nerdexam
Microsoft

SC-100 · Question #261

You have a Microsoft 365 tenant that uses Microsoft SharePoint Online and Microsoft Purview. Microsoft Purview has a sensitivity label named Label1 that is applied to the files stored on SharePoint…

The correct answer is A. Devices. Applying the DLP policy to the Devices location enables Endpoint DLP, which runs on the user's Windows device and monitors file activity at the OS and browser level. Endpoint DLP can detect when a user attempts to upload a file (identified by Label1) via a browser or app, then…

Design security operations, identity, and compliance capabilities

Question

You have a Microsoft 365 tenant that uses Microsoft SharePoint Online and Microsoft Purview. Microsoft Purview has a sensitivity label named Label1 that is applied to the files stored on SharePoint Online sites. You need to recommend a Microsoft Purview Data Loss Prevention (DLP) policy that meets the following requirements:

  • Prevents users from uploading the files to third-party external

websites

  • Allows users to upload the files to Microsoft OneDrive for Business

To which location should you apply the DLP policy?

Options

  • ADevices
  • BOneDrive accounts
  • CSharePoint sites
  • DMicrosoft Defender for Cloud Apps

How the community answered

(47 responses)
  • A
    77% (36)
  • B
    6% (3)
  • C
    13% (6)
  • D
    4% (2)

Explanation

Applying the DLP policy to the Devices location enables Endpoint DLP, which runs on the user's Windows device and monitors file activity at the OS and browser level. Endpoint DLP can detect when a user attempts to upload a file (identified by Label1) via a browser or app, then enforce rules that block uploads to third-party external websites while explicitly allowing uploads to Microsoft OneDrive for Business. This granular allow/block control over upload destinations - differentiating between trusted Microsoft services and untrusted external sites - is unique to Endpoint DLP. OneDrive accounts (B) would apply policy to content already stored in OneDrive, not control where users upload files to. SharePoint sites (C) would protect content in SharePoint but not govern upload behavior on user devices to external sites. Microsoft Defender for Cloud Apps (D) can control cloud app sessions but does not provide the same per-destination upload control that Endpoint DLP does at the device level.

Topics

#Microsoft Purview#Data Loss Prevention (DLP)#Endpoint DLP#Sensitivity Labels

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice