HOTSPOT
You have a Microsoft 365 subscription.
1.
You identify the following data loss prevention (DLP) requirements:
2.
Send notifications to users if they attempt to send attachments that contain EU social security numbers
3.
Prevent any email messages that contain credit card numbers from being sent outside your organization
4.
Block the external sharing of Microsoft OneDrive content that contains EU passport numbers
5.
Send administrators email alerts if any rule matches occur.
What is the minimum number of DLP policies and rules you must create to meet the requirements? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:
HOTSPOT
You have a Microsoft 365 E5 subscription that contains the users shown in the following table.
You need to delegate the following tasks:
1.
Create and manage data loss prevention (DLP) policies.
2.
Review classified content by using Content explorer.
The solution must use the principle of least privilege.
Which user should perform each task? To answer, drag the appropriate users to the correct tasks. Each user may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content.
NOTE: Each correct selection is worth one point.
Hot Area:
SIMULATION
You need to configure your organization to automatically quarantine all phishing email messages. To complete this task, sign in to the Microsoft 365 portal.
You need to create a case that prevents the members of a group named Operations from deleting email messages that contain the word IPO.
To complete this task, sign in to the Microsoft Office 365 admin center.
You need to ensure that each user can join up to five devices to Azure Active Directory (Azure AD).
To complete this task, sign in to the Microsoft Office 365 admin center.
You have a Microsoft 365 subscription.
You need to ensure that all users who are assigned the Exchange administrator role have multi-factor authentication (MFA) enabled by default.
What should you use to achieve the goal?
A. Security and Compliance permissions
B. Microsoft Azure Active Directory (Azure AD) Privileged Identity Management
C. Microsoft Azure AD group management
D. Microsoft Office 365 user management
You have a Microsoft 365 subscription.
You need to enable auditing for all Microsoft Exchange Online users.
What should you do?
A. From the Exchange admin center, create a journal rule
B. Run the Set-MailboxDatabase cmdlet
C. Run the Set-Mailbox cmdlet
D. From the Exchange admin center, create a mail flow message trace rule.
You have a Microsoft 365 subscription.
You create and run a content search from the Security and Compliance admin center.
You need to download the results of the content search.
What should you obtain first?
A. an export key
B. a password
C. a certificate
D. a pin
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft 365 subscription that contains 1,000 user mailboxes.
An administrator named Admin1 must be able to search for the name of a competing company in the mailbox of a user named User5.
You need to ensure that Admin1 can search the mailbox of User5 successfully. The solution must prevent Admin1 from sending email messages as User5.
Solution: You modify the permissions of the mailbox of User5, and then create an eDiscovery case.
Does this meet the goal?
A. Yes
B. No
An administrator plans to deploy several Azure Advanced Threat Protection (ATP) sensors.
You need to provide the administrator with the Azure information required to deploy the sensors.
What information should you provide?
A. an Azure Active Directory Authentication Library (ADAL) token
B. the public key
C. the access key
D. the URL of the Azure ATP admin center
You have an Azure Active Directory (Azure AD) tenant named contoso.com and a Microsoft 365 subscription.
All users in contoso.com use the Microsoft SharePoint Newsfeed.
You need to ensure that all the users use the Yammer.com service.
What should you do?
A. From the Yammer admin center, modify the Usage Policy settings
B. From the SharePoint admin center, modify the Enterprise Social Collaboration settings
C. From the SharePoint admin center, modify the Connected Services settings
D. From the Yammer admin center, modify the Configuration settings
You have a Microsoft 365 subscription that contains the users shown in the following table.
You enable self-service password reset for Group1 and configure security questions as the only authentication method for self-service password reset.
You need to identity which user must answer security questions to reset their password.
Which user should you identify?
A. User1
B. User2
C. User3
D. User4
You have a Microsoft 365 subscription that contains 50 devices- The devices are enrolled in Microsoft Endpomt Manager and have Microsoft Defender for Endpoint enabled.
You need to identify devices that have a pending offline scan.
What should you do?
A. From the Microsoft 365 Defender portal, review the Threat and Vulnerability Management dashboard.
B. From the Microsoft 365 Defender portal, review the Threat analytics dashboard
C. From the Microsoft Endpoint Manager admin center, review the Detected malware report
D. From the Microsoft Endpoint Manager admin center, review the Antivirus agent status report.
You have a Microsoft 365 subscription that contains a Microsoft 365 group named Group1. Group1 contains 100 users and has dynamic user membership.
All users have Windows 10 devices and use Microsoft SharePoint Online and Exchange Online.
You create a sensitivity label named Label and publish Label 1 as the default label for Group!.
You need to ensure that the users in Group1 must apply Label! to their email and documents.
Which two actions should you perform? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.
A. Install the Azure Information Protection unified labeling client on the Windows 10 devices.
B. From the Microsoft 365 Compliance center, modify the settings of the Label1 policy.
C. Install the Active Directory Rights Management Services (AD RMS) client on the Windows 10 devices.
D. From the Microsoft 365 Compliance center, create an auto-labeling policy.
E. From the Azure Active Directory admin center, set Membership type for Group1 to Assigned.
You have a Microsoft 365 E5 subscription.
You need to use Microsoft Defender for Cloud Apps to identify documents stored in Microsoft SharePoint Online that contain proprietary information.
What should you create in Defender for Cloud Apps?
A. an app connector and a file policy
B. an app connector and an app discovery policy
C. a data source and an app discovery policy
D. a data source and a file policy