nerdexam
Microsoft

SC-401 · Question #124

SIMULATION Username and password Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password…

The correct answer is A. Insider Risk Management G. Data Loss Prevention. Creating a Data Loss Prevention (DLP) policy is the direct action to identify and protect content containing specific keywords, which also provides critical signals for Insider Risk Management to monitor potential insider threats.

Implement data loss prevention and retention

Question

SIMULATION Username and password Use the following login credentials as needed:

To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username:

[email protected] Microsoft 365 Password: XXXXXXXXX If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://admin microsoft.com”, and press Enter. The following information is for technical support purposes only:

Lab Instance: XXXXXXXX. Task 9 You plan to create a data loss prevention (DLP) policy that will apply to content containing the following keywords:

  • Tailspin
  • Litware
  • Falcon

You need to create a keyword list that can be used in the DLP policy. Answer:

To create a sensitive information type that matches all words in a keyword list, you can use the "All" condition instead of the default "Any" condition. Here are the steps to create such a sensitive information type:

Step 1: Go to the Microsoft 365 compliance center and navigate to the "Sensitive information types" page. Step 2: Click on "Create a sensitive information type". Step 3: Choose "Keyword dictionary" as the type of sensitive information you want to create. Step 4: Enter a name and description for the sensitive information type. Step 5: In the "Keywords" section, enter all the words you want to match separated by com-mas. Here we enter: Tailspin, Litware, Falcon Step 6: Click on "Add condition" and choose "Any" as the condition type. Step 7: Click on "Create" to create the sensitive information type. Step 8: Click on "Create" to create the sensitive information type. With this configuration, the DLP policy will only detect the sensitive information if any the words in the keyword list are present in the content being scanned. Reference:

https://learn.microsoft.com/en-us/answers/questions/1419105/how-to-create-sensitive- information-types-to-match

Options

  • AInsider Risk Management
  • BInformation Protection
  • CCompliance Manager
  • DDSPM for AI
  • EInformation Barriers
  • FData Lifecycle Management
  • GData Loss Prevention

How the community answered

(51 responses)
  • A
    75% (38)
  • B
    14% (7)
  • C
    2% (1)
  • D
    4% (2)
  • E
    6% (3)

Why each option

Creating a Data Loss Prevention (DLP) policy is the direct action to identify and protect content containing specific keywords, which also provides critical signals for Insider Risk Management to monitor potential insider threats.

AInsider Risk ManagementCorrect

Insider Risk Management uses signals, including those from DLP policies, to identify and act on risky activities by internal users, such as unauthorized access or sharing of sensitive company information like content containing specific keywords.

BInformation Protection

Information Protection is a broad category that includes sensitivity labels and data loss prevention, but it is not the specific service for creating the policy itself.

CCompliance Manager

Compliance Manager helps manage and assess compliance, but it is not the service for creating DLP policies.

DDSPM for AI

DSPM for AI (Data Security Posture Management for AI) is a specialized tool for AI data, not general DLP.

EInformation Barriers

Information Barriers are used to prevent communication between specific groups of users, not for detecting keywords in general content.

FData Lifecycle Management

Data Lifecycle Management focuses on retention and deletion policies, not on preventing loss of sensitive data.

GData Loss PreventionCorrect

Data Loss Prevention (DLP) is the direct service used to create policies that detect, monitor, and protect sensitive information (such as content containing specific keywords like Tailspin and Litware) from being shared inappropriately.

Concept tested: Data Loss Prevention and Insider Risk Management integration

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp?view=o365-worldwide

Topics

#Data Loss Prevention#Sensitive Information Types#Keyword Dictionaries

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice