Microsoft 365 Administrator Expert MS-102 Practice Question
You are rolling out Endpoint DLP to Windows 10/11 devices that have the MDE sensor onboarded. A new policy must block users from copying files that are labeled Highly Confidential to any removable storage except a fleet of company-issued IronKey USB drives whose vendor and product IDs are known. You configure a policy with the location Devices, add a condition for the Highly Confidential sensitivity label, and select the activity Copy to removable storage with the action Block with override. In testing, the policy also blocks copying to the IronKey drives. You must allow the IronKey drives while still blocking all other USB storage devices.
Which Endpoint DLP configuration should you modify to meet the requirement?
Add the IronKey hardware IDs to an exception rule that uses the File path group type.
Define a Cloud content inspection location for the IronKey drives and assign it to a policy exception.
Enable advanced classification mode and exclude the IronKey drives by adding their drive letters to the file-path exclusion list.
Create a device group of type USB that contains the IronKey vendor and product IDs, mark the group as Privileged, and reference it as an exception in the policy.
Endpoint DLP can treat specific removable-storage hardware as trusted by placing the hardware IDs into a USB device group that is marked as Privileged (trusted). After the group is created, it can be added to a DLP policy as an exception so the policy's restrictions do not apply to those devices. File-path exclusions or drive-letter exclusions do not reliably distinguish individual USB drives, and there is no Cloud content inspection location for removable media. Therefore, creating a USB device group that contains the IronKey vendor and product IDs and then referencing that group as an exception in the policy is the correct approach, while the other options either do not exist or cannot target specific USB hardware.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Endpoint DLP?
Open an interactive chat with Bash
What are USB device groups in Endpoint DLP?
Open an interactive chat with Bash
Why can't file-path exclusions or drive-letter exclusions target specific USB hardware?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage compliance by using Microsoft Purview
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .