nerdexam
MicrosoftMicrosoft

MS-102 · Question #398

MS-102 Question #398: Real Exam Question with Answer & Explanation

The correct answer is B: Turn on auditing.. Activity explorer in Microsoft Purview is populated by audit log data. If auditing is not enabled in the Microsoft 365 tenant, no events - including DLP rule matches - are recorded, so Activity explorer will have nothing to display. Turning on auditing (B) is therefore the prereq

Submitted by khalil_dz· Apr 18, 2026Manage compliance by using Microsoft Purview

Question

You have a new Microsoft 365 E5 subscription. You plan to use Activity explorer to monitor data loss prevention (DLP) rule activity. You need to ensure that Activity explorer contains data for analysis. What should you do first?

Options

  • AAdd a new alert policy.
  • BTurn on auditing.
  • CCreate a sensitivity label.
  • DCreate a new content search.

Explanation

Activity explorer in Microsoft Purview is populated by audit log data. If auditing is not enabled in the Microsoft 365 tenant, no events - including DLP rule matches - are recorded, so Activity explorer will have nothing to display. Turning on auditing (B) is therefore the prerequisite step before any DLP activity data can appear. Adding an alert policy (A) generates notifications but does not produce Activity explorer data. Creating a sensitivity label (C) or a content search (D) are unrelated to populating Activity explorer with DLP events.

Topics

#Activity Explorer#DLP#Auditing#Microsoft 365 Purview

Community Discussion

No community discussion yet for this question.

Full MS-102 PracticeBrowse All MS-102 Questions