Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security team needs to implement a policy in Microsoft Defender for Office 365 to prevent users from accidentally or maliciously sharing sensitive information, such as credit card numbers or social security numbers, via email. This policy should scan email content (subject, body, and attachments) for specific data patterns and, if found, block the email from being sent. Which type of policy should they configure?
- ASafe Links policy
- BAnti-phishing policy
- CData Loss Prevention (DLP) policy
- DAnti-spam policy
Show answer & explanationAnswer & explanation
Correct answer: C. Data Loss Prevention (DLP) policy
Data Loss Prevention (DLP) policies in Microsoft 365 are designed to identify, monitor, and protect sensitive information across various services, including email. They can be configured to detect specific sensitive information types (like credit card numbers) in email content and then block the email from being sent, thus preventing data exfiltration.
Why the other options are wrong
- A. Safe Links policies protect against malicious URLs, not sensitive data in email content.
- B. Anti-phishing policies protect against phishing attempts, not the accidental sharing of sensitive data.
- D. Anti-spam policies filter unwanted bulk email, not sensitive data content.
Microsoft 365 DLP Policy
A Data Loss Prevention (DLP) policy in Microsoft 365 that identifies, monitors, and protects sensitive information across various Microsoft 365 services, including Exchange Online, SharePoint Online, and OneDrive for Business.
- Detects sensitive information types (SITs) like credit card numbers.
- Can be configured to block, notify, or encrypt content.
- Helps comply with regulatory requirements.
Memory trick: DLP stops sensitive data from slipping out.