nerdexam
Microsoft

SC-401 · Question #31

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is B. No. You can unsanction a specific risky app by clicking the three dots at the end of the row. Then select Unsanction. Unsanctioning an app doesn't block use, but enables you to more easily monitor its use with the Cloud Discovery filters. You can then notify users of the…

Implement data loss prevention and retention

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You have a Microsoft 365 tenant and 500 computers that run Windows 11. The computers are onboarded to Microsoft Purview. You discover that a third-party application named Tailspin_scanner.exe accessed protected sensitive information on multiple computers. Tailspin_scanner.exe is installed locally on the computers. You need to block Tailspin_scanner.exe from accessing sensitive documents without preventing the application from accessing other documents. Solution: From the Microsoft Defender for Cloud Apps, you mark the application as Unsanctioned. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(60 responses)
  • A
    28% (17)
  • B
    72% (43)

Explanation

You can unsanction a specific risky app by clicking the three dots at the end of the row. Then select Unsanction. Unsanctioning an app doesn't block use, but enables you to more easily monitor its use with the Cloud Discovery filters. You can then notify users of the unsanctioned app and suggest an alternative safe app for their use. https://docs.microsoft.com/en-us/microsoft-365/compliance/endpoint-dlp-using?view=o365-

Topics

#Defender for Cloud Apps#Unsanctioned applications#Information Protection#Data Loss Prevention

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice