exam questions

Exam MS-203 All Questions

View all questions & answers for the MS-203 exam

Exam MS-203 topic 4 question 22 discussion

Actual exam question from Microsoft's MS-203
Question #: 22
Topic #: 4
[All MS-203 Questions]

Note: This question is part of a series of questions that present the same scenario. Each question in the series contains a unique solution that might meet the stated goals. Some question sets might have more than one correct solution, while others might not have a correct solution.
After you answer a question in this section, you will NOT be able to return to it. As a result, these questions will not appear in the review screen.
You have a Microsoft Exchange Server 2019 hybrid deployment. All user mailboxes are hosted in Microsoft 365. All outbound SMTP email is routed through the on-premises Exchange organization.
A corporate security policy requires that you must prevent credit card numbers from being sent to internet recipients by using email.
You need to configure the deployment to meet the security policy requirement.
Solution: From the Exchange organization, you create a data loss prevention (DLP) policy.
Does this meet the goal?

  • A. Yes
  • B. No
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Ronnie123
Highly Voted 3 years, 9 months ago
B. No, in hybrid DLP is only applied in EXO
upvoted 5 times
slimeycat
3 years, 8 months ago
Agreed. https://docs.microsoft.com/en-us/exchange/policy-and-compliance/data-loss-prevention/data-loss-prevention?view=exchserver-2019 "In hybrid environments where some mailboxes are in on-premises Exchange and some are in Exchange Online, DLP policies are only applied in Exchange Online. Messages that are sent between on-premises users don't have DLP policies applied, because the messages don't leave the on-premises environment."
upvoted 1 times
Jfran
3 years, 7 months ago
In this scenario it says that ALL mailboxes are in EXO not some in EXO and others in the organization
upvoted 1 times
...
3x4m1n4t0r
3 years, 8 months ago
But that just mean it's not applied between internal users. The question said, it must prevent sending it to "internet recipients" and onPrem DLP policies are applied to them. Since all traffic is routed through onprem, it should be possible like that.
upvoted 3 times
...
...
...
ServerBrain
Most Recent 9 months, 3 weeks ago
Selected Answer: B
How do create a DLP policy from Exchange??
upvoted 1 times
...
kazaki
2 years, 4 months ago
Selected Answer: B
From compliance center
upvoted 1 times
...
maxustermann
2 years, 6 months ago
Selected Answer: B
All mailboxes are online so only DLP from exchange online will take affact
upvoted 1 times
...
SCT
2 years, 8 months ago
Correct, All outbound SMTP email is routed through the on-premises Exchange organization, so you need DLP Solution on-prem.
upvoted 2 times
...
J4U
2 years, 10 months ago
All mailboxes are hosted in ExO. So creating a DLP policy in onprem makes no sense for internal emails as they are routed within ExO. Answer is No.
upvoted 1 times
J4U
2 years, 10 months ago
Please ignore me. I misread it as internal instead of internet. All the emails going out from Onprem server should get the DLP policy applied.
upvoted 3 times
...
...
Cbruce
3 years ago
Answer should be No. In hybrid environments where some mailboxes are in on-premises Exchange and some are in Exchange Online, DLP policies are only applied in Exchange Online. Messages that are sent between on-premises users don't have DLP policies applied, because the messages don't leave the on-premises environment. https://docs.microsoft.com/en-us/exchange/policy-and-compliance/data-loss-prevention/data-loss-prevention
upvoted 2 times
...
fred
3 years, 5 months ago
remember that the question said "from the exchange organisation" and not from O365. On EAC of exchange 2019 you cannot do a dlp policy, the answer is no
upvoted 3 times
...
Sara_Mo
3 years, 5 months ago
A With a DLP policy, you can: Identify sensitive information across many locations, such as Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. For example, you can identify any document containing a credit card number that's stored in any OneDrive for Business site, or you can monitor just the OneDrive sites of specific people. Prevent the accidental sharing of sensitive information. https://docs.microsoft.com/en-us/microsoft-365/compliance/data-loss-prevention-policies?view=o365-worldwide
upvoted 2 times
...
m2L
3 years, 6 months ago
According to this link, the answer is correct https://docs.microsoft.com/en-us/exchange/transport-routing
upvoted 1 times
...
m2L
3 years, 6 months ago
According to this link answer is correct
upvoted 1 times
...
Jfran
3 years, 7 months ago
DLP policies should be applied to the INTERNET RECIPIENTS and all traffic is ROUTED TO on premises so I think they can be configured in both BEFORE it goes to the internet
upvoted 1 times
Jfran
3 years, 7 months ago
I have changed my mind and agree with cbytes. Although it may be possible to do it, there is no sense to configure DLP policies on-premises when aBll the mailboxes are in EXO. Also, the traffic to be routed to on-premises will go through the internet. So I would choose B
upvoted 1 times
...
...
cbytes
3 years, 7 months ago
It says that all user mailboxes are in 365. On-prem does not have DLPs, but since the mailboxes are in 365 the mail flows from 365 to on-prem. Thus, all mail goes through the DLP configured in 365.
upvoted 3 times
donathon
3 years, 7 months ago
https://docs.microsoft.com/en-us/exchange/policy-and-compliance/data-loss-prevention/data-loss-prevention?view=exchserver-2019 >> Exchange 2019 does have DLP policies.
upvoted 5 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...