Q1.You need to configure a new data loss prevention (DLP) policy in your organization.
Which administrative tool should you use for this task?
Show answer
A data loss prevention (DLP) policy detects and controls sensitive information across all of Microsoft 365, including email, SharePoint, OneDrive, and Teams.
The official administrative console for creating and managing these DLP policies is the Microsoft Purview compliance portal.
From here you centrally manage DLP policies, sensitivity labels, information protection, and more.
The Microsoft 365 admin center is for user and license management, the Intune admin center is for endpoint management, and the Microsoft 365 Defender portal focuses on threat detection and response (XDR); none of these is where DLP is created.
Microsoft Purview Data Loss Prevention
Overview of the Microsoft 365 admin center
Q2.Select the word or phrase that correctly completes the statement.
[ ] provides cloud workload protection for resources on Azure and in hybrid cloud environments.
Show answer
Microsoft Defender for Cloud is a security service that provides cloud workload protection (CWPP) for Azure and hybrid environments (on-premises and other clouds).
It provides vulnerability assessment, threat detection, and security recommendations for resources such as virtual machines, containers, SQL, and storage.
Azure Monitor is intended for monitoring and log collection and has no protection capability.
The Microsoft cloud security benchmark is a set of security guidelines and does not perform actual protection.
Microsoft Secure Score is a metric that quantifies and visualizes your security posture.
What is Microsoft Defender for Cloud?
What is CWPP?
Q3.For each of the following statements, select [Yes] if the statement is true or [No] if it is not.
| Statement | Yes | No | |
|---|---|---|---|
| In Security Center’s Secure Score, you can review recommendations related to Defender for Cloud Apps | |||
| From Security Center, you can display your organization’s score compared with other organizations’ scores | |||
| Even when you address an improvement action using a third-party app, you are awarded score points |
Show answer
Microsoft Secure Score can be viewed from the Microsoft 365 Defender portal, where it aggregates and displays recommendations from each security product, including Defender for Cloud Apps.
Therefore, improvement actions related to Defender for Cloud Apps are also included in the score.
In addition, you can display your organization’s score compared with the industry average or with other organizations (anonymized, aggregated data).
On the other hand, points are awarded only for improvement actions that Microsoft can detect and evaluate, so measures taken with third-party apps cannot be verified and are not added to the score.
Microsoft Secure Score
Q4.For each of the following statements, select [Yes] if the statement is true or [No] if it is not.
| Statement | Yes | No | |
|---|---|---|---|
| You can export the search results of Microsoft Purview eDiscovery (Standard) | |||
| You can integrate Microsoft Purview eDiscovery (Standard) with insider risk management | |||
| You can use Microsoft Purview eDiscovery (Standard) to search Exchange Online public folders |
Show answer
Microsoft Purview eDiscovery (Standard) is a basic electronic discovery capability that provides search, hold, and export for Microsoft 365 data, and search results can be exported for review or evidence submission.
On the other hand, integration with insider risk management is a feature of eDiscovery (Premium) and is not supported in Standard, so that statement is incorrect.
In addition, even in Standard you can include Exchange Online public folders in the search scope, along with mailboxes.
Get started with eDiscovery (Standard)
Overview of Microsoft Purview eDiscovery (Premium)
Q5.In the cloud shared responsibility model, which management responsibility does Microsoft bear entirely on its own?
Show answer
In the shared responsibility model, security and management responsibilities in a cloud environment are divided between Microsoft (the cloud provider) and the customer.
What Microsoft is solely responsible for is managing physical hardware such as datacenter facilities, servers, and network equipment.
On the other hand, managing user accounts, access permissions to user data, and mobile devices are among the responsibilities of the customer using the cloud.
Because security for these depends on identity management, access control, and device management settings, Microsoft does not manage them automatically.
Shared responsibility in the cloud
Q6.You need to retain a copy of all files on a SharePoint site for one year.
What should you apply to the site?
Show answer
When you want to retain a copy of all files on a SharePoint site for a set period (one year), what you should apply is a Microsoft Purview retention policy.
A retention policy can be applied at the SharePoint site level and reliably preserves a retained copy (a hold copy) even if a file is deleted or modified during the specified period.
Sensitivity labels are intended for classification and encryption and are not suited to enforcing retention periods.
An insider risk policy is for detecting internal wrongdoing, and a DLP policy is for preventing data exfiltration.
Learn about retention policies and retention labels
Learn about retention for SharePoint and OneDrive
Q7.Select the service to use in the answer area to display the Azure Secure Score.
Show answer
The Azure Secure Score is a metric that visualizes the security posture of your Azure environment and indicates areas for improvement numerically.
The service that displays and manages this score is Microsoft Defender for Cloud (formerly Azure Security Center).
In Defender for Cloud, the Secure Score is displayed together with security recommendations across your subscriptions and resources.
Azure Monitor and Application Insights are intended for monitoring and observability and do not provide Secure Score; Advisor offers optimization suggestions, Policy enforces rules, and Subscriptions are a management unit.
What is Microsoft Defender for Cloud?
Secure score in Defender for Cloud
Q8.For each of the following statements, select [Yes] if the statement is true or [No] if it is not.
| Statement | Yes | No | |
|---|---|---|---|
| Conditional Access is implemented using Microsoft Entra ID policies | |||
| You can block or allow connections based on the specific platform of the user’s device | |||
| You can apply a Conditional Access policy to a Microsoft 365 group |
Show answer
Conditional Access is an identity-based access control capability provided by Microsoft Entra ID and is implemented using policies.
Based on users and sign-in conditions (such as location, risk, and device state), it can grant, block, or require additional authentication for access.
Because you can specify the device platform (iOS, Android, Windows, and so on) as a condition, controlling connections from specific operating systems is possible.
On the other hand, the assignment targets are users, security groups, and apps; you cannot directly specify a Microsoft 365 group.
What is Conditional Access?
Conditional Access: Users, groups, agents, and workload identities
Q9.Which capability is provided by the extended detection and response (XDR) features of Azure Sentinel?
Show answer
Microsoft Sentinel (formerly Azure Sentinel) is a SIEM/SOAR service, but its XDR capabilities are realized through integration with Microsoft 365 Defender.
This integration correlates threat signals from multiple domains, such as endpoints, identities, email, and cloud apps, and lets you visualize and respond to them centrally as incidents.
Support for Azure Monitor workbooks and threat hunting are Sentinel features, but they are not XDR-specific capabilities.
Also, the compliance center (Purview) is intended for data protection and governance and is not directly related to XDR.
Integrate Microsoft Defender XDR with Microsoft Sentinel
What is Microsoft Defender XDR?
Q10.When connecting to an Azure virtual machine by using Azure Bastion, what should you use?
Show answer
Azure Bastion is a managed service that provides RDP or SSH connectivity directly from the Azure portal without exposing the VM’s public IP to the internet.
Because the connection is made through the browser from within the Azure portal, there is no need to install an RDP client or SSH client on the client device.
PowerShell remoting is also not a prerequisite for a Bastion connection.
From the standpoint of “where do you connect from,” the Azure portal is the correct answer.
What is Azure Bastion?
Create an RDP connection to a Windows VM using Azure Bastion
