exam questions

Exam MS-203 All Questions

View all questions & answers for the MS-203 exam

Exam MS-203 topic 2 question 16 discussion

Actual exam question from Microsoft's MS-203
Question #: 16
Topic #: 2
[All MS-203 Questions]

You have a Microsoft Exchange Online tenant.
All users use an email address suffix of @contoso.com.
You need to ensure that all the email messages sent to users who use an email address suffix of @fabrikam.com are encrypted automatically. The solution must ensure that the messages can be inspected for data loss prevention (DLP) rules before they are encrypted.
What should you create?

  • A. an Outbound connector
  • B. a safe attachments policy
  • C. a remote domain
  • D. a mail flow rule
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Seph1981
Highly Voted 2 years, 11 months ago
Correct Answer is D, Mail Flow Rule. A connector dont encrypt messages (message content), just the connection itself (TLS).
upvoted 23 times
Cbruce
2 years, 10 months ago
Yes, D is correct. A connector will not encrypt messages.
upvoted 4 times
...
VictorSaiz
2 years, 8 months ago
Disagree: "You can create a connector to enforce encryption via transport layer security (TLS)". Reference: https://docs.microsoft.com/en-us/exchange/mail-flow-best-practices/use-connectors-to-configure-mail-flow/set-up-connectors-for-secure-mail-flow-with-a-partner
upvoted 5 times
MalikShaikh
1 year, 6 months ago
I disagree to you. TLS encryption is the connection encryption. Question is about email encryption which can be done by Transport rule only not the Outbound connector.
upvoted 3 times
...
...
...
J4U
Highly Voted 2 years, 7 months ago
Outbound connector can encrypt emails using "Always use Transport Layer Security (TLS) to secure the connection (recommended)". All Exchange mail flow rules are processed first, and then the DLP rules from the Security & Compliance Center are processed. https://docs.microsoft.com/en-us/microsoft-365/compliance/how-dlp-works-between-admin-centers?view=o365-worldwide
upvoted 9 times
J4U
2 years, 7 months ago
So based on the question, Outbound connector is correct.
upvoted 4 times
...
Harshul
2 years, 4 months ago
Good explaination!
upvoted 2 times
...
...
Amir1909
Most Recent 5 months ago
A is correct
upvoted 1 times
...
Nyamnyam
6 months, 2 weeks ago
Selected Answer: A
Agree that D would be better, especially when it states that messages need to be encrypted (and not specifically in transport). But if I think twice about the requirement that the messages need to be inspected by DLP I come back to answer A. This is because DLP mail flow rule is already in place - most probably for all domains, so you cannot edit this one. Instead you'll create a new one for Fabrikam. And here comes the catch: "In the transport pipeline, mail flow rules evaluate and act on message before DLP rules." https://learn.microsoft.com/en-us/exchange/security-and-compliance/mail-flow-rules/configuration-best-practices#dont-chain-dlp-rule-actions-and-mail-flow-rule-conditions
upvoted 1 times
...
ServerBrain
6 months, 3 weeks ago
Selected Answer: D
The question asks for the solution to satisfy two requirements: messages to go through DLP rules before Encryption. How do you do this using a connector?
upvoted 1 times
...
Mshaty
10 months, 1 week ago
the link to the reference shows Mail flow rules and these are used to encrypt messages
upvoted 1 times
...
Forkbeard
1 year, 3 months ago
Selected Answer: D
You can create DLP policies in the Microsoft Purview compliance portal, but also in the Exchange admin center. DLP policies from the Admin center resemble those in Purview but have more options specific to handling mail. Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/how-dlp-works-between-admin-centers?view=o365-worldwide The order in which the rules are processed: 1. DLP + mail flow rules from Exchange 2. DLP from Purview Within the Exchange admin center you can create a data loss prevention policy (tested it with one that scans for mail containing credit card numbers), lets say give it prio 3, and then create a mail flow rule that encrypts mail to fabrikam.com or whatever and give it prio 4. This will meet the requirement of encrypting the message itself while allowing for DLP before the encryption. Based on this the answer should be D. As stated by more people here, an outbound connector can only encrypt the connection, not the message itself; therefor A is wrong.
upvoted 2 times
...
EGZAMSY
1 year, 6 months ago
Selected Answer: A
Correct Answer is A
upvoted 1 times
...
PawelNotts
1 year, 7 months ago
Selected Answer: D
You can create a mail flow rule which encrypts based on DLP inspection results: https://learn.microsoft.com/en-us/microsoft-365/compliance/ome-sensitive-info-types?view=o365-worldwide Example mail flow rule created with PowerShell when you want to encrypt a message if the email or attachment contains sensitive information: Set-IRMConfiguration -DecryptAttachmentForEncryptOnly $true New-TransportRule -Name "Encrypt outbound sensitive emails (out of box rule)" -SentToScope NotInOrganization -ApplyRightsProtectionTemplate "Encrypt" -MessageContainsDataClassifications @(@{Name="ABA Routing Number"; minCount="1"},@{Name="Credit Card Number"; minCount="1"},@{Name="Drug Enforcement Agency (DEA) Number"; minCount="1"},@{Name="U.S. / U.K. Passport Number"; minCount="1"},@{Name="U.S. Bank Account Number"; minCount="1"},@{Name="U.S. Individual Taxpayer Identification Number (ITIN)"; minCount="1"},@{Name="U.S. Social Security Number (SSN)"; minCount="1"}) -SenderNotificationType "NotifyOnly"
upvoted 1 times
...
Solozero
1 year, 11 months ago
Selected Answer: D
D is the correct answer
upvoted 2 times
...
Kodeblack
2 years ago
ON exam - 4/18/2022 All 3 case studies were also on exam
upvoted 1 times
...
AyKy
2 years, 2 months ago
I think this is tricky verbiage question. It doesn't say ome or rms encryption. Note if you use mail flow rules and encrypt you won't be able to inspect messages for dlp.
upvoted 4 times
...
maxustermann
2 years, 2 months ago
Selected Answer: D
Only a mailflow rule can encrypt a message itself, a connector can encrypt the connection. So answer is D
upvoted 4 times
...
lss83
2 years, 3 months ago
Selected Answer: D
Connectors encrypt the traffic betwen endpoints only on the transport layer not the message itself. Based on Microsoft documentation it must be D. https://docs.microsoft.com/en-us/microsoft-365/compliance/define-mail-flow-rules-to-encrypt-email?view=o365-worldwide
upvoted 2 times
...
Laxreasoning
2 years, 3 months ago
"However, if you forward a message that was sent through a TLS-encrypted connection, that message isn't necessarily encrypted. TLS doesn't encrypt the message, just the connection." So yes connector will encrypt it during transport but it will not leave it encrypted at destination like mail flow encryption setting would
upvoted 1 times
...
gta33578
2 years, 5 months ago
on exam 11-27-21
upvoted 5 times
...
Domza
2 years, 6 months ago
Little hint. Microsoft Exchange Online - you don't configure outbound setting. ~Server Exchange does~ Read the question, its say Exchange Online. Very little configuration on Connectors, there is no security or encryption. Transport Rule OR Mail Flow Rule there you have encryption and TLS. With Love~
upvoted 2 times
Domza
2 years, 6 months ago
By the way, provided link says Mail flow rules or transport rule lol
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago