Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A global organization uses Microsoft 365. The security team needs to implement a data loss prevention (DLP) policy to prevent sensitive financial reports, identified by specific keywords and patterns, from being shared externally via email. However, internal sharing of these reports should be allowed. Which type of DLP policy in Microsoft Defender for Office 365 should be configured?

  1. AA communication compliance policy.
  2. BAn information barriers policy.
  3. CA safe attachments policy.
  4. DA DLP policy with an 'External Sharing' condition.
Show answer & explanation

Correct answer: D. A DLP policy with an 'External Sharing' condition.

A DLP policy in Microsoft Defender for Office 365 is specifically designed to identify sensitive information (using keywords, patterns, sensitive info types) and enforce rules about its sharing. The 'External Sharing' condition can be used to differentiate between internal and external recipients.

Why the other options are wrong

  • A. Communication compliance policies are primarily for monitoring and reviewing internal communications for regulatory compliance or organizational policies, not for preventing data loss based on content.
  • B. Information barriers policies are used to prevent communication between specific groups of users within an organization, which is not the primary goal here.
  • C. Safe attachments policies protect against malicious attachments by sandboxing them, which is unrelated to preventing sensitive data from being shared.

Microsoft 365 DLP Policy (MDO context)

A Data Loss Prevention (DLP) policy in Microsoft 365 helps prevent sensitive information from being accidentally or intentionally shared outside the organization by identifying, monitoring, and protecting sensitive data across Microsoft 365 services.

  • Identifies sensitive information using built-in or custom sensitive info types, keywords, or patterns.
  • Enforces rules on content based on location (Exchange, SharePoint, OneDrive, Teams).
  • Can block sharing, encrypt content, or notify users/admins.

Memory trick: DLP policies are the 'Do Not Pass Go' for sensitive data to outsiders.

More Mitigate threats using Microsoft Defender XDR questions