Q1.A manufacturing company uses a Microsoft 365 E5 subscription that includes a Microsoft Teams channel named Channel1.
Channel1 is used to manage documents for the research and development department.
The company plans to introduce Microsoft 365 Copilot to this subscription soon.
You need to prevent the contents of files stored in Channel1 from being incorporated into the answers that Copilot generates and shown to unauthorized users.
Which feature should you use?
Show answer
Microsoft 365 Copilot generates answers based on the Microsoft 365 data that each user has permission to access.
Therefore, to keep the R&D documents in Channel1 out of the answers shown to unauthorized users, a sensitivity label that can apply protection to the files themselves is effective.
Sensitivity labels let you configure content classification, encryption, and access control so that only authorized users can open and use a file.
Copilot recognizes sensitivity labels and preserves the protection of labeled data.
DLP controls sharing and transmission, Insider Risk Management detects internal risk, and Information Barriers separate users from one another, so sensitivity labels are the best fit for this requirement.
Learn about sensitivity labels
Restrict access to content by using sensitivity labels to apply encryption
Q2.You operate a Microsoft 365 E5 subscription.
You need to create a new sensitivity label named Label1.
In this configuration, users must be able to use Microsoft 365 Copilot to summarize files to which Label1 is applied.
Which access permission should you assign to Label1?
Show answer
For Copilot to summarize a file encrypted with a sensitivity label, it is not enough for the user simply to have access to the target file.
When encryption is applied, the user needs the EXTRACT (copy and extract content) usage right in order for Copilot to return the data.
With only the VIEW permission, the user can open and read the file outside of Copilot, but Copilot cannot summarize it.
EXPORT is for saving in another format, DOCEDIT is for editing, and VIEW is for viewing, so none of these are the central permission that meets the summarization requirement.
Therefore, assign Copy and extract content (EXTRACT) to Label1.
Learn about sensitivity labels
Security and compliance considerations for Microsoft 365 Copilot
Q3.You have a Microsoft 365 E5 subscription.
You need to enable support for sensitivity labels in Microsoft SharePoint Online.
Which tool should you use to do this?
Show answer
To use sensitivity labels on Office files stored in SharePoint Online and OneDrive, you must enable the information protection setting on the SharePoint side.
This setting is configured not in the Microsoft Purview portal but as the option to enable sensitivity labels for Office files under Settings in the SharePoint admin center.
Once enabled, recognizing and applying labels and processing encrypted files is supported for files across both services.
The Microsoft Entra admin center focuses on identity and access management, and the Microsoft 365 admin center on tenant-wide administration, so neither is where this requirement is configured.
Therefore, the tool you should use is the SharePoint admin center.
Enable sensitivity labels for files in SharePoint and OneDrive
Q4.You use a Microsoft 365 subscription.
In this environment, you need to customize the appearance of encrypted email.
This work must meet the following requirements.
When encrypted email is sent, your company’s logo is displayed on the message.
Administrative effort is kept to a minimum.
Which PowerShell cmdlet should you run?
Show answer
To add branding elements such as a company logo to encrypted email, you modify the branding settings of Microsoft Purview Message Encryption.
To update an existing encrypted-message configuration, you can use Set-OMEConfiguration to set the logo, disclaimer text, body text, background color, and so on.
New-OMEConfiguration is used to create a new template, but that adds more effort than modifying an existing configuration and works against minimizing administrative work.
Set-IRMConfiguration configures Information Rights Management, and Set-RMSTemplate relates to RMS templates, so neither is suited to adding a logo.
Therefore, Set-OMEConfiguration is best for customizing encrypted email that includes a company logo.
Add your organization’s brand to encrypted messages
Set-OMEConfiguration
Q5.You have a Microsoft 365 E5 subscription.
You need to be able to revoke encrypted email messages sent to external recipients afterward, or have them expire automatically within 7 days.
What should you configure first?
Show answer
To control revocation and expiration of encrypted email sent to external recipients, you configure the encryption settings in a Microsoft Purview sensitivity label.
Sensitivity labels can apply encryption to email and files and let you set access permissions, offline access expiration, and usage rights per user or group.
Revocation and expiration management of encrypted email is a content protection setting rather than a branding or delivery control.
A custom branding template changes what is displayed, a mail flow rule performs condition-based processing, and a Conditional Access policy controls sign-in and app usage.
Therefore, what you should configure first is a sensitivity label that includes encryption settings.
Restrict access to content by using sensitivity labels to apply encryption
Learn about sensitivity labels
Q6.You have a Microsoft SharePoint Online site named Site1 that contains a document library.
The library holds more than 1,000 documents.
Some of them are applicant resumes.
All documents are written in English.
You plan to automatically apply a sensitivity label to documents identified as resumes.
Only documents that describe work experience, education, and accomplishments must be labeled automatically.
You need a mechanism to identify and classify resumes.
This configuration must minimize administrative effort.
What should you include in the solution?
Show answer
A resume is unstructured data that contains elements such as a name, work experience, education, and accomplishments, yet varies in wording and format from document to document.
To identify such documents, a trainable classifier that learns content and structure to classify is better suited than a keyword dictionary or a function.
In Microsoft Purview, you can use a trainable classifier as the condition for automatically applying a sensitivity label.
The pre-trained classifiers include one that identifies resumes, and it can be used with English-language documents.
An EDM classifier is intended for matching known, exact data, so it is not suited to classifying documents like resumes.
Therefore, to minimize administrative work, use a trainable classifier.
Learn about trainable classifiers
Automatically apply a sensitivity label to Microsoft 365 data
Q7.You are designing a data loss prevention (DLP) solution for Windows client computers.
When a user attempts to copy a file that contains sensitive information to a USB storage device, you must meet the following requirements.
If the user belongs to a group named Group1, allow the copy and record the event in the audit log.
For all other users, block the copy.
What should you create?
Show answer
With Microsoft Purview endpoint DLP, you can detect operations in which a file containing sensitive information is copied to a USB removable device on a Windows device and apply controls such as audit, warn, and block.
Here, for the same target data and the same device operation, you need to allow the copy with auditing for Group1 and block it for all other users.
Therefore, within a single DLP policy, you configure a separate audit rule for Group1 and a block rule for the other users.
A single rule cannot appropriately branch between auditing and blocking per user under the same conditions.
Therefore, what you should create is one DLP policy that contains two DLP rules.
Learn about endpoint data loss prevention
Create and deploy a data loss prevention policy
Q8.You use a Microsoft 365 subscription.
You need to enable users to apply retention labels to individual documents in a Microsoft SharePoint library.
Which two actions should you perform?
Each correct answer presents part of the solution.
Show answer
To enable users to apply retention labels to individual documents in a SharePoint library, you must first create the retention label in the Microsoft Purview portal and then publish it to the target users or SharePoint sites.
A retention label defines things such as how long content is retained, deletion after retention, and declaring content as a record.
A label is not shown to users just by being created; it becomes available in SharePoint only after it is published as a label policy.
A file policy in Microsoft Defender for Cloud Apps or site settings in the SharePoint admin center are not the primary steps for making retention labels available to users.
Therefore, you need to create and publish the retention label in the Microsoft Purview portal.
Publish retention labels and apply them in apps
Learn about retention policies and retention labels
Q9.You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint Online site named Site1.
You need to implement Microsoft Purview Data Lifecycle Management.
What should you create first?
Show answer
Microsoft Purview Data Lifecycle Management controls how long content such as SharePoint Online content is retained and when it is deleted after the retention period.
The foundation of this control is the retention label.
A retention label lets you define behaviors such as the retention period, the basis for when retention starts, and deletion or review after retention.
After creating a retention label, you publish it so users can apply it manually, or you apply it to content that matches conditions with an auto-apply policy.
A sensitivity label policy is for information protection, a DLP policy is for preventing information leakage, and an auto-labeling policy is for automatically applying existing labels.
Therefore, what you should create first is a retention label.
Publish retention labels and apply them in apps
Learn about retention policies and retention labels
Q10.You have a Microsoft 365 E5 subscription.
You need to create static retention policies that target each of the following locations.
Teams chats
Exchange email
SharePoint sites
Microsoft 365 Groups
Teams channel messages
What is the minimum number of retention policies required?
Show answer
In a Microsoft Purview retention policy, you can specify locations such as Exchange email, SharePoint sites, and Microsoft 365 Groups together in a single retention policy.
On the other hand, when you select Teams-related retention locations such as Teams chats or Teams channel messages, there is a constraint that other locations cannot be selected in the same retention policy.
Therefore, you need one retention policy for Exchange email, SharePoint sites, and Microsoft 365 Groups, and another for Teams chats and Teams channel messages.
Because Teams message retention is treated as a Teams-only location, you cannot combine everything into a single static retention policy.
Therefore, the minimum number of retention policies required is 2.
Create and configure retention policies
Learn about retention for Microsoft Teams
