nerdexam
Microsoft

SC-401 · Question #13

You are planning a data loss prevention (DLP) solution that will apply to Windows Client computers. You need to ensure that when users attempt to copy a file that contains sensitive information to a…

The correct answer is B. one DLP policy that contains two DLP rules. You only need one DLP policy, but it requires two separate rules within that policy to handle the two different outcomes. Rule 1 targets members of Group1 and uses the 'Audit only' action - this allows the copy to proceed while logging an event. Rule 2 targets all other users…

Implement data loss prevention and retention

Question

You are planning a data loss prevention (DLP) solution that will apply to Windows Client computers. You need to ensure that when users attempt to copy a file that contains sensitive information to a USB storage device, the following requirements are met:

If the users are members of a group named Group1, the users must be allowed to copy the file, and an event must be recorded in the audit log. All other users must be blocked from copying the file. What should you create?

Options

  • Aone DLP policy that contains one DLP rule
  • Bone DLP policy that contains two DLP rules
  • Ctwo DLP policies that each contains one DLP rule

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    74% (17)
  • C
    17% (4)

Explanation

You only need one DLP policy, but it requires two separate rules within that policy to handle the two different outcomes. Rule 1 targets members of Group1 and uses the 'Audit only' action - this allows the copy to proceed while logging an event. Rule 2 targets all other users and uses the 'Block' action to prevent the file from being copied to USB. DLP rules within the same policy are evaluated in priority order; the Group1 rule should be ranked higher so it is matched first for Group1 members. One policy with one rule (A) cannot express two different actions for two different user groups. Two separate policies (C) would work but is unnecessarily complex and harder to manage.

Topics

#DLP Policy#DLP Rule#Endpoint DLP#Conditional Access

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice