nerdexam
Microsoft

SC-401 · Question #154

You are configuring a data loss prevention (DLP) policy to report when credit card data is found on a Microsoft Entra joined Windows device. You plan to use information from the policy to restrict…

The correct answer is B. an action. To restrict the ability to copy sensitive data to the clipboard using a DLP policy, you must configure a specific 'action' within the advanced DLP rule that directly controls endpoint activities.

Implement data loss prevention and retention

Question

You are configuring a data loss prevention (DLP) policy to report when credit card data is found on a Microsoft Entra joined Windows device. You plan to use information from the policy to restrict the ability to copy the sensitive data to the clipboard. What should you configure in the policy advanced DLP rule?

Options

  • Auser notifications
  • Ban action
  • Cuser overrides
  • Dthe incident report

How the community answered

(14 responses)
  • B
    79% (11)
  • C
    14% (2)
  • D
    7% (1)

Why each option

To restrict the ability to copy sensitive data to the clipboard using a DLP policy, you must configure a specific 'action' within the advanced DLP rule that directly controls endpoint activities.

Auser notifications

User notifications inform users about policy matches but do not enforce restrictions on data activities.

Ban actionCorrect

To restrict the ability to copy sensitive data to the clipboard, you must configure an 'action' within the advanced DLP rule. Endpoint DLP actions allow you to control specific user activities, such as blocking or auditing the copying of sensitive data to the clipboard on a Microsoft Entra joined Windows device.

Cuser overrides

User overrides provide a mechanism for users to bypass a restriction with justification, but they are not the setting used to define the restriction itself.

Dthe incident report

The incident report specifies how and to whom alerts about policy matches are sent, which is for auditing and alerting, not for restricting data activities.

Concept tested: Configuring DLP actions for endpoint data protection

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp-actions?view=o365-worldwide

Topics

#DLP policies#Endpoint DLP#DLP actions#Sensitive info types

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice