SC-401 · Question #210
You have a data loss prevention (DLP) policy that applies to the Devices location. The policy protects documents that contain United States passport numbers. Users report that they cannot upload…
The correct answer is A. Service domains. Endpoint DLP 'Service domains' (Cloud Service Domains) lets you create an explicit allowlist of websites where users are permitted to upload sensitive content that would otherwise be blocked by a DLP policy. By adding the travel management website's domain to the allowed list…
Question
You have a data loss prevention (DLP) policy that applies to the Devices location. The policy protects documents that contain United States passport numbers. Users report that they cannot upload documents to a travel management website because of the policy. You need to ensure that the users can upload the documents to the travel management website. The solution must prevent the protected content from being uploaded to other locations. Which Microsoft 365 Endpoint data loss prevention (Endpoint DLP) setting should you configure?
Options
- AService domains
- BUnallowed apps
- CUnallowed browsers
- DFile path exclusions
How the community answered
(36 responses)- A83% (30)
- B3% (1)
- C6% (2)
- D8% (3)
Explanation
Endpoint DLP 'Service domains' (Cloud Service Domains) lets you create an explicit allowlist of websites where users are permitted to upload sensitive content that would otherwise be blocked by a DLP policy. By adding the travel management website's domain to the allowed list, users can successfully upload their documents there while the DLP policy continues to block uploads to every other cloud destination. File path exclusions remove files from DLP scanning entirely, which would allow uploads everywhere - violating the requirement. Unallowed apps and unallowed browsers block by application or browser, not by destination website, so they cannot selectively permit a single site.
Topics
Community Discussion
No community discussion yet for this question.