SC-401 · Question #32
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…
The correct answer is B. No. To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys. Mail flow rules (transport…
Question
Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties. You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted. Solution: You configure a mail flow rule that matches a sensitive info type. Does this meet the goal?
Options
- AYes
- BNo
How the community answered
(47 responses)- A21% (10)
- B79% (37)
Explanation
To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys. Mail flow rules (transport rules) can detect sensitive info, but they are limited in encryption DLP policies provide more advanced protection and integration with Microsoft Purview for sensitive info detection.
Topics
Community Discussion
No community discussion yet for this question.