Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A global organization uses Microsoft 365 services extensively. The security team needs to configure a policy that automatically encrypts and applies specific sensitivity labels to any email containing financial data (e.g., credit card numbers, bank account numbers) before it leaves the organization. Which Microsoft Defender for Office 365 capability, integrated with Microsoft Purview, is essential for this requirement?
- AAttack simulation training
- BData Loss Prevention (DLP) policies
- CAnti-phishing policies
- DSafe Links
Show answer & explanationAnswer & explanation
Correct answer: B. Data Loss Prevention (DLP) policies
Data Loss Prevention (DLP) policies in Microsoft Defender for Office 365 (integrated with Microsoft Purview Information Protection) are designed to identify, monitor, and automatically protect sensitive information like financial data by applying encryption and sensitivity labels based on predefined rules.
Why the other options are wrong
- A. Attack simulation training is for user education and testing, not for automated data protection.
- C. Anti-phishing policies detect and prevent phishing attempts, not the accidental or malicious exfiltration of sensitive data.
- D. Safe Links protects users from malicious URLs by wrapping them, which is unrelated to sensitive data protection.
DLP Policies (MDO)
Data Loss Prevention (DLP) policies within Microsoft Defender for Office 365, powered by Microsoft Purview, help organizations prevent sensitive information from being accidentally or maliciously shared outside the organization.
- Identifies sensitive information types (SITs).
- Can apply actions like blocking, encrypting, or notifying.
- Integrates with sensitivity labels for persistent protection.
Memory trick: To prevent data leaks, you need a strong DLP policy to seal the email.