Microsoft Certified Information Protection Administrator Associate · Free Practice Question Medium
Question 2
A compliance administrator recently created several data loss prevention (DLP) policies.
After the policies are created, you receive a higher than expected volume of DLP alerts.
You need to identify which rules are generating the alerts.
Which DLP report should you use?
- A A. Third-party DLP policy matches
- B C. DLP incidents
- C B. DLP policy matches
- D D. False positive and override
Reveal correct answer
Correct answer: C
Explanation
"The policy matches report is better for identifying matches with specific rules and fine tuning DLP policies. The incidents report is better for identifying specific pieces of content that are problematic for your DLP policies." https://docs.microsoft.com/en-us/microsoft-365/compliance/view-the-dlp-reports?view=o365-worldwideDiscussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
