SC-900 Information Protection & Data Governance 5 — Questions and Answers
Question 1: What is the role of 'named entities' as a sensitive information type in Microsoft Purview?
- They match data to exact records in an employee database
- They detect personal information like names, medical terms, and addresses using AI-based models (Correct answer)
- They identify documents by matching their structural fingerprint
- They classify data based on keywords defined in a custom dictionary
Correct answer: They detect personal information like names, medical terms, and addresses using AI-based models
Named entities use pre-built AI models to detect personal information such as people's names, medical conditions, and physical addresses across content.
Question 2: A company must ensure that emails containing Social Security Numbers are never sent outside the organization. Which Microsoft Purview solution directly addresses this?
- Retention policies
- Communication compliance
- Data Loss Prevention (DLP) policies (Correct answer)
- Microsoft Purview Audit
Correct answer: Data Loss Prevention (DLP) policies
DLP policies can detect sensitive information types like Social Security Numbers and block or restrict sharing of that content outside the organization.
Question 3: In Microsoft Purview, what is the difference between 'auto-apply' retention labels and 'published' retention labels?
- Auto-apply labels are applied by users manually; published labels are applied automatically by the system
- Published labels are made available for users or admins to apply manually; auto-apply labels are applied automatically based on conditions (Correct answer)
- Auto-apply labels only work in Exchange; published labels work across all services
- Published labels can only be deleted by global admins; auto-apply labels can be deleted by users
Correct answer: Published labels are made available for users or admins to apply manually; auto-apply labels are applied automatically based on conditions
Published retention labels appear in apps for users or admins to manually apply, while auto-apply labels are configured with conditions and applied by the service automatically.
Question 4: Which Microsoft Purview feature provides a risk score for each user based on their activities, such as downloading large volumes of data before resigning?
- Communication compliance
- Insider risk management (Correct answer)
- Data Loss Prevention
- Compliance Manager
Correct answer: Insider risk management
Insider risk management assigns risk scores to users based on signals like unusual file downloads, access to sensitive data, or departure indicators like resignation emails.
Question 5: What is the Microsoft Purview 'Service Trust Portal' used for?
- Configuring DLP policies for Microsoft cloud services
- Accessing audit reports, compliance documentation, and trust information about Microsoft's cloud services (Correct answer)
- Managing sensitivity labels across Microsoft 365 tenants
- Monitoring the health of Microsoft Purview compliance tools
Correct answer: Accessing audit reports, compliance documentation, and trust information about Microsoft's cloud services
The Service Trust Portal provides access to Microsoft's audit reports, compliance certifications, and documentation about how Microsoft protects customer data.
Question 6: When a sensitivity label is configured with visual markings, where do these markings appear?
- Only in the file's metadata, not visible to users
- As headers, footers, or watermarks in Office documents and emails (Correct answer)
- Only in the compliance portal, not in documents
- As a colored border around the document in Windows Explorer
Correct answer: As headers, footers, or watermarks in Office documents and emails
Visual markings configured in sensitivity labels appear as headers, footers, or watermarks directly in Office documents and emails, making the classification visible to users.
Question 7: Which component of the Microsoft Purview compliance portal shows administrators a historical view of all labeling, DLP, and retention activities across the organization?
- Content Explorer
- Activity Explorer (Correct answer)
- Compliance Manager
- Audit log
Correct answer: Activity Explorer
Activity Explorer provides a timeline-based view of labeling activities, DLP policy matches, and other compliance events across the Microsoft 365 environment.
What is the role of 'named entities' as a sensitive information type in Microsoft Purview?