exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 2 question 31 discussion

Actual exam question from Microsoft's MS-100
Question #: 31
Topic #: 2
[All MS-100 Questions]

HOTSPOT -
You have a Microsoft Azure Active Directory (Azure AD) tenant named contoso.com.
You have three applications App1, App2, App3. The Apps use files that have the same file extensions.
Your company uses Windows Information Protection (WIP). WIP has the following configurations:
✑ Windows Information Protection mode: Silent
✑ Protected apps: App1
✑ Exempt apps: App2
From App1, you create a file named File1.
What is the effect of the configurations? To answer, select the appropriate options in the answer area.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Exempt apps: These apps are exempt from this policy and can access corporate data without restrictions.
Windows Information Protection mode: Silent: WIP runs silently, logging inappropriate data sharing, without stopping anything that would've been prompted for employee interaction while in Allow overrides mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still stopped.
Reference:
https://docs.microsoft.com/en-us/intune/apps/windows-information-protection-policy-create https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
saasaa
Highly Voted 5 years, 4 months ago
Silent mode detects and logs inappropriate actions, but doesn't block them. SO, for the first selection, App1, App2 and App3 can be used to open the file. Its scope doesn't include App1 because the File1 is created on App1. Apps2 is also not included because it's exempted. So, the attempt to open the file, which is to be logged, is only the one from App3. This is mu understanding. Please correct me if I'm wrong.
upvoted 70 times
Rosco
5 years, 1 month ago
I think everyone is wrong. I believe inappropriate actions "sharing data" ie. cut and paste are allowed but logged in Silent. Opening in an unprotected app would be an unallowed action and would still be blocked in silent mode I believe. no? https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/protect-enterprise-data-using-wip
upvoted 6 times
...
STFN2019
4 years, 11 months ago
Perfect. Box1: all apps, Box2: App3 only
upvoted 20 times
...
...
sailerjerry
Highly Voted 5 years, 5 months ago
You can open an app from app1,2 or 3 as it is in silent mode. This will only log, not alert or block user. Log will be generated on app 3 only. It wont log on protected app or exempt app.
upvoted 30 times
...
donb21
Most Recent 2 years, 10 months ago
Box 1 should be 1,2,3 and Box2 should be only App3
upvoted 2 times
...
DenisRossi
3 years ago
MS-101 question
upvoted 3 times
...
Eggsamine
3 years, 8 months ago
Has anyone had this show up in the MS-100 exam as it is an MS-101 question?
upvoted 3 times
Razuli
2 years, 5 months ago
Yeah I did
upvoted 2 times
...
...
MomoLomo
3 years, 10 months ago
So user can open file from 1.2.3 cause it's in silent mode and agree on that as for the logs https://docs.microsoft.com/en-us/mem/intune/apps/windows-information-protection-policy-create When working with WIP-enabled apps and WIP-unknown apps, we recommend that you start with Silent or Allow Overrides while verifying with a small group that you have the right apps on your protected apps list. After you're done, you can change to your final enforcement policy, Block. WIP runs silently, logging inappropriate data sharing, without blocking anything that would have been prompted for employee interaction while in Allow Override mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still stopped. it says to make sure you have the right apps on your protect list and silent logs contain inappropriate data sharing which means apps that are blocked and unknown aka not on the protect list
upvoted 2 times
...
Aysan
4 years, 1 month ago
Ms-101question
upvoted 4 times
...
Mr01z0
4 years, 1 month ago
Per Microsoft: "Silent. Windows Information Protection runs silently. It logs inappropriate data sharing without blocking anything that would’ve prompted employee interaction in Allow Overrides mode. Unallowed actions, like apps trying to access a network resource or Windows Information Protection protected data, are allowed but audited. Silent mode is good choice for more open IT environments or where large groups of users, like testers or application developers, have legitimate reasons to perform actions that might be blocked under other circumstances. Silent mode is also good to use when an organization is thinking about implementing Allow Overrides or Hide Overrides mode, because the event log will offer information about the number of overridden or blocked events that implementing Windows Information Protection will cause." this phrase "the event log will offer information about the number of overridden or blocked events" suggests that the exempt app does not get logged at all. Only events where a block would occur or a user overrides the block will be logged.
upvoted 3 times
...
init2winit
4 years, 2 months ago
is this on the test?
upvoted 1 times
...
YounesDump
4 years, 3 months ago
i think that skajam66 is right ;
upvoted 1 times
...
Parvezg
4 years, 4 months ago
I believe it should be only App1 and App2 can open because App3 is out of protection/exemption so not allowed to open any file. And, logs will be generated for such type of actions for App1 only because that is the protected app.
upvoted 2 times
...
Duyons
4 years, 4 months ago
MS-101 question - MS-100 does not cover WIP
upvoted 6 times
Turak64
3 years, 9 months ago
it shoudn't, but this is a MS exam... they tend to pull this sort of thing
upvoted 2 times
...
Razuli
2 years, 5 months ago
No it doesn’t cover this like most of the material in the ms100 but it’s definitely in there a I seen it
upvoted 1 times
...
...
Takloy
4 years, 6 months ago
so what's the correct answer?
upvoted 1 times
...
mkoprivnj
4 years, 6 months ago
1, 2, 3 & 2, 3.
upvoted 4 times
...
palani75
4 years, 8 months ago
You Can open File1 from App1,App2, and App3 An action will be logged when you attempt to open File1 from: App3 only WIP Silent mode will not block any action but will log inappropriate data sharing, giving you the opportunity to monitor your WIP enabled apps but also apps you did not add to your WIP policy.
upvoted 10 times
...
Jayatheerthan
4 years, 8 months ago
Silent mode. The Windows Information Protection-protected work files can be moved or copied to the user’s personal local OneDrive sync folder, the files will sync without issue, and an audit log event will be generated.
upvoted 1 times
...
LucWave
4 years, 9 months ago
WIP runs silently, logging inappropriate data sharing, without stopping anything that would’ve been prompted for employee interaction while in Allow overrides mode. Unallowed actions, like apps inappropriately trying to access a network resource or WIP-protected data, are still stopped. Unallowed actions in silent are blocked so I think App 3 can't access the file. For the log, i'm not sure that events for "exempt app" are logged so if someone can provide a link with the answer, it would be greatly appreciated!
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...