Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A global organization uses Microsoft 365 services extensively. The security team needs to implement a policy that automatically encrypts all outbound emails containing sensitive financial data (e.g., credit card numbers, bank account details) when sent to external recipients. This encryption should prevent unauthorized viewing by anyone other than the intended recipient. Which Microsoft Defender for Office 365 (MDO) capability should the security team configure?
- ASafe Attachments policy
- BData Loss Prevention (DLP) policy with encryption actions
- CAnti-phishing policy
- DSafe Links policy
Show answer & explanationAnswer & explanation
Correct answer: B. Data Loss Prevention (DLP) policy with encryption actions
Data Loss Prevention (DLP) policies in Microsoft 365 (which includes MDO capabilities) are designed to identify sensitive information and apply actions like encryption or blocking based on policy rules. Configuring a DLP policy to detect financial data and automatically encrypt outbound emails to external recipients directly fulfills this requirement.
Why the other options are wrong
- A. Safe Attachments protects against malicious attachments by sandboxing them, not encrypting sensitive data in emails.
- C. Anti-phishing policies detect and prevent phishing attacks, not encrypt sensitive data in legitimate emails.
- D. Safe Links protects against malicious URLs in emails, not sensitive data encryption.
MDO DLP with Encryption
Microsoft Defender for Office 365 (via Microsoft 365 DLP) allows creating policies to detect sensitive information in emails and automatically apply encryption when specific conditions, such as external recipients, are met.
- Identifies sensitive information types (SITs).
- Applies protective actions like encryption.
- Crucial for regulatory compliance and data protection.
Memory trick: DLP is the data's bodyguard, encrypting secrets before they leave the building.