Microsoft 365 Administrator Expert MS-102 Practice Question
Your organization deploys Microsoft Purview data loss prevention (DLP) policies to Exchange Online, SharePoint Online, OneDrive for Business, Microsoft Teams, and Windows 11 endpoints. Security Operations Center (SOC) analysts already work day-to-day in the Microsoft 365 Defender portal (https://security.microsoft.com/) to investigate endpoint, e-mail, and identity incidents. You must enable these analysts to triage and remediate DLP alerts with the following requirements:
View DLP alerts automatically correlated into incidents together with other security signals.
Reassign incidents, add tags, and start a Microsoft Teams chat with stakeholders directly from the alert.
Run advanced hunting queries that pivot on DLP alert metadata (for example, file name and policy ID). Which combination of portal and role assignment meets the requirements while following the principle of least privilege?
Assign the Data Loss Prevention Administrator role and instruct the analysts to use the Microsoft Purview compliance portal.
Assign the Security Operator role and instruct the analysts to use the Microsoft 365 Defender portal.
Assign the Global Reader role and instruct the analysts to use the Microsoft 365 security center.
Assign the Compliance Data Administrator role and instruct the analysts to use the Microsoft Purview compliance portal.
DLP alerts are surfaced in the Microsoft 365 Defender portal where they are automatically correlated with other signals into incidents. In that portal, analysts can open an alert, view evidence such as file paths and policy matches, launch a Teams chat by using the Collaborate tab, tag or assign the incident, and run advanced hunting queries that include the DLP schema tables. The Security Operator built-in Azure AD role grants permission to manage (but not configure) incidents and alerts in Microsoft 365 Defender, meeting the least-privilege requirement. The Data Loss Prevention Administrator and Compliance Data Administrator roles grant access in the Microsoft Purview compliance portal, which does not provide incident correlation, Teams collaboration, or advanced hunting. Global Reader is read-only and cannot reassign or remediate incidents.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Microsoft Purview's role in DLP policies?
Open an interactive chat with Bash
What is the role of the Security Operator in the Microsoft 365 Defender portal?
Open an interactive chat with Bash
What is advanced hunting in Microsoft 365 Defender, and how does it assist with DLP alerts?
Open an interactive chat with Bash
Microsoft 365 Administrator Expert MS-102
Manage compliance by using Microsoft Purview
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .