nerdexam
Microsoft

SC-401 · Question #30

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. The answer is No - this second proposed solution also does not meet the goal. As with Question 9, the scenario involves blocking Tailspin_scanner.exe from accessing sensitive information on Windows 11 endpoints that are onboarded to Microsoft Purview. The correct and complete…

Implement data loss prevention and retention

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview. You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers. You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents. Solution: From Microsoft Defender for Cloud Apps, you create an app discovery policy. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(38 responses)
  • A
    16% (6)
  • B
    84% (32)

Explanation

The answer is No - this second proposed solution also does not meet the goal. As with Question 9, the scenario involves blocking Tailspin_scanner.exe from accessing sensitive information on Windows 11 endpoints that are onboarded to Microsoft Purview. The correct and complete solution requires: (1) adding Tailspin_scanner.exe to the Endpoint DLP restricted apps list in the Microsoft Purview compliance portal, and (2) creating or modifying an Endpoint DLP policy with a rule that enforces blocking when this app accesses content matching sensitive info types. The alternative solution presented here - likely a variation such as using a different policy type, a different Purview feature, or an incomplete configuration - fails to apply the correct enforcement mechanism at the application layer on the endpoint, so it does not satisfy the requirement.

Topics

#Microsoft Defender for Cloud Apps#App Discovery#Endpoint DLP#Sensitive Information Protection

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice