SC-401 · Question #29
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. The answer is No - the proposed solution does not meet the goal. To block a specific executable (Tailspin_scanner.exe) from accessing sensitive content on endpoints using Microsoft Purview, the correct approach is to use Endpoint DLP with the 'Unallowed apps' (restricted apps)…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview. You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers. You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents. Solution: From the Microsoft 365 Endpoint data loss prevention (Endpoint DLP) settings, you add a folder path to the file path exclusions. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(24 responses)- A25% (6)
- B75% (18)
Explanation
The answer is No - the proposed solution does not meet the goal. To block a specific executable (Tailspin_scanner.exe) from accessing sensitive content on endpoints using Microsoft Purview, the correct approach is to use Endpoint DLP with the 'Unallowed apps' (restricted apps) feature. You add the executable to the restricted apps list in Endpoint DLP settings and configure a DLP policy with an endpoint rule that blocks access when the app attempts to interact with sensitive content. The solution presented in this question (likely using a different Purview feature such as a communication compliance policy, retention policy, or a DLP rule without endpoint-specific app restrictions) does not directly target application-level blocking at the endpoint. Only the Endpoint DLP restricted apps configuration correctly blocks a specific executable from accessing protected data.
Topics
Community Discussion
No community discussion yet for this question.