SC-401 Practice Question 3560

Exam: SC-401
Domain: Implement data loss prevention and retention
Difficulty: easy
You need to configure Microsoft Purview to send incident alert emails to a security operations mailbox whenever a high-volume DLP violation (more than 50 sensitive records in one file) occurs. Where is this alert configured?

Answer Options

A
Under Incident reports in the DLP rule configuration
B
In the local Windows Event Viewer
C
In the DNS registrar zone management blade
D
In Azure Cost Management alerts

Correct Answer

A: Under Incident reports in the DLP rule configuration

Explanation

In the DLP rule definition under "Incident reports", toggle alerts on and specify the severity and target administrative email distribution list.