nerdexam
Microsoft

MS-102 · Question #32

You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Purview policies to meet the following requirements: - Identify documents that are stored in Microsoft Teams and SharePoint…

The correct answer is A. a data loss prevention (DLP) policy. To identify and report on Personally Identifiable Information (PII) within documents stored in Microsoft Teams and SharePoint, a data loss prevention (DLP) policy is the appropriate solution.

Submitted by noor.lb· Apr 18, 2026Manage compliance by using Microsoft Purview

Question

You have a Microsoft 365 E5 subscription. You plan to implement Microsoft Purview policies to meet the following requirements:

  • Identify documents that are stored in Microsoft Teams and SharePoint

that contain Personally Identifiable Information (PII).

  • Report on shared documents that contain PII.

What should you create?

Options

  • Aa data loss prevention (DLP) policy
  • Ba retention policy
  • Can alert policy
  • Da Microsoft Defender for Cloud Apps policy

How the community answered

(38 responses)
  • A
    92% (35)
  • B
    3% (1)
  • D
    5% (2)

Why each option

To identify and report on Personally Identifiable Information (PII) within documents stored in Microsoft Teams and SharePoint, a data loss prevention (DLP) policy is the appropriate solution.

Aa data loss prevention (DLP) policyCorrect

A data loss prevention (DLP) policy is specifically designed to identify sensitive information, such as PII, in locations like Microsoft Teams and SharePoint, and can be configured to report on shared documents containing such data.

Ba retention policy

A retention policy focuses on retaining or deleting content for compliance, not primarily on identifying sensitive information like PII or reporting on its sharing.

Can alert policy

An alert policy generates alerts based on detected activities but doesn't inherently define what sensitive information to detect or how to handle it; DLP policies trigger such alerts for data loss.

Da Microsoft Defender for Cloud Apps policy

A Microsoft Defender for Cloud Apps policy (MCAS) primarily focuses on monitoring and controlling access to cloud apps, identifying Shadow IT, and detecting anomalous behavior, rather than directly identifying PII within documents in Microsoft 365 services for data loss prevention purposes.

Concept tested: Microsoft Purview Data Loss Prevention (DLP)

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#Data Loss Prevention (DLP)#Microsoft Purview#PII protection#Sensitive Information Types

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice