exam questions

Exam SC-400 All Questions

View all questions & answers for the SC-400 exam

Exam SC-400 topic 1 question 55 discussion

Actual exam question from Microsoft's SC-400
Question #: 55
Topic #: 1
[All SC-400 Questions]

You have a Microsoft 365 tenant that has data loss prevention (DLP) policies.

You need to review DLP policy matches for the tenant.

What should you use?

  • A. Content explorer
  • B. Activity explorer
  • C. Compliance Manager
  • D. records management events
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TC1Labs
6 months, 4 weeks ago
Activity Explorer is the right answer
upvoted 2 times
...
SDiwan
1 year, 1 month ago
Selected Answer: B
Activity Explorer is the right answer. Content Explorer is Data Classification feature and not DLP feature.
upvoted 2 times
...
emartiy
1 year, 2 months ago
Selected Answer: B
Correct- B- In addition, using Endpoint data loss prevention (DLP), **Activity explorer** gathers **DLP policy matches** events from Exchange, SharePoint, OneDrive, Teams Chat and Channel, on-premises SharePoint folders and libraries, on-premises file shares, and devices running Windows 10, Windows 11, and any of the three most recent major macOS versions. Ref: https://learn.microsoft.com/en-us/purview/data-classification-activity-explorer Fouces to words between ( ** ** )
upvoted 4 times
...
Ruslan23
1 year, 2 months ago
Selected Answer: A
To review DLP policy matches for the tenant, you should use the Content Explorer (Option A). The Content Explorer in the Microsoft 365 compliance center allows you to view and manage sensitive information that matches your Data Loss Prevention (DLP) policies. It provides insights into where sensitive information resides in your organization and helps you manage risks associated with this data. Please note that appropriate permissions are required to access the Content Explorer. - Copilot -
upvoted 2 times
Ruslan23
1 year, 1 month ago
Copilot shows you a link of a Microsoft doc, if you search in the page Content Explorer no results are found but Activity Explorer is mentioned, so don't trust Copilot for this question.
upvoted 3 times
Ehernandez
1 year ago
The Activity explorer provides a historical view of activities on your labeled content, collected from the Microsoft 365 unified audit logs. It’s used to monitor what’s being done with your labeled content, such as when a label is applied, changed, or removed. On the other hand, the Content explorer gives you visibility into what content has been discovered and labeled, and where that content is located. It specifically allows you to see the actual content of scanned files that match your DLP policies. This is why Content explorer is the appropriate tool for reviewing DLP policy matches, as it directly shows the content that triggered the DLP policy. Activity explorer is more about the actions taken on the content, rather than the content itself. https://microsoft.github.io/ComplianceCxE/playbooks/teamsdlp/#introduction
upvoted 1 times
Ruslan23
1 year ago
https://learn.microsoft.com/en-us/training/modules/manage-data-loss-prevention-polices/4-use-data-loss-prevention-reports The Activity explorer tab on the DLP page has multiple filters you can use to view DLP events. Use this tool to "review activity" related to content that contains sensitive info or has labels applied, such as what labels were changed, files were modified, and matched a rule.
upvoted 1 times
...
...
...
...
Kodoi
1 year, 2 months ago
Selected Answer: B
In addition, using Endpoint data loss prevention (DLP), Activity explorer gathers DLP policy matches events from Exchange, SharePoint, OneDrive, Teams Chat and Channel, on-premises SharePoint folders and libraries, on-premises file shares, and devices running Windows 10, Windows 11, and any of the three most recent major macOS versions. https://learn.microsoft.com/en-us/purview/data-classification-activity-explorer
upvoted 1 times
...
Tzu_Hsien
1 year, 2 months ago
I think it is (A)content explorer which can Investigating incidents related to data loss, security, or compliance.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago