Describe security management capabilities of Azure
Objective azure.security-management sits in Describe capabilities of Microsoft security solutions, which carries 38% of the SCI Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.
Objective title verbatim from the official objectives. Microsoft Azure exam page ↗
A worked example
Shown solved, with the whole explanation open: this is what every question here carries.
A compliance administrator wants a graphical view of which SharePoint files carry a sensitivity or retention label, and how users are interacting with those files. Which Microsoft Purview capability supplies this view?
The concept
Microsoft Purview provides several distinct capabilities for identifying and reporting on sensitive data, each serving a different purpose within information protection.
Why this answer
Data classification gives a graphical identification of items that have a sensitivity label, a retention label, or have been otherwise classified, along with the actions users are taking on them, matching the administrator's need for a visibility report.
- ASensitivity labels apply protection actions like encryption and markings, but they do not themselves produce the graphical usage report the administrator wants.
- BTrainable classifiers are a method for identifying sensitive items by example, used to build classification, not to display a report of labeled items.
- Correct: this capability provides the graphical view of labeled and classified items and user activity.
- DSensitive information types are a detection method using regex or functions, feeding classification rather than producing the visibility report itself.
- EData Loss Prevention enforces policy actions on sensitive content but is not the reporting capability that shows labeled items and their usage.
Now you: objective azure.security-management questions
No account needed. The explanation opens when you answer.
Sample question 1 of 3
A security team builds a Microsoft Purview data loss prevention policy that blocks sharing of documents containing driver's license numbers, but lets users override the block with a justification. Which DLP policy element controls this behavior?
Sample question 2 of 3
Defender for Endpoint detects a malicious file on a user's device. Defender for Office 365 immediately scans and removes the same file from every mailbox across the organization without manual action. Which Microsoft Defender XDR feature describes this behavior?
Sample question 3 of 3
A compliance administrator needs a Microsoft Purview capability that applies encryption, access restrictions, and visual markings while also interacting with other Purview solutions. Which capability serves this foundational role?
Full SCI Fundamentals question bank coming
We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.
Read the sources
These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.