nerdexam
Microsoft

SC-100 · Question #214

You have a Microsoft 365 subscription that contains 1,000 users. Each user is assigned a Microsoft 365 E5 license. The subscription uses sensitivity labels to classify corporate documents. All the…

The correct answer is B. Microsoft Purview data loss prevention (DLP). Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it can inspect files synced through OneDrive, detect sensitive content using sensitivity labels already applied to the documents, and enforce policies that block upload or sharing of those files to…

Design security solutions for applications and data

Question

You have a Microsoft 365 subscription that contains 1,000 users. Each user is assigned a Microsoft 365 E5 license. The subscription uses sensitivity labels to classify corporate documents. All the users have Windows 11 devices that are onboarded to Microsoft Defender for Endpoint and are configured to sync files to Microsoft OneDrive. You need to prevent the users from uploading the documents from OneDrive to external websites. What should you include in the solution?

Options

  • AMicrosoft Purview Information Protection
  • BMicrosoft Purview data loss prevention (DLP)
  • Cweb content filtering in Defender for Endpoint
  • Dan endpoint security policy

How the community answered

(47 responses)
  • A
    9% (4)
  • B
    72% (34)
  • C
    2% (1)
  • D
    17% (8)

Explanation

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it can inspect files synced through OneDrive, detect sensitive content using sensitivity labels already applied to the documents, and enforce policies that block upload or sharing of those files to external websites. DLP policies can target endpoints (Windows 11 devices onboarded to Defender for Endpoint) and apply actions such as block, audit, or warn when users attempt to upload labeled documents to unauthorized external destinations. Microsoft Purview Information Protection (A) handles classification and labeling but does not enforce exfiltration prevention by itself-DLP consumes the labels to enforce controls. Web content filtering in Defender for Endpoint (C) blocks access to website categories broadly but cannot target specific actions like document uploads based on content sensitivity. An endpoint security policy (D) is too broad and does not have content-aware upload blocking capability.

Topics

#Data Loss Prevention#Microsoft Purview#Endpoint DLP#OneDrive Security

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice