SC-401 · Question #30
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. The answer is No - this second proposed solution also does not meet the goal. As with Question 9, the scenario involves blocking Tailspin_scanner.exe from accessing sensitive information on Windows 11 endpoints that are onboarded to Microsoft Purview. The correct and complete…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview. You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers. You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents. Solution: From Microsoft Defender for Cloud Apps, you create an app discovery policy. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(38 responses)- A16% (6)
- B84% (32)
Explanation
The answer is No - this second proposed solution also does not meet the goal. As with Question 9, the scenario involves blocking Tailspin_scanner.exe from accessing sensitive information on Windows 11 endpoints that are onboarded to Microsoft Purview. The correct and complete solution requires: (1) adding Tailspin_scanner.exe to the Endpoint DLP restricted apps list in the Microsoft Purview compliance portal, and (2) creating or modifying an Endpoint DLP policy with a rule that enforces blocking when this app accesses content matching sensitive info types. The alternative solution presented here - likely a variation such as using a different policy type, a different Purview feature, or an incomplete configuration - fails to apply the correct enforcement mechanism at the application layer on the endpoint, so it does not satisfy the requirement.
Topics
Community Discussion
No community discussion yet for this question.