MS-203 - Microsoft 365 Messaging Data Loss Prevention Policies Questions and Answers — Questions and Answers
Question 1: An organization needs to prevent employees from emailing documents containing credit card numbers to external recipients. However, the policy must allow for legitimate business cases where a user can send the information after providing a reason. Which combination of actions should an administrator configure in the Data Loss Prevention (DLP) policy rule?
- Set the action to 'Restrict access' and enable 'User notifications'.
- Set the action to 'Audit only' and configure an 'Incident report'.
- Set the action to 'Restrict access' to block external users, and enable 'User overrides' with a business justification. (Correct answer)
- Set an 'Exception' for the finance department and set the action to 'Encrypt the message content'.
Correct answer: Set the action to 'Restrict access' to block external users, and enable 'User overrides' with a business justification.
To meet the requirement, the policy must first block the action ('Restrict access' for people outside the organization). Then, to allow for exceptions with a reason, the 'User overrides' option must be enabled, which can be configured to require a business justification. This combination blocks the action by default but gives users a way to proceed if necessary, while logging their reason for audit purposes.
Question 2: What is the primary function of a "Policy Tip" within a Microsoft 365 Data Loss Prevention (DLP) policy for Exchange Online?
- To automatically encrypt the email message before it is sent.
- To send a detailed incident report to the compliance administrator.
- To quarantine the message for review before delivery is attempted.
- To display a real-time notification to the sender in their Outlook client, warning them of a potential policy violation. (Correct answer)
Correct answer: To display a real-time notification to the sender in their Outlook client, warning them of a potential policy violation.
A Policy Tip is a notification that appears in Outlook and Outlook on the web while a user is composing an email. Its main purpose is to inform the sender that their message content appears to violate a DLP policy, allowing them to correct the issue before sending or, if configured, to override the policy.
Question 3: An administrator is creating a new Data Loss Prevention (DLP) policy to identify and protect Australian financial data, including bank account and tax file numbers. Which of the following components should the administrator use to define the specific patterns for this type of data?
- A transport rule
- A retention label
- Sensitive Information Types (SITs) (Correct answer)
- A communication compliance policy
Correct answer: Sensitive Information Types (SITs)
Sensitive Information Types (SITs) are pattern-based classifiers used to detect specific types of sensitive data. Microsoft provides over 300 built-in SITs for various countries and regulations, including specific types for Australian financial data. DLP policies use SITs as a condition to identify content that needs protection.
Question 4: A financial services company has a strict DLP policy that blocks any email containing a high volume of customer financial records from being sent externally. A user in the wealth management group needs to send an encrypted report to a pre-approved external auditor. How can an administrator modify the DLP policy to allow this specific scenario without weakening the overall policy?
- Add the auditor's domain to the organization's safe sender list.
- Disable the DLP rule temporarily whenever the user needs to send the report.
- Add an exception to the rule that allows the email if the message is encrypted. (Correct answer)
- Create a new, less restrictive DLP policy specifically for the wealth management group.
Correct answer: Add an exception to the rule that allows the email if the message is encrypted.
DLP rules can be configured with exceptions. A common and secure exception is to allow an action if the message is protected with encryption (rights management). This allows the specific business process to continue while ensuring the sensitive data remains protected. Disabling the rule or creating a separate, weaker policy is less secure, and the safe sender list does not override DLP policy blocks.
Question 5: An administrator is creating a unified Data Loss Prevention (DLP) policy. They need to ensure the policy applies to emails, files stored in personal cloud storage, and collaborative team chats. Which of the following locations must be selected in the policy scope?
- Exchange Online, on-premises file shares, and Skype for Business
- Exchange Online, Microsoft Entra ID, and Microsoft Teams
- Exchange Online, OneDrive for Business accounts, and Microsoft Teams chat and channel messages (Correct answer)
- SharePoint sites, Azure File Storage, and Exchange Online
Correct answer: Exchange Online, OneDrive for Business accounts, and Microsoft Teams chat and channel messages
Microsoft 365 DLP policies can be scoped to multiple locations. To cover emails, personal cloud storage, and team chats, the administrator must select Exchange Online, OneDrive for Business accounts, and Microsoft Teams chat and channel messages respectively.
Question 6: A messaging administrator wants to be automatically notified via email and receive a comprehensive summary whenever a user triggers a high-severity DLP rule by attempting to send a large number of Social Security Numbers. Which feature should be configured within the DLP policy rule to achieve this?
- Policy Tips
- User overrides
- Incident reports
- A mail flow rule with a 'Generate incident report' action (Correct answer)
Correct answer: A mail flow rule with a 'Generate incident report' action
The 'Incident reports' feature within a DLP policy rule is designed specifically for this purpose. It can be configured to send an email notification to specified administrators when a policy match occurs. The severity level (low, medium, high) can also be set, and the report will contain details about the incident.
An organization needs to prevent employees from emailing documents containing credit card numbers to external recipients.
However, the policy must allow for legitimate business cases where a user can send the information after providing a reason.
Which combination of actions should an administrator configure in the Data Loss Prevention (DLP) policy rule?