You are configuring a custom Sensitive Information Type (SIT) in Microsoft Purview to detect an internal employee ID that always starts with the prefix "EMP-", followed by exactly six digits. Which pattern component should you define to identify this string structure?
- Regular Expression (RegEx) (Correct)
- Keyword Dictionary only
- Document Fingerprint template
- Trainable Classifier
Explanation: A Regular Expression (RegEx) pattern defines the precise character syntax requirements (such as `EMP-d{6}`) to match structured strings with exact alphanumeric lengths.
Your organization must detect proprietary customer bank account numbers stored in a database table containing 250,000 active records. You need to prevent false positives by matching the exact bank account number alongside the customer full name and tax identifier. Which classification feature should you deploy?
- Exact Data Match (EDM) Sensitive Information Type (Correct)
- Standard Regular Expression match
- Document Fingerprint template
- Trainable Classifier
Explanation: Exact Data Match (EDM) based Sensitive Information Types enable organizations to upload structured hashes from a database or CSV file, matching dynamic multi-field records (such as Account + Name + SSN) with zero false positives.
You need to train Microsoft Purview to automatically recognize a proprietary technical design specification format that has variable wording and unstructured prose. Which classification method is best suited for categorizing this unstructured content based on human review samples?
- Trainable Classifier (Correct)
- Regular Expression
- Exact Data Match
- Keyword Dictionary
Explanation: Trainable Classifiers use machine learning models trained on a positive seed set of 50-300 representative documents and a negative set of non-matching documents to recognize unstructured text patterns.
You have a standardized, pre-printed government tax intake form that users fill in with handwritten or typed data. You want Microsoft Purview to detect when any scanned copy or digital version of this specific form template is shared. Which data classification technology should you use?
- Document Fingerprinting (Correct)
- Trainable Classifier
- Exact Data Match
- Regular Expression
Explanation: Document Fingerprinting converts a blank standard template form into a unique cryptographic hash digest, enabling the classification engine to detect when filled-out instances of that form structure are transmitted.
You are configuring optical character recognition (OCR) in Microsoft Purview. Why would an administrator enable OCR support within information protection and DLP policies?
- Extracts and evaluates sensitive text embedded in image files and scanned PDFs (Correct)
- Compresses images uploaded to SharePoint libraries
- Converts audio voice recordings into MP3 format
- Translates foreign languages in email attachments
Explanation: Enabling OCR allows Microsoft Purview classification engines to extract, parse, and evaluate sensitive text and data embedded inside image file formats (such as TIFF, JPG, and PNG) and scanned PDFs.
In Microsoft Purview Information Protection, what is the effect of configuring a sensitivity label with co-authoring enabled for encrypted files in Microsoft 365 desktop and web applications?
- Enables real-time simultaneous editing of encrypted files across apps (Correct)
- Removes encryption when files are opened by multiple users
- Prevents more than one user from opening the file
- Converts documents to unencrypted PDF format automatically
Explanation: Enabling co-authoring for files encrypted with sensitivity labels allows multiple users to simultaneously edit labeled and encrypted Word, Excel, and PowerPoint documents in real time across web and desktop apps.
You need to configure a sensitivity label named "Confidential - External" that applies Rights Management encryption. You want users from a trusted external partner organization (@partner.com) to view and edit files, but strictly block them from printing or forwarding content. Which configuration achieves this?
- Custom usage rights granting View/Edit while revoking Print and Export (Correct)
- Assigning Full Control to the external domain
- Applying password protection via a zip archive
- Disabling TLS 1.3 across tenant connections
Explanation: Configure custom usage rights within the sensitivity label encryption settings, granting specific user accounts or the @partner.com domain Viewer and Reviewer permissions while revoking Print and Export rights.
You want to automatically classify and protect on-premises file shares and local SharePoint Server document libraries containing unencrypted sensitive files. What component should you deploy to scan these on-premises repositories?
- Microsoft Purview Information Protection scanner (Correct)
- Microsoft Defender for Identity sensor
- Exchange Edge Transport server
- Azure Virtual Network gateway
Explanation: The Microsoft Purview Information Protection scanner installs on Windows Server instances on-premises to discover, classify, label, and protect files stored on SMB network shares and SharePoint Server.
When publishing sensitivity labels, what is the purpose of configuring the "Users must provide justification to remove a label or lower its classification" setting in a sensitivity label policy?
- Forces users to record a justification reason logged in the audit log (Correct)
- Locks the user account immediately upon label change
- Deletes the file automatically if downgraded
- Sends a text message to the tenant Global Administrator
Explanation: It forces users to select a predefined justification reason or type a business explanation when downgrading a label or removing encryption, which is logged to the Unified Audit Log.
You are configuring auto-labeling for data at rest. You want to apply the "Secret" sensitivity label to all existing SharePoint and OneDrive documents containing credit card numbers without requiring users to open or save the files. What must you create?
- An Auto-labeling Policy for data at rest (Correct)
- A local client-side GPO script
- An Exchange message trace filter
- A Microsoft Teams messaging policy
Explanation: An Auto-labeling Policy configured in the Microsoft Purview portal evaluates data at rest asynchronously across SharePoint Online, OneDrive, and Exchange mailboxes, applying labels in simulation or live mode.
What is the role of simulation mode when deploying a service-side auto-labeling policy in Microsoft Purview?
- Evaluates classification rule matches and false positives before enforcing labels (Correct)
- Encrypts all files with temporary test encryption keys
- Deletes non-compliant files during the evaluation phase
- Simulates user sign-in attacks across endpoints
Explanation: Simulation mode allows administrators to evaluate how many items and files match the classification conditions across targeted workloads, reviewing accuracy and false positives before enforcing labels.
An organization needs to encrypt outbound email sent to external recipients using Microsoft Purview Message Encryption. When an external recipient does not have a Microsoft 365 or Google account, how do they access the encrypted message?
- Via secure web portal authenticated with a One-Time Passcode (OTP) (Correct)
- By installing on-premises Active Directory Domain Services
- By having the message decrypted into cleartext automatically in transit
- They are permanently blocked from reading encrypted messages
Explanation: External recipients receive an email notification containing a secure web link directing them to the Microsoft Purview Message Encryption web portal, where they authenticate using a One-Time Passcode (OTP).
What capability is unlocked when an organization upgrades from standard Microsoft Purview Message Encryption to Microsoft Purview Advanced Message Encryption?
- Message revocation, message expiration, and custom branded external portals (Correct)
- Unlimited mailbox storage quotas for all users
- Automatic conversion of emails into audio podcasts
- Bypassing spam scanning for external senders
Explanation: Advanced Message Encryption enables administrators to revoke encrypted emails sent externally, enforce message expiration timeframes, and customize multi-branded portal templates per recipient domain.
You need to ensure that when a sensitivity label is applied to a Microsoft Teams team, the underlying SharePoint site collection is automatically set to Private and external guest access is blocked. What label container setting governs this?
- Groups & sites container settings (Correct)
- Items & files scope settings
- Schematized data assets scope
- Exchange transport rules
Explanation: Configuring the "Groups & sites" protection scope on a sensitivity label allows administrators to govern privacy (Public vs Private), external user access, and unmanaged device access for containers.
Where in the Microsoft Purview portal can an administrator view a consolidated inventory of labeled files, sensitive information type matches, and sensitive data locations across the enterprise?
- Content Explorer (Correct)
- Service Health dashboard
- Secure Score dashboard
- Message Trace console
Explanation: Data classification > Content Explorer provides a hierarchical view of all sensitive information type matches, retention labels, and sensitivity labels applied across SharePoint, OneDrive, and Exchange.
Which tool in Microsoft Purview Data Classification displays historical event telemetry regarding labeling changes, file renames, sensitive file downloads, and label modifications over the past 30 days?
- Activity Explorer (Correct)
- Content Explorer
- Audit log retention policies
- Security Baselines
Explanation: Activity Explorer displays historical audit records and trends regarding user interactions with sensitive files, including label application, removal, file modifications, and file read events.
You need to assign a user the administrative role required to create, publish, and manage sensitivity labels in Microsoft Purview without granting them broader Global Administrator permissions. Which role should you assign?
- Information Protection Administrator (Correct)
- Helpdesk Administrator
- Billing Administrator
- Directory Writers
Explanation: The Information Protection Administrator role grants full administrative permissions to create and manage sensitivity labels, label policies, and sensitive information types across Purview.
You want to implement a sensitivity label that adds a visual header and watermark stating "CONFIDENTIAL" to Word documents. In what order of precedence do multiple labels apply if priority is configured?
- The label positioned at the bottom of the list has the highest priority (Correct)
- The label at the top of the list always overrides all other labels
- Priority is determined alphabetically by label display name
- All labels have identical priority and apply randomly
Explanation: Sensitivity labels follow an ordered priority where the label at the bottom of the list in the admin center has the highest priority (e.g., Priority 0 is lowest; higher numbers represent higher confidentiality).
What happens when a user attempts to change a document sensitivity label from "Highly Confidential" to "General" if the label policy has "Require justification" enabled?
- A prompt requires a business justification, which is logged to the audit log (Correct)
- The downgrade is blocked and the user workstation is locked
- The document is deleted immediately
- The file permissions are converted to read-only permanently
Explanation: The user client displays a prompt requiring them to enter a business justification or select an approved reason, which is written to the tenant unified audit log.
You are configuring Exact Data Match (EDM). What is the purpose of the EDM Upload Agent (EdmUploadAgent.exe) command-line utility?
- Hashes sensitive database records locally before upload to Purview (Correct)
- Extracts cleartext passwords from domain controllers
- Installs printer drivers on client laptops
- Formats on-premises database hard drives
Explanation: The EDM Upload Agent hashes sensitive database data locally using a salt before uploading the encrypted schema and hash tables to Microsoft Purview, ensuring plaintext data never leaves the network.
You are configuring default sensitivity labels. You want any newly created Word, Excel, or PowerPoint document authored by a user to automatically inherit a base classification. What should you configure?
- Default label setting in the Sensitivity Label Policy (Correct)
- A Group Policy Object mapping network drives
- An Exchange ActiveSync mobile policy
- An Azure Network Security Group rule
Explanation: Configure the "Default label" setting within the Sensitivity Label Policy assigned to that target group of users in Microsoft Purview.
An administrator configures sensitivity labels for Microsoft Fabric and Power BI datasets. What happens to downstream Power BI reports built from an encrypted and labeled dataset?
- Downstream inheritance applies the sensitivity label and encryption automatically (Correct)
- The label is stripped and the report becomes public
- The downstream report fails to generate and errors out
- Power BI reports cannot connect to labeled datasets
Explanation: Downstream inheritance automatically propagates the sensitivity label and its associated encryption protection to all reports, dashboards, and dataflows derived from that parent dataset.
You are deploying the Microsoft Purview Information Protection client on Windows 11 endpoints. What does this client provide to end users in Windows File Explorer?
- Right-click "Classify and protect" context menu to label files outside Office (Correct)
- Full disk BitLocker volume encryption tool
- Automatic uninstallation of third-party software
- Direct RDP access to domain controllers
Explanation: It adds a right-click context menu ("Classify and protect") in Windows File Explorer, allowing users to inspect, label, and encrypt files stored outside of Microsoft 365 apps.
You want to detect credit card numbers in French, German, and English using a single built-in Sensitive Information Type. Which built-in SIT should you select?
- Credit Card Number (Correct)
- U.S. Social Security Number
- EU Passport Number
- SWIFT Code
Explanation: The "Credit Card Number" built-in Sensitive Information Type is a global SIT that uses the Luhn algorithm checksum to identify valid credit card numbers worldwide regardless of language.
What is the function of a Keyword Dictionary in Microsoft Purview Data Classification compared to a standard keyword list?
- Supports up to 100,000 terms for high-volume dictionary matching (Correct)
- Translates documents into foreign languages automatically
- Can only contain a maximum of 10 terms
- Requires installing SQL Server on every workstation
Explanation: A Keyword Dictionary supports up to 100,000 terms (totaling up to 1 MB of text), simplifying management and performance when matching large lists of medical terms, drug names, or proprietary code words.
You need to configure Microsoft Purview to automatically decrypt protected email messages so that third-party journaling or compliance archival tools can index cleartext content. Which feature enables this?
- Journal report decryption in Exchange Online (Correct)
- Disabling Information Rights Management tenant-wide
- Exporting user private keys to an unencrypted text file
- Configuring an anonymous SMTP relay connector
Explanation: Journal report decryption in Exchange Online decrypts Rights Management-protected email messages attached to journal reports before dispatching them to external journal mailboxes.
How do sensitivity labels interact with Microsoft 365 Copilot when Copilot references an encrypted corporate document to generate a summary in Word?
- Copilot checks user rights, requiring Extract (Copy) right, and inherits label (Correct)
- Copilot bypasses encryption and publishes data publicly
- Copilot is blocked from referencing any encrypted content under all conditions
- Copilot strips the sensitivity label from generated files
Explanation: Copilot checks user rights: it only accesses and summarizes content if the user possesses the "Extract" (Copy) right under the label encryption, and the output document inherits the source sensitivity label.
You want to prevent external recipients of encrypted emails from using the "Reply All" or "Forward" actions in Microsoft Outlook. What Rights Management permission template provides this?
- Do Not Forward (Correct)
- Encrypt-Only without restrictions
- Public Unrestricted
- Confidential - Full Access
Explanation: The "Do Not Forward" option encrypts the message, restricts viewing to addressed recipients only, and programmatically disables Forward, Print, and Copy controls across email clients.
You want to prevent external recipients of encrypted emails from using the "Reply All" or "Forward" actions in Microsoft Outlook. What Rights Management permission template provides this?
- Do Not Forward (Correct)
- Encrypt-Only without restrictions
- Public Unrestricted
- Confidential - Full Access
Explanation: The "Do Not Forward" option encrypts the message, restricts viewing to addressed recipients only, and programmatically disables Forward, Print, and Copy controls across email clients.
In Microsoft Purview Information Protection, what is a "Sublabel" used for in a labeling hierarchy?
- Organizing related classification tiers logically under a parent label (Correct)
- Encrypting hard drives with a second recovery key
- Creating duplicate copies of files on OneDrive
- Compressing video files uploaded to SharePoint
Explanation: Sublabels allow organizations to group related classification tiers under a parent label (e.g., "Confidential > Finance" and "Confidential > HR") to present a logical, clean hierarchy in Office apps.
You need to revoke an encrypted email sent via Advanced Message Encryption to an external customer after realizing the attachment contained confidential trade secrets. Where does the sender perform revocation?
- Opens the message in Sent Items in Outlook on the web and selects Revoke (Correct)
- Deletes the recipient email account in Microsoft Entra ID
- Calls the recipient telephone company to cancel delivery
- Restores the Exchange database from an offline tape
Explanation: In Outlook on the web under Sent Items, the sender opens the message and clicks "Revoke message", which invalidates the decryption token on the secure web portal.
You need to revoke an encrypted email sent via Advanced Message Encryption to an external customer after realizing the attachment contained confidential trade secrets. Where does the sender perform revocation?
- Opens the message in Sent Items in Outlook on the web and selects Revoke (Correct)
- Deletes the recipient email account in Microsoft Entra ID
- Calls the recipient telephone company to cancel delivery
- Restores the Exchange database from an offline tape
Explanation: In Outlook on the web under Sent Items, the sender opens the message and clicks "Revoke message", which invalidates the decryption token on the secure web portal.
You are auditing sensitive items across SharePoint Online. You need to verify the exact string values that triggered a Sensitive Information Type match inside an executive document. Which role is required to view source text in Content Explorer?
- Content Explorer Content Viewer (Correct)
- Content Explorer List Viewer only
- Security Reader
- Helpdesk Administrator
Explanation: The Content Explorer Content Viewer role (in addition to Content Explorer List Viewer) is required to inspect the actual plaintext source data and snippets inside Content Explorer.
You are auditing sensitive items across SharePoint Online. You need to verify the exact string values that triggered a Sensitive Information Type match inside an executive document. Which role is required to view source text in Content Explorer?
- Content Explorer Content Viewer (Correct)
- Content Explorer List Viewer only
- Security Reader
- Helpdesk Administrator
Explanation: The Content Explorer Content Viewer role (in addition to Content Explorer List Viewer) is required to inspect the actual plaintext source data and snippets inside Content Explorer.
Which PowerShell module is used to connect to Microsoft Purview and manage sensitivity labels, label policies, and sensitive information types programmatically?
- Exchange Online PowerShell module via Connect-IPPSSession (Correct)
- Azure CLI storage blob commands
- Active Directory Users and Computers module
- Microsoft Teams PowerShell module
Explanation: The Exchange Online PowerShell module (specifically using `Connect-IPPSSession` to access the Compliance and Information Protection endpoint) manages Purview classification cmdlets.
What is the effect of configuring "Auto-labeling for files and emails" within a sensitivity label configuration rather than an auto-labeling policy?
- Evaluates and applies labels client-side in real time during authoring (Correct)
- Scans content at rest asynchronously across SharePoint databases
- Deletes files if sensitive information is detected
- Requires installing on-premises SQL Server instances
Explanation: Configuring auto-labeling inside the sensitivity label itself applies client-side: it prompts the user or automatically applies the label in real time as the user edits the document in desktop Office apps.
What is the effect of configuring "Auto-labeling for files and emails" within a sensitivity label configuration rather than an auto-labeling policy?
- Evaluates and applies labels client-side in real time during authoring (Correct)
- Scans content at rest asynchronously across SharePoint databases
- Deletes files if sensitive information is detected
- Requires installing on-premises SQL Server instances
Explanation: Configuring auto-labeling inside the sensitivity label itself applies client-side: it prompts the user or automatically applies the label in real time as the user edits the document in desktop Office apps.
You are designing a Microsoft Purview Data Loss Prevention (DLP) policy. You need to ensure the policy applies to files stored in personal OneDrive accounts across the company. Which location should you enable in the policy configuration?
- OneDrive accounts (Correct)
- Exchange mailboxes only
- Teams chat and channel messages only
- On-premises file shares
Explanation: Selecting the "OneDrive accounts" location applies the DLP policy to all files uploaded, modified, or shared across personal OneDrive for Business document libraries.
You are designing a Microsoft Purview Data Loss Prevention (DLP) policy. You need to ensure the policy applies to files stored in personal OneDrive accounts across the company. Which location should you enable in the policy configuration?
- OneDrive accounts (Correct)
- Exchange mailboxes only
- Teams chat and channel messages only
- On-premises file shares
Explanation: Selecting the "OneDrive accounts" location applies the DLP policy to all files uploaded, modified, or shared across personal OneDrive for Business document libraries.
You want to configure an educational prompt in Outlook that warns users before they send an email containing sensitive customer tax identifiers to an external domain. Which DLP component provides this?
- DLP Policy Tips (Correct)
- Exchange transport disclaimer footer
- Windows battery notification popup
- Safe Attachments scan progress bar
Explanation: DLP Policy Tips display visual notification bars directly within Outlook and web clients, alerting senders to policy violations before the message is dispatched.
You want to configure an educational prompt in Outlook that warns users before they send an email containing sensitive customer tax identifiers to an external domain. Which DLP component provides this?
- DLP Policy Tips (Correct)
- Exchange transport disclaimer footer
- Windows battery notification popup
- Safe Attachments scan progress bar
Explanation: DLP Policy Tips display visual notification bars directly within Outlook and web clients, alerting senders to policy violations before the message is dispatched.
You need to allow users to override a DLP block when emailing external business auditors, provided they record a business reason. How should the DLP rule action be configured?
- Block access with override allowed requiring business justification (Correct)
- Allow access without any logging or alerts
- Block access permanently with no override capability
- Delete the user email mailbox immediately
Explanation: Configure the rule action to "Block access" but check "Allow override from M365 services" and select "Require a business justification to override".
You need to allow users to override a DLP block when emailing external business auditors, provided they record a business reason. How should the DLP rule action be configured?
- Block access with override allowed requiring business justification (Correct)
- Allow access without any logging or alerts
- Block access permanently with no override capability
- Delete the user email mailbox immediately
Explanation: Configure the rule action to "Block access" but check "Allow override from M365 services" and select "Require a business justification to override".
An administrator is implementing Microsoft Purview Endpoint DLP. You need to prevent users from copying corporate data containing credit card numbers into personal web browsers (like Google Chrome). What setting should you configure?
- Configure Unallowed browsers in Endpoint DLP settings or deploy Purview extension (Correct)
- Uninstall web browsers from client workstations
- Block TCP port 80 at corporate edge firewalls
- Disable IPv6 on client laptops
Explanation: In Microsoft Purview Endpoint DLP global settings, configure "Unallowed browsers" to block unsupported browsers, or deploy the Microsoft Purview extension to monitor web uploads.
An administrator is implementing Microsoft Purview Endpoint DLP. You need to prevent users from copying corporate data containing credit card numbers into personal web browsers (like Google Chrome). What setting should you configure?
- Configure Unallowed browsers in Endpoint DLP settings or deploy Purview extension (Correct)
- Uninstall web browsers from client workstations
- Block TCP port 80 at corporate edge firewalls
- Disable IPv6 on client laptops
Explanation: In Microsoft Purview Endpoint DLP global settings, configure "Unallowed browsers" to block unsupported browsers, or deploy the Microsoft Purview extension to monitor web uploads.
You want to block Windows 11 endpoint users from copying sensitive intellectual property files to USB removable flash drives, while allowing read-only access. Which Endpoint DLP action enforces this?
- Set "Copy to removable USB media" to Block in Endpoint DLP settings (Correct)
- Disable USB controllers in the computer BIOS
- Deploy BitLocker Drive Encryption to client hard drives
- Unassign Microsoft 365 licenses from users
Explanation: Under Endpoint DLP actions within the policy rule, configure "Audit or restrict activities on Windows devices" and set "Copy to removable USB media" to "Block".
What is the operational function of Microsoft Purview Adaptive Protection when integrated with Data Loss Prevention (DLP)?
- Dynamically applies stricter DLP block controls based on insider risk levels (Correct)
- Automatically orders hardware upgrades for high-risk users
- Translates DLP policy tips into foreign languages
- Deletes files from SharePoint if not opened for 30 days
Explanation: Adaptive Protection dynamically integrates DLP with Insider Risk Management, automatically applying stricter block controls to users who have an elevated insider risk level.
What is the operational function of Microsoft Purview Adaptive Protection when integrated with Data Loss Prevention (DLP)?
- Dynamically applies stricter DLP block controls based on insider risk levels (Correct)
- Automatically orders hardware upgrades for high-risk users
- Translates DLP policy tips into foreign languages
- Deletes files from SharePoint if not opened for 30 days
Explanation: Adaptive Protection dynamically integrates DLP with Insider Risk Management, automatically applying stricter block controls to users who have an elevated insider risk level.
You are creating a DLP policy targeting Microsoft Teams chat and channel messages. What action can Microsoft Purview DLP take when a user posts a message containing an unencrypted social security number?
- Blocks the message in real time, displaying a policy violation notice (Correct)
- Deletes the entire Teams channel permanently
- Forwards the message to external law enforcement
- Mutes the user microphone in all Teams meetings
Explanation: The DLP engine blocks the message in real time, replacing the post with a notification stating "This message was blocked by compliance policy" visible to the sender and channel.
You are creating a DLP policy targeting Microsoft Teams chat and channel messages. What action can Microsoft Purview DLP take when a user posts a message containing an unencrypted social security number?
- Blocks the message in real time, displaying a policy violation notice (Correct)
- Deletes the entire Teams channel permanently
- Forwards the message to external law enforcement
- Mutes the user microphone in all Teams meetings
Explanation: The DLP engine blocks the message in real time, replacing the post with a notification stating "This message was blocked by compliance policy" visible to the sender and channel.