SC-401 · Question #241
SIMULATION Username and password Use the following login credentials as needed: To enter your username, place your cursor in the Sign in box and select the username below. To enter your password…
The correct answer is D. EnableMIPLabels G. Microsoft 365. Encrypting outbound email containing 'Falcon' in the subject via an RMS template requires enabling MIP labels (EnableMIPLabels) on a Microsoft 365 group type, which supports sensitivity label enforcement.
Question
SIMULATION Username and password Use the following login credentials as needed:
To enter your username, place your cursor in the Sign in box and select the username below. To enter your password, place your cursor in the Enter password box and select the password below. Microsoft 365 Username:
[email protected] Microsoft 365 Password: XXXXXXXXX If the Microsoft Edge browser or Microsoft 365 portal does not load successfully, select the Microsoft Edge browser icon from the task bar, type the URL “https://admin.microsoft.com”, and press Enter. The following information is for technical support purposes only:
Lab Instance: XXXXXXXXX Task 2 You need to ensure that email sent to external recipients with the word Falcon in the subject line will be encrypted by using an RMS template named Highly Confidential \ All Employees. Answer:
To encrypt emails with "Falcon" in the subject to external recipients, you must first create an Information Protection sensitivity label with RMS encryption, then create a mail flow rule in the Purview compliance portal that applies this label to emails that are sent externally and have "Falcon" in the subject line. Task 1: Set up the Information Protection sensitivity label Step 1: Go to the Microsoft Purview compliance portal and navigate to Information protection. Step 2: Open the Labels tab and click Create a label. Step 3: Follow the wizard to configure the new label. On the label settings page, enable Encrypt and then select the RMS template that you want to apply. Task 2: Create the mail flow rule Step 4: Go to the Purview compliance portal and navigate to Mail flow rules. Step 5: Click New rule. Step 6: Set the conditions:
Condition 1: Select "The subject contains..." and enter "Falcon". Condition 2: Select "The recipient is located..." and choose "External". Step 7: Set the action:
Select "Apply the sensitivity label..." and choose the label you created in the previous step. Step 8: Review and save the rule. Reference:
Options
- AClassificationDescriptions
- BClassificationList
- CDefaultClassification
- DEnableMIPLabels
- EDistribution
- FMail-enabled security
- GMicrosoft 365
- HSecurity
How the community answered
(32 responses)- B6% (2)
- C3% (1)
- D78% (25)
- F3% (1)
- H9% (3)
Why each option
Encrypting outbound email containing 'Falcon' in the subject via an RMS template requires enabling MIP labels (EnableMIPLabels) on a Microsoft 365 group type, which supports sensitivity label enforcement.
ClassificationDescriptions provides human-readable descriptions for label classifications and does not control or enable RMS encryption on outbound email.
ClassificationList defines the set of available classification values for a group but does not configure or enforce encryption based on subject line keywords.
DefaultClassification sets a default label for a group but does not configure rule-based encryption triggered by subject line content.
EnableMIPLabels is the parameter that activates Microsoft Information Protection sensitivity label support on a Microsoft 365 group, which is a prerequisite for applying RMS template-based encryption through sensitivity label policies on outbound mail.
Distribution group type does not support sensitivity labels or MIP label enforcement and cannot be used to apply RMS template encryption.
Mail-enabled security groups do not support MIP label assignment and therefore cannot enforce sensitivity label-based RMS encryption on outbound messages.
Microsoft 365 is the group type that natively supports sensitivity label assignment and MIP label enforcement - other group types such as Distribution or Security do not support this capability and cannot serve as the target for label-driven RMS encryption.
Security group type lacks support for MIP label assignment and cannot be used to enforce RMS template encryption on email traffic.
Concept tested: MIP label and RMS encryption enforcement on Microsoft 365 groups
Source: https://learn.microsoft.com/en-us/purview/sensitivity-labels-teams-groups-sites
Topics
Community Discussion
No community discussion yet for this question.