AI Bot

SC-500: Information Protection & Encryption Flashcards

Microsoft Cloud and AI Security Engineer Associate SC-500 Flashcards

Study our SC-500: Information Protection & Encryption flashcards for the Microsoft Cloud and AI Security Engineer Associate SC-500 exam with 36+ flashcards. View as flashcards, a searchable table, or as a fun matching game.
Microsoft Cloud and AI Security Engineer Associate SC-500 Course Header Image
FrontBack
How are labels published to users?Via a label policy that targets users groups or entire tenant
How can you audit access to protected documents?Collect logs from Azure AD AIP and Microsoft Purview activity to monitor access and use
How do you apply protection to emails in Exchange Online?Use sensitivity labels or IRM templates or Exchange transport rules to apply encryption and restrictions
How do you protect PDF files with AIP?Use the AIP client or service protections that apply RMS based encryption to PDF content
What are the three main protection actions of a sensitivity label?Encrypt restrict access and apply visual markings
What is a customer managed key CMK?A key that the customer creates and controls typically stored in Key Vault or HSM
What is a protection template?A preconfigured set of rights and encryption settings applied to content
What is a sensitivity label scope?Specifies whether a label applies to documents emails or both
What is a sensitivity label?A metadata tag applied to content to enforce classification retention and protection
What is an HSM Hardware Security Module?A physical device that securely stores and manages cryptographic keys
What is automatic labeling?Using rules or ML based classifiers to apply labels without user intervention
What is Azure Information Protection AIP?A cloud based service to classify label and protect documents and emails
What is Azure Information Protection scanner?A service that discovers on premise files and applies labels and protection
What is Azure Key Vault Managed HSM?A managed HSM service that provides FIPS 140 2 level 3 key protection
What is Bring Your Own Key benefit?Allows control over key lifecycle access revocation and compliance requirements
What is BYOK Bring Your Own Key?Customer supplies and controls the cryptographic keys used to protect cloud data
What is client side encryption?Encrypting data before sending to cloud service using keys controlled by the client
What is Do Not Forward in AIP?A rights setting that prevents recipients from forwarding emails or changing recipients
What is document revocation?A feature that invalidates access to a protected file preventing further opening
What is encryption at rest?Data encryption applied when stored on disk or in persistent storage
What is encryption in transit?Encryption used to protect data while moving between systems typically TLS
What is envelope encryption?A method where a data key encrypts the data and a key encryption key protects the data key
What is IRM Information Rights Management?A set of features that restrict how documents and emails are used after distribution
What is key escrow?Storing backup copies of encryption keys with a trusted party for recoverability
What is key rotation?Regularly replacing encryption keys to limit exposure if a key is compromised
What is key wrapping?Encrypting a data encryption key using a key encryption key for secure storage and transfer
What is offline protection?Allowing protected content to be accessed without continuous network connectivity via cached licenses
What is recommended labeling?Suggesting a label to the user based on detected sensitive content
What is Rights Management Services RMS?A Microsoft technology for applying persistent usage restrictions to content
What is server side encryption?Encryption performed by the service provider after data is received typically transparent to the client
What is the AIP client?An endpoint agent that applies labels protects files and integrates with Office apps
What is the difference between Azure Information Protection and Microsoft Purview sensitivity labels?AIP is legacy client centric Purview provides unified labels across services and newer management
What is the effect of visual markings?Adds headers footers or watermarks to show classification and deter unauthorized use
What is the role of Azure AD in label based protection?Provides identity and access controls used to validate and enforce rights
What is TLS used for in transit encryption?Secures network channels using certificates and symmetric encryption negotiated via handshake
What is View Only permission?Grants read only access and prevents printing and copying in protected content

About the Flashcards

Flashcards for the Microsoft Cloud and AI Security Engineer Associate exam help students review data protection concepts used across Microsoft cloud security and compliance tools. This deck focuses on sensitivity labels, Azure Information Protection, Microsoft Purview labeling, and rights-based controls for documents and email.

Students can use these cards to reinforce key terminology around encryption, key management, label policies, automatic and recommended labeling, and protected content access. The deck also covers practical ideas such as visual markings, Exchange Online protection, document revocation, offline access, and auditing protected files.

Topics covered in this flashcard deck:

  • Sensitivity labels
  • Azure Information Protection
  • Encryption methods
  • Key management
  • Rights management
  • Label policies
Share on...
Follow us on...