SC-401 · Question #20
You have a Microsoft 365 tenant. You have a database that stores customer details. Each customer has a unique 13-digit identifier that consists of a fixed pattern of numbers and letters. You need to…
The correct answer is B. a sensitive information type C. a DLP policy. The solution requires two components: a sensitive information type (B) and a DLP policy (C). First, you create a custom sensitive information type that matches the unique 13-digit alphanumeric pattern of your customer identifier - this teaches the DLP engine what to look for…
Question
You have a Microsoft 365 tenant. You have a database that stores customer details. Each customer has a unique 13-digit identifier that consists of a fixed pattern of numbers and letters. You need to implement a data loss prevention (DLP) solution that meets the following requirements:
- Email messages that contain a single customer identifier can be sent
outside your company.
- Email messages that contain two or more customer identifiers must be
approved by the company's data privacy team. Which two components should you include in the solution? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Options
- Aa sensitivity label
- Ba sensitive information type
- Ca DLP policy
- Da retention label
- Ea mail flow rule
How the community answered
(55 responses)- A5% (3)
- B73% (40)
- D16% (9)
- E5% (3)
Explanation
The solution requires two components: a sensitive information type (B) and a DLP policy (C). First, you create a custom sensitive information type that matches the unique 13-digit alphanumeric pattern of your customer identifier - this teaches the DLP engine what to look for. Then, you create a DLP policy with two rules: one that allows emails with a single instance of that identifier to be sent externally, and another that blocks or requires approval when two or more instances are detected. A sensitivity label (A) controls access but does not count occurrences. A retention label (D) manages data lifecycle, not transmission. A mail flow rule (E) alone cannot detect custom sensitive information types with instance-count thresholds the way DLP can.
Topics
Community Discussion
No community discussion yet for this question.