Monitor and investigate data and activities Flashcards
What are the functionalities of Content Search? (2)
Search and export
What are the functionalities of eDiscovery Standard? (3)
All of Content Search + case management and legal holds
What are the functionalities of eDiscovery Premium? (8)
All of eDiscovery Standard +
1) Assign case to people outside of your organization
2) legal hold notification
3) advanced indexing
4) tagging
5) analytics e.g., ML-based predictive coding
6) end-to-end workflow
7) OCR
8) review sets
What is the functionality that helps reducing the number of content match to the most useful one?
ML based predictive coding
What are the limitations of Content Search in a hybrid Exchange set-up?
You cannot search on-premise
What is the maximum number of conditions in a Content Search query?
100
What is a Review Set?
A secure Microsoft-provided Azure storage location where the the result of a search can be added. It is possible to export to customer owner location. This is a eDiscovery Premium feature.
What are the two things you need to open exported search results?
1) Export Key 2) eDiscovery Export Tool
What are the search preview limitations? (3)
1000 files or max 100/location (whichever is smaller), Other elements than Emails in Outlook (calendar items, tasks, contacts, folders, lists)
On which standards is the M365 Baseline Score based on? (3)
NIST CSF, ISO and FedRAMP
What can you add in addition to users when adding people that will be able to manage an ediscovery case?
Role groups
How long does it take for a eDiscovery hold to take effect?
Up to 24 hours
When creating a eDiscovery hold, for which location do you need to select the specific locations where it will apply?
Exchange (specific mailboxes) and SharePoint (specific sites)
What are the two options to download a eDiscovery case?
1) Using a Microsoft provided Azure space to export outside of the organization 2) Using eDiscovery Export Tool to download locally
How is the compliance score determined?
It is the sum of the improvement actions scores, which depend on whether the action is mandatory/discretionary and if it is preventive/detective/corrective.
What is the difference between technical and non-technical remediation actions in how they affect the compliance score?
Non-technical are counted only once per Group, while technical are counted once
To which format is data from a Content Search exported?
Email: PST
SharePoint/OneDrive: Native document format
What are the 3 technical requirements to be able to export Content Search?
1) Latest Windows or .NET Framework
2) Edge
3) being connected to the temporary Azure space where the files will be stored temporarily
How long are results of a Content Search stored for?
2 weeks
Why should you protect the Export Key?
Because it can be used by anyone to download search results
What other information does an export from Content Search contains? (4)
1) Summary
2) Errors
3) Skipped items reports
4) trace log about the export process
Note that it is also possible to only download these reports
What are three tips to speed the download of the Content Search exports?
1) Disabled anti-virus scanning
2) Download only to internal drive (no network/external drive or OneDrive)
3) Download to different folders for concurrent download jobs
What is Search Permission Filers?
It limits what an eDiscovery manager is able to search for (content/location)
What is the PowerShell command to limit what an eDiscovery Manager is able to search for?
New-ComplianceSecurityFilter