SC-401 Practice Question 3560
Exam: SC-401
Domain: Implement data loss prevention and retention
Difficulty: easy
You need to configure Microsoft Purview to send incident alert emails to a security operations mailbox whenever a high-volume DLP violation (more than 50 sensitive records in one file) occurs. Where is this alert configured?
Answer Options
A
Under Incident reports in the DLP rule configuration
B
In the local Windows Event Viewer
C
In the DNS registrar zone management blade
D
In Azure Cost Management alerts
Correct Answer
A: Under Incident reports in the DLP rule configuration
Explanation
In the DLP rule definition under "Incident reports", toggle alerts on and specify the severity and target administrative email distribution list.