nerdexam
Microsoft

MS-102 · Question #298

You have a Microsoft 365 E5 tenant. You create an auto-labeling policy to encrypt emails that contain a sensitive info type. You specify the locations where the policy will be applied. You need to…

The correct answer is A. Run the policy in simulation mode. The first step to deploy an auto-labeling policy is to run it in simulation mode to evaluate its impact and accuracy.

Submitted by kim_seoul· Apr 18, 2026Manage compliance by using Microsoft Purview

Question

You have a Microsoft 365 E5 tenant. You create an auto-labeling policy to encrypt emails that contain a sensitive info type. You specify the locations where the policy will be applied. You need to deploy the policy. What should you do first?

Options

  • ARun the policy in simulation mode.
  • BTurn on co-authoring for files with sensitivity labels.
  • CReview the sensitive information in Activity explorer.
  • DTurn on the policy.

How the community answered

(21 responses)
  • A
    90% (19)
  • B
    5% (1)
  • C
    5% (1)

Why each option

The first step to deploy an auto-labeling policy is to run it in simulation mode to evaluate its impact and accuracy.

ARun the policy in simulation mode.Correct

Before turning on an auto-labeling policy, especially one that encrypts emails, it is crucial to run it in simulation mode first. This allows you to evaluate the policy's impact, identify potential false positives, and ensure it correctly identifies and encrypts the intended content without disrupting user workflows.

BTurn on co-authoring for files with sensitivity labels.

Turning on co-authoring for files with sensitivity labels is a separate configuration related to document collaboration, not a prerequisite for deploying an auto-labeling policy for emails.

CReview the sensitive information in Activity explorer.

Reviewing sensitive information in Activity explorer might be part of an investigation or monitoring, but it is not the required first step for deploying a new auto-labeling policy; simulation mode is specifically designed for pre-deployment testing.

DTurn on the policy.

Turning on the policy immediately without prior testing in simulation mode is risky, as it could lead to unintended encryption or data access issues, especially for a policy with significant impact like email encryption.

Concept tested: Auto-labeling policy deployment best practices

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/auto-apply-sensitivity-labels?view=o365-worldwide#run-the-policy-in-simulation-mode

Topics

#Auto-labeling policies#Data Loss Prevention (DLP)#Email encryption#Simulation mode

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice