Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A global organization uses Microsoft 365 and needs to implement data loss prevention (DLP) across its email communications to prevent sensitive information, such as credit card numbers and national identification numbers, from being accidentally or maliciously shared outside the organization. The DLP policies must be applied specifically to Exchange Online. Which Microsoft Defender XDR component is used to configure and manage these types of DLP policies?

  1. AMicrosoft Defender for Cloud Apps
  2. BMicrosoft Defender for Endpoint
  3. CMicrosoft Defender for Office 365
  4. DMicrosoft Defender for Identity
Show answer & explanation

Correct answer: C. Microsoft Defender for Office 365

Microsoft Defender for Office 365, which includes Exchange Online Protection (EOP) and advanced features, is the component responsible for configuring and managing Data Loss Prevention (DLP) policies specifically for email (Exchange Online) and other Microsoft 365 services like SharePoint and OneDrive.

Why the other options are wrong

  • A. Defender for Cloud Apps primarily focuses on SaaS application usage and data at rest/in transit within those apps, but MDO is the primary for Exchange Online email DLP.
  • B. Defender for Endpoint focuses on device-level protection, not email DLP.
  • D. Defender for Identity protects on-premises Active Directory identities, not email content.

Data Loss Prevention (DLP) in MDO

Policies configured within Microsoft Defender for Office 365 (and the Microsoft Purview compliance portal) to identify, monitor, and protect sensitive information in email, SharePoint, and OneDrive.

  • Prevents accidental or malicious sharing of sensitive data.
  • Uses sensitive info types (SITs) to detect data.
  • Can apply actions like block, encrypt, or notify.

Memory trick: MDO Secures Sensitive Email Content.

More Mitigate threats using Microsoft Defender XDR questions