nerdexam
Microsoft

SC-401 · Question #92

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might…

The correct answer is A. Yes. You create a data loss prevention (DLP) policy that has only the Exchange email location To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information…

Implement data loss prevention and retention

Question

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution. After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen. You recently discovered that the developers at your company emailed Azure Storage Account keys in plain text to third parties. You need to ensure that when Azure Storage Account keys are emailed, the emails are encrypted. Solution: You create a data loss prevention (DLP) policy that has Exchange email, SharePoint sites, OneDrive accounts, and Teams chat and channel messages selected. Does this meet the goal?

Options

  • AYes
  • BNo

How the community answered

(26 responses)
  • A
    92% (24)
  • B
    8% (2)

Explanation

  • You create a data loss prevention (DLP) policy that has only the Exchange email location To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys. A DLP policy with Exchange email as the only location meets this requirement because it identifies sensitive data in email messages and it applies protection actions, such as encryption, blocking, or alerts. * You create a data loss prevention (DLP) policy that has Exchange email, SharePoint sites, OneDrive accounts, and Teams chat and channel messages selected.OneDrive accounts, and Teams chat and channel messages selected. Creating a Data Loss Prevention (DLP) policy that includes Exchange email as a location can help detect and prevent the sharing of sensitive information, like Azure Storage keys, in plain text. By setting up a DLP policy with conditions to identify Azure Storage keys and enforce encryption or blocking actions for Exchange email, the policy will ensure that any emails containing such sensitive information are either encrypted or prevented from being sent. * You configure a mail flow rule that matches a sensitive info type. * You configure a mail flow rule that matches the text patterns. To ensure Azure Storage Account keys are encrypted when sent via email, you need a Data Loss Prevention (DLP) policy that detects Azure Storage Account keys using a sensitive information type and automatically encrypts emails containing these keys. Text patterns in mail flow rules are not as reliable as sensitive information types in DLP. Mail flow rules lack advanced content detection and machine learning-based classification, making them less effective than DLP. * You create a data loss prevention (DLP) policy that has all locations selected. https://docs.microsoft.com/en-us/exchange/policy-and-compliance/mail-flow-rules/conditions-and-

Topics

#Data Loss Prevention (DLP)#Email Encryption#Sensitive Information Types#Azure Storage Account Keys

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice