MS-500 Information Protection & Governance 2 — Questions and Answers
Question 1: What is required before sensitivity labels can be applied by end users in Microsoft 365 Apps?
- Enabling DLP policies for Office apps
- Publishing the labels via a label policy to users or groups (Correct answer)
- Activating Azure Information Protection separately
- Configuring an Azure Key Vault for encryption keys
Correct answer: Publishing the labels via a label policy to users or groups
Sensitivity labels must be published through a label policy that targets specific users or groups before users can see and apply them in Microsoft 365 Apps.
Question 2: Which Microsoft Purview feature monitors employee communications for policy violations such as harassment or insider threats?
- eDiscovery
- Communication Compliance (Correct answer)
- Insider Risk Management
- Audit Logs
Correct answer: Communication Compliance
Communication Compliance analyzes emails, Teams messages, and other communications to detect policy violations including harassment, sensitive data leaks, and regulatory violations.
Question 3: An organization needs to identify all documents containing credit card numbers stored across Microsoft 365. Which capability should be used?
- Microsoft Defender for Cloud Apps
- Microsoft Purview Content Explorer (Correct answer)
- Azure Security Center
- Microsoft 365 Audit Log
Correct answer: Microsoft Purview Content Explorer
Content Explorer in Microsoft Purview shows all items across Microsoft 365 that contain sensitive information types such as credit card numbers.
Question 4: Which type of sensitive information type uses trainable classifiers rather than regex patterns to detect content?
- Built-in sensitive information types
- Exact Data Match (EDM) classifiers
- Trainable classifiers (Correct answer)
- Keyword dictionaries
Correct answer: Trainable classifiers
Trainable classifiers use machine learning models trained on sample content to identify categories of sensitive content that are difficult to define with regex patterns.
Question 5: What is the function of Exact Data Match (EDM) in Microsoft Purview DLP?
- Match documents using document fingerprinting
- Detect sensitive data that exactly matches records in a custom database (Correct answer)
- Classify emails based on user behavior
- Apply labels automatically based on file metadata
Correct answer: Detect sensitive data that exactly matches records in a custom database
EDM allows organizations to create custom sensitive information types that match exact data values from an organization's database, such as employee IDs or patient records.
Question 6: A label policy is configured to require users to justify downgrading a sensitivity label. What type of control is this?
- Automatic labeling
- Mandatory labeling
- Label justification for downgrade (Correct answer)
- Default label assignment
Correct answer: Label justification for downgrade
Label justification for downgrade requires users to provide a reason when removing or lowering a sensitivity label, creating an audit trail for label changes.
What is required before sensitivity labels can be applied by end users in Microsoft 365 Apps?