exam questions

Exam MS-101 All Questions

View all questions & answers for the MS-101 exam

Exam MS-101 topic 3 question 21 discussion

Actual exam question from Microsoft's MS-101
Question #: 21
Topic #: 3
[All MS-101 Questions]

HOTSPOT -
Your company has a Microsoft 365 subscription that uses an Azure Active Directory (Azure AD) tenant named contoso.com. The tenant contains the users shown in the following table.

You create a retention label named Label1 that has the following configurations:
✑ Retains content for five years
✑ Automatically deletes all content that is older than five years
You turn on Auto labeling for Label1 by using a policy named Policy1. Policy1 has the following configurations:
✑ Applies to content that contains the word Merger
✑ Specifies the OneDrive accounts and SharePoint sites locations
You run the following command.
Set-RetentionCompliancePolicy Policy1 `"RestrictiveRetention $true
-Force
For each of the following statements, select Yes if the statement is true. Otherwise, select No.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Reference:
https://docs.microsoft.com/en-us/powershell/module/exchange/policy-and-compliance-retention/set-retentioncompliancepolicy?view=exchange-ps

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
LoremanReturns
Highly Voted 3 years, 11 months ago
Answers are correct: YNY https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide Global Admins are members of Organization Management role in Exchange Online, which have the Compliance Admin right. So a Global Admin is able to change the policy
upvoted 13 times
...
donathon
Highly Voted 4 years ago
N: Compliance Data Admin does not have sufficient privilege. N: You cannot remove location once the preservation lock is in place. Y: You can still add. https://docs.microsoft.com/en-us/microsoft-365/compliance/retention-preservation-lock?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/compliance/retention-preservation-lock?view=o365-worldwide
upvoted 8 times
ccadenasa
3 years, 7 months ago
Compliance data admin can manage retention policies, retention labels, and retention label policies. Based on this, the answer is Yes,No,Yes. https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide The Restriction value set to true: "Preservation Lock is enabled for the policy. No one (including an administrator) can turn off the policy or make it less restrictive. After a policy has been locked, no one can turn off or disable it, or remove content from the policy. And it's not possible to modify or delete content that's subject to the policy during the retention period. The only way that you can modify the retention policy are by adding content to it, or extending its duration. A locked policy can be increased or extended, but it can't be reduced, disabled, or turned off.
upvoted 2 times
...
kiketxu
3 years, 12 months ago
I disagree with CDA does not have privileges. Look at this both and about "retention management" permission. Both CD and CDA have this allowed. https://docs.microsoft.com/en-us/microsoft-365/compliance/get-started-with-retention?view=o365-worldwide#permissions-required-to-create-and-manage-retention-policies-and-retention-labels https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/permissions-in-the-security-and-compliance-center?view=o365-worldwide#role-groups-in-the-security--compliance-center To my view, it's a YES, NO, YES. You cannot remove location due the lock. You can still add a word as this can't be considered LESS restrictive.
upvoted 20 times
Riaan_Haasbroek
3 years, 3 months ago
Definitely the right answer no doubt about it
upvoted 2 times
...
...
...
Amir1909
Most Recent 1 year, 4 months ago
- Yes - No - No
upvoted 1 times
...
Meebler
2 years, 3 months ago
Based on the information provided, the updated answers to the questions are: A) Yes, User1 can add exchange email as a location to Policy1, as they have the Compliance Data Administrator role which allows them to manage settings for device management, data protection, data loss prevention, reports, and preservation. B) Yes, User2 can remove SharePoint sites from Policy1, as they have the Global Administrator role which grants them permissions to manage all aspects of Azure AD and Microsoft 365 services, including SharePoint. C) Yes, User2 can add the word "Acquisition" to Policy1, as they are a Global Administrator and have the necessary permissions to manage compliance policies. However, the current configuration of Policy1 only applies to content that contains the word "Merger," so adding a different keyword would require adjusting the policy configurations accordingly.
upvoted 2 times
Meebler
2 years, 3 months ago
answer B as "yes" because User2 is a Global Administrator, which is the highest level of administrative privilege in Microsoft 365. Global Administrators have access to all administrative features and functions, including the ability to modify policies and settings. Since Policy1 is a retention policy, which is a feature of SharePoint and OneDrive for Business, User2 should have the ability to modify it and remove SharePoint sites from it. While it is possible for the organization to restrict User2's ability to modify policies and settings through Azure AD Privileged Identity Management (PIM) or other access controls, this information is not provided in the scenario. Therefore, based solely on the information provided, it is reasonable to assume that User2 has the necessary permissions to modify Policy1 and remove SharePoint sites from it.
upvoted 1 times
...
EsamiTopici
2 years, 3 months ago
the second is no because: Set-RetentionCompliancePolicy Policy1 `"RestrictiveRetention $true
upvoted 2 times
...
...
Contactfornitish
2 years, 10 months ago
On exam on 13 aug'22
upvoted 5 times
...
venwaik
3 years, 1 month ago
Preservation Lock locks a retention policy or retention label policy so that no one—including a global admin—can turn off the policy, delete the policy, or make it less restrictive. This configuration might be needed for regulatory requirements and can help safeguard against rogue administrators. To make it short. With "-RestrictiveRetention" you can only edit the policy to ADD content to it. See also; After a policy has been locked, no one can turn off or disable it, or remove content from the policy. And it's not possible to modify or delete content that's subject to the policy during the retention period. The only way that you can modify the retention policy are by adding content to it, or extending its duration. A locked policy can be increased or extended, but it can't be reduced, disabled, or turned off. Link; https://docs.microsoft.com/en-us/powershell/module/exchange/set-retentioncompliancepolicy?view=exchange-ps
upvoted 6 times
...
itmaster
3 years, 2 months ago
https://docs.microsoft.com/en-us/powershell/module/exchange/set-retentioncompliancepolicy?view=exchange-ps#:~:text=%24true%3A%20Preservation%20Lock%20is%20enabled%20for%20the%20policy.%20No%20one%20(including%20an%20administrator)%20can%20turn%20off%20the%20policy%20or%20make%20it%20less%20restrictive
upvoted 1 times
...
ajna_
3 years, 3 months ago
N | N | Y
upvoted 1 times
...
Domza
3 years, 9 months ago
When Policy is locked. Add or extend
upvoted 3 times
...
agayam
3 years, 10 months ago
You can add new locations but not remove them. Am I correct?
upvoted 6 times
...
AnoniMouse
4 years ago
[or make it less restrictive], I was going for YES NO NO, but since user2 is a global admin and ADDING something doesn't make it LESS restrictive, then the last answer should be YES? Am I correct?
upvoted 2 times
...
MSGrady
4 years, 2 months ago
Confused. How is user 2 who is a "Global Admin" not able to remove SharePoint sites from Policy1?
upvoted 2 times
IgorMatic
4 years, 2 months ago
Here you can find explanation: https://docs.microsoft.com/en-us/microsoft-365/compliance/retention-preservation-lock?view=o365-worldwide Preservation Lock locks a retention policy or retention label policy so that no one—including a global admin—can turn off the policy, delete the policy, or make it less restrictive. This configuration might be needed for regulatory requirements and can help safeguard against rogue administrators.
upvoted 17 times
MSGrady
4 years, 2 months ago
Thank You.... helps to do the homework
upvoted 4 times
...
...
Domza
3 years, 9 months ago
GA would need to assign Compliance role in order to make changes. Plus, there is lock on it.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...