MS-102 M365 Compliance Management Flashcards
(14 cards)
What is the Microsoft Purview Compliance Portal?
The central hub for managing compliance across Microsoft 365, providing access to compliance solutions, policies, and reports. It allows administrators to assess compliance risks, protect sensitive information, respond to data requests, and address regulatory requirements.
What are sensitivity labels in Microsoft 365?
allow organizations to classify and protect sensitive content by applying encryption, visual markings, access controls, and protection settings. Labels follow content wherever it goes, across devices, apps, and services.
What are retention labels and policies?
Retention labels and policies allow organizations to define how long content is kept before being permanently deleted or when content should be deleted. They help organizations comply with industry regulations and internal policies regarding record retention.
What is the difference between sensitivity labels and retention labels?
Sensitivity labels protect content and control access based on sensitivity, while retention labels manage how long content is kept and when it should be deleted. Sensitivity labels travel with the content, while retention labels are applied to content in place.
What is Microsoft Purview Data Lifecycle Management?
helps organizations manage their data lifecycle by applying retention and deletion policies to email and documents. It helps reduce legal risk while retaining content needed for compliance.
What is Content Search in Microsoft 365
tool that allows administrators to search for content across multiple Microsoft 365 services including Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams. Results can be exported or used in eDiscovery cases.
What are the different eDiscovery solutions in Microsoft 365?
Core eDiscovery: Basic case management, search, and export functionality
Advanced eDiscovery: Adds analytics, legal hold notifications, review sets, and machine learning capabilities
What is a legal hold in Microsoft 365?
A process that preserves all content in mailboxes, sites, or locations relevant to a specific case or investigation, preventing users from permanently deleting content that may be relevant to the case.
What is Data Loss Prevention (DLP) in Microsoft 365?
A set of technologies that help prevent the inadvertent disclosure of sensitive information. DLP policies detect, monitor, and protect sensitive information across Microsoft 365 services including Exchange, SharePoint, OneDrive, and Teams.
What are the components of a DLP policy?
-Conditions: What triggers the policy (sensitive info types, labels, etc.)
-Locations: Where the policy applies (Exchange, -SharePoint, OneDrive, Teams, etc.)
-Actions: What happens when policy conditions are met (block, notify, restrict access)
-User notifications: Messages shown to users when policy is triggered
-User overrides: Options for users to override policy restrictions with justification
What are sensitive information types in DLP?
Predefined or custom patterns that identify sensitive data like credit card numbers, social security numbers, passport numbers, health information, or other confidential data using pattern matching, proximity, and confidence levels.
What is Microsoft Purview Audit (Premium)?
An enhanced auditing solution that provides longer retention of audit logs (1 year), higher bandwidth for accessing audit data, and access to crucial events for security and compliance investigations.
What are alert policies in Microsoft 365?
Rules that trigger notifications when users perform specific activities. Administrators can create custom alert policies to monitor and be notified about suspicious or high-risk activities in their Microsoft 365 environment.
What is Double Key Encryption in Microsoft 365?
A solution that enables organizations to protect their most sensitive data while maintaining full control of their encryption keys. It uses two keys – one stored in Microsoft and one managed by the customer – both keys are required to decrypt protected content.