feature supports offline DLP enforcement?
- Endpoint DLP with offline policy cache (Correct answer)
- Azure AD Conditional Access
- Microsoft Defender for Endpoint integration only
- VPN-based policy enforcement
Correct answer: Endpoint DLP with offline policy cache
Endpoint DLP caches policies locally on Windows devices, allowing enforcement to continue even when the device is offline or disconnected from the corporate network.
Question 6: An administrator wants to monitor DLP policy matches specifically for copy-to-clipboard actions on managed endpoints. Which tool provides this visibility?
- Activity explorer (Correct answer)
- Content explorer
- DLP alert dashboard
- Microsoft Defender portal
Correct answer: Activity explorer
Activity explorer records endpoint DLP activities including copy-to-clipboard events, allowing administrators to audit user actions involving sensitive content.
Question 7: Which DLP policy setting determines the order in which multiple DLP policies are evaluated when content matches rules in more than one policy?
- Policy priority (Correct answer)
- Rule severity
- Instance count
- Confidence threshold
Correct answer: Policy priority
Policy priority (order number) determines which DLP policy is evaluated first when content could match multiple policies; lower numbers indicate higher priority.
An organization needs to prevent external sharing of files containing health information only when confidence is high.
Which DLP rule configuration achieves this?