Study guide
Technical reference and lesson notes
Purpose of This Lesson
Microsoft Purview Data Loss Prevention relies on role-based access control to determine who can create policies, review reports, investigate alerts, and access sensitive content.
For the SC-200 exam, the important skill is not simply memorizing administrator titles. You must understand:
- The difference between a role, a role group, and a Microsoft Entra administrator role
- Which permissions are required to create or modify DLP policies
- Which roles allow analysts to investigate DLP alerts without changing policies
- How to apply least privilege
- Where roles and role groups are managed
- When to use Microsoft Purview versus Microsoft Defender XDR
These decisions directly affect how a security operations team separates policy administration, alert investigation, reporting, and access to sensitive evidence.
Key Concepts
Microsoft Purview Role-Based Access Control
Microsoft Purview uses a role-based access control, or RBAC, model.
The three concepts to distinguish are:
Role
A role grants permission to perform a specific set of tasks.
Examples of individual Purview permissions include:
- DLP Compliance Management
- View-Only DLP Compliance Management
- Manage Alerts
- Data Classification Content Viewer
- Role Management
A role represents the actual permission being granted.
Role Group
A role group is a collection of roles assigned to users or groups.
For example, an Information Protection role group may contain several roles that collectively allow its members to view reports, investigate policy matches, or administer information protection features.
Microsoft generally expects administrators to assign users to an appropriate built-in role group rather than assigning extremely broad tenant-wide access.
Microsoft Entra Administrator Role
Microsoft Entra administrator roles are tenant-level administrative roles such as:
- Global Administrator
- Compliance Administrator
- Compliance Data Administrator
- Security Administrator
- Security Reader
Some Entra roles map to Purview role groups and provide access to Purview functionality. However, Microsoft Entra roles and Microsoft Purview role groups are not identical concepts.
For exam questions, focus on the permission required for the task rather than assuming that a similarly named administrator role automatically grants every possible Purview permission.
Role Groups Versus Individual Roles
A frequent Microsoft exam scenario presents a user who needs to perform only one part of a compliance workflow.
For example:
- A policy administrator needs to create DLP policies.
- A SOC analyst needs to investigate DLP alerts.
- An auditor needs to view reports.
- A data investigator needs to see matched sensitive content.
- A role administrator needs to assign Purview permissions.
Assigning the Global Administrator role would probably grant sufficient access, but it would violate least-privilege principles.
Microsoft recommends using roles with the fewest permissions required and minimizing the number of Global Administrators.
Important DLP-Related Roles and Role Groups
The exact effective permissions depend on the individual Purview roles contained within a role group. The following table summarizes the general responsibilities associated with the roles discussed in the lesson.
| Role or Role Group | Typical DLP Responsibility | Policy Creation or Editing | Alert and Report Access |
|---|---|---|---|
| Compliance Administrator | Broad compliance and Purview administration | Usually permitted through associated Purview permissions | Yes |
| Compliance Data Administrator | Manages compliance-related data and associated controls | Usually permitted through associated Purview permissions | Yes |
| Information Protection Admin | Administers information protection, classification, labels, and DLP-related settings | Yes, when assigned DLP Compliance Management | Yes |
| Information Protection Analyst | Reviews activity and analyzes information protection events | Normally limited compared with an administrator | Yes |
| Information Protection Investigator | Investigates DLP and information protection activity | Normally no policy administration requirement | Yes |
| Information Protection Reader | Read-only access to reports and information protection data | No | Read-only |
| Security Administrator | Manages security configuration and security alerts | Do not assume full DLP policy-authoring access without checking assigned Purview roles | Yes |
| Security Operator | Performs security operations and alert-management activities | Normally no | Yes |
| Security Reader | Reviews security information and alerts | No | Read-only |
| Global Administrator | Broad tenant-wide administrative access | Yes | Yes |
| Custom Purview Role Group | Contains administrator-selected Purview roles | Depends on roles selected | Depends on roles selected |
Important Qualification
Do not rely only on the role-group name.
For example, an account that creates or edits a DLP policy needs the DLP Compliance Management role permission.
Similarly, access to the DLP alert management dashboard requires:
- The Manage Alerts role
- Either DLP Compliance Management or View-Only DLP Compliance Management
This is more precise than saying that every security or compliance administrator automatically has identical DLP capabilities.
Compliance Administrator
The Compliance Administrator role is intended for users responsible for broad compliance administration across Microsoft 365.
Typical responsibilities may include:
- Creating and editing DLP policies
- Managing compliance configurations
- Reviewing DLP reports
- Working with information protection and governance features
- Managing compliance-related investigations
This role is powerful and should normally be limited to administrators responsible for compliance program configuration.
A SOC analyst who only investigates alerts generally should not need this level of access.
Compliance Data Administrator
The Compliance Data Administrator role focuses on managing compliance-related data and controls.
Depending on the Purview roles mapped to the account, this user may be able to:
- Create and edit DLP policies
- Review DLP alerts
- Access reports
- Manage compliance data across Microsoft 365 workloads
- Work with content stored in Exchange, SharePoint, and OneDrive
This role may be appropriate when a person manages the data and operational aspects of compliance but does not require broader tenant administration.
Information Protection Admin
The Information Protection Admin role is closely associated with:
- Sensitivity labels
- Sensitive information types
- Classification
- Information protection policies
- DLP configuration
- Information protection reporting
This role is often a better fit than Global Administrator when the administrator is responsible specifically for labeling, classification, and DLP.
Remember that sensitivity labels and DLP policies are related but separate controls:
- A sensitivity label classifies and may protect an item.
- A DLP policy detects risky handling of sensitive information and applies a restriction, notification, audit action, or alert.
Information Protection Reader
An Information Protection Reader is intended for read-only access.
Typical uses include:
- Reviewing DLP reports
- Viewing labeling activity
- Reviewing classification information
- Observing trends without changing policies
Microsoft lists Information Protection Reader as an applicable role for Purview posture reports.
This is appropriate for:
- Auditors
- Managers
- Compliance reviewers
- Analysts who need visibility but should not change configuration
It is not appropriate for creating or modifying DLP policies.
Security Administrator
The Security Administrator role is focused primarily on security configuration and security operations.
A Security Administrator may have access to:
- Security alerts
- Security reports
- DLP alert-management capabilities
- Microsoft Defender security features
However, do not assume that the Security Administrator role automatically provides every DLP policy-management permission.
For a policy-authoring task, confirm that the account has DLP Compliance Management or membership in a role group that includes that permission.
For exam questions, choose the most task-specific role rather than automatically selecting Security Administrator.
Security Reader
A Security Reader can review security information without changing security configuration.
Typical responsibilities include:
- Monitoring DLP alerts
- Reviewing security incidents
- Viewing reports
- Assisting with triage
- Providing evidence to another team
A Security Reader cannot normally create or edit DLP policies.
This role is useful for a Tier 1 analyst, auditor, or manager who requires visibility but should not be able to alter tenant-wide controls.
Global Administrator
Global Administrator provides extremely broad access across the Microsoft 365 tenant.
A Global Administrator can generally perform DLP configuration and permission-management tasks, but it should not be the default answer to a permissions question.
Microsoft recommends minimizing the number of Global Administrators and assigning the least privilege necessary for each job function.
Use Global Administrator when:
- Initial tenant configuration requires it
- No narrower role supports the required task
- Emergency administrative access is necessary
- Role-management recovery is required
Do not use it merely because it is the easiest way to resolve a permissions problem.
Custom Microsoft Purview Role Groups
Custom role groups allow an organization to combine specific Purview roles for a specialized job function.
A custom role group can be useful when the built-in groups are:
- Too broad
- Too restrictive
- Misaligned with the organization’s separation-of-duties model
- Unable to distinguish policy administrators from alert investigators
For example, an organization could create a role group for DLP alert investigators that includes:
- Manage Alerts
- View-Only DLP Compliance Management
The group could intentionally exclude:
- DLP policy-editing permissions
- Role Management
- Content-viewing permissions
Microsoft Purview allows administrators to select the roles included in a custom role group and then assign users or groups as members.
Access to Sensitive DLP Evidence
Being able to view an alert does not necessarily mean that the analyst can view all sensitive content associated with the alert.
To access features such as:
- Content preview
- Matched sensitive content
- Context surrounding a policy match
The analyst must have the appropriate data-classification content-viewer permission, typically through the Content Explorer Content Viewer role group.
This supports separation of duties:
- One analyst may triage alert metadata.
- A more privileged investigator may inspect the sensitive content.
- A compliance or legal team may authorize further review.
This distinction is important because DLP alerts may contain regulated, confidential, financial, personal, or legally sensitive information.
Managing Roles in Microsoft Purview
Purview roles and role groups are managed in the Microsoft Purview portal.
Current general navigation:
- Open the Microsoft Purview portal.
- Select Settings.
- Select Roles and scopes.
- Open Role groups.
- Select a built-in role group or create a custom role group.
- Review or select the included roles.
- Add users or groups as members.
- Save the configuration.
Microsoft documents the current management path as:
Microsoft Purview portal → Settings → Roles and scopes → Role groups.
Permission Required to Manage Role Groups
A user generally needs one of the following to view and manage Purview role groups:
- Global Administrator
- The Role Management role, which is assigned through the Organization Management role group
The Role Management permission allows a user to view, create, and modify role groups.
This creates an important separation:
- A DLP administrator may be able to create policies.
- That administrator may not necessarily be able to grant roles to other people.
- A role administrator manages membership and permission assignments.
Microsoft Security Operations Context
Separation of Policy Administration and Alert Investigation
A mature security operations program should separate DLP policy administration from day-to-day alert investigation.
DLP Policy Administrator
The policy administrator:
- Creates and edits DLP policies
- Selects protected locations
- Configures sensitive information types
- Defines conditions and actions
- Configures policy tips
- Configures alert thresholds
- Tests policies in simulation mode
- Reviews policy effectiveness
SOC or DLP Analyst
The analyst:
- Reviews generated DLP alerts
- Determines whether the activity is legitimate
- Examines the user, device, file, email, or cloud activity
- Determines whether sensitive data was exposed
- Documents the event
- Escalates suspicious activity
- Coordinates containment or remediation
Compliance or Legal Investigator
A compliance or legal investigator may:
- Review matched sensitive content
- Determine whether a policy or regulatory violation occurred
- Preserve evidence
- Contact the employee’s manager
- Coordinate with HR, privacy, or legal teams
- Approve further investigative steps
Separating these responsibilities reduces the risk that one user can both alter the control and investigate the resulting evidence without oversight.
DLP Alert Investigation Workflow
A practical DLP alert workflow may look like this:
1. Review the Alert
Determine:
- Which DLP policy and rule matched
- The severity
- The affected user
- The affected workload
- The sensitive information type
- The activity that triggered the alert
- Whether the event was blocked, warned, audited, or overridden
2. Review the Entity Context
Investigate relevant entities such as:
- User account
- Endpoint device
- File
- Email message
- SharePoint site
- OneDrive account
- Teams message
- IP address
- Cloud application
3. Determine Scope
Ask:
- Was this a single event or repeated behavior?
- Did the user access or transfer other sensitive content?
- Were multiple files involved?
- Was the destination internal or external?
- Was the action performed from a managed device?
- Was a DLP policy tip overridden?
- Did the user provide a justification?
4. Determine Intent and Impact
Possible classifications include:
- Authorized business activity
- User mistake
- Policy misunderstanding
- Negligent handling
- Compromised account
- Malware-driven exfiltration
- Deliberate insider activity
- False positive
5. Take or Recommend Action
Actions may include:
- Close the alert as benign
- Educate the user
- Escalate to a compliance investigator
- Escalate to the incident response team
- Revoke sharing access
- Isolate a device
- Disable or restrict an account
- Preserve evidence
- Initiate insider-risk procedures
- Tune the DLP policy
The analyst should avoid destructive or tenant-wide actions unless the evidence and authorization support them.
Microsoft Purview Versus Microsoft Defender XDR
Microsoft currently recommends different portals for different portions of the DLP lifecycle.
- Use Microsoft Purview to create and edit DLP policies.
- Use Microsoft Defender XDR as the recommended location for investigating and managing DLP alerts.
This is an important SC-200 decision point.
Microsoft Purview is primarily the policy, compliance, classification, and data-protection administration platform.
Microsoft Defender XDR provides a unified security operations experience for investigating alerts and correlating them with other security signals.
For example, a DLP alert involving a user copying sensitive files to removable storage might be investigated alongside:
- Endpoint alerts
- User identity alerts
- Malware detections
- Suspicious sign-ins
- Cloud application activity
- Other incidents associated with the device or user
Incident Documentation
The analyst should document:
- Alert identifier
- Policy and rule involved
- Date and time
- User and device
- Sensitive information type
- Data location
- Destination
- User action
- Whether the action was blocked
- Whether the user overrode the warning
- Business justification
- Evidence reviewed
- Containment performed
- Teams notified
- Final disposition
- Recommended policy improvements
Because DLP investigations may involve sensitive content, documentation should avoid copying unnecessary regulated data into tickets or unrestricted collaboration systems.
Improving Future Detection
After an investigation, the organization may need to adjust:
- Sensitive information type confidence levels
- Instance-count thresholds
- Included or excluded users
- Included locations
- Alert aggregation
- Severity
- User notifications
- Override permissions
- Policy-tip wording
- Endpoint restrictions
- Approved business exceptions
Policy changes should generally be tested before full enforcement to avoid unexpected disruption.
Exam-Relevant Takeaways
Remember these points for the SC-200 exam:
- Microsoft Purview uses RBAC.
- A role grants permissions.
- A role group bundles roles and members.
- A Microsoft Entra administrator role is not the same thing as a Purview role group.
- Creating or editing DLP policies requires DLP Compliance Management permissions.
- Viewing the DLP alert dashboard requires Manage Alerts plus either DLP Compliance Management or View-Only DLP Compliance Management.
- Access to an alert does not automatically grant access to matched sensitive content.
- Content preview requires additional content-viewer permission.
- Use Microsoft Purview to configure DLP policies.
- Microsoft Defender XDR is the recommended portal for investigating and managing DLP alerts.
- Security Reader is read-only.
- Information Protection Reader is read-only.
- Global Administrator is powerful but usually not the least-privilege answer.
- Custom role groups can combine only the permissions required for a particular job.
- Managing role groups requires Role Management or sufficiently broad administrative access.
- Always match the role to the task described in the scenario.
Tool / Feature Decision Guide
| Scenario | Best Microsoft Security Tool or Feature | Why |
|---|---|---|
| Create or edit a DLP policy | Microsoft Purview Data Loss Prevention | Purview is the policy-administration location |
| Investigate and manage a DLP alert | Microsoft Defender XDR | Microsoft recommends Defender XDR for DLP alert investigation |
| Review DLP posture and policy trends | Microsoft Purview DLP Reports | Provides reporting on policy triggers, activity, and violators |
| Give an auditor read-only report access | Information Protection Reader or another appropriate read-only role group | Provides visibility without policy modification |
| Allow an analyst to manage alerts but not edit policies | Custom role group with Manage Alerts and View-Only DLP Compliance Management | Supports least privilege |
| Allow an investigator to view matched sensitive content | Content Explorer Content Viewer permission | Alert access alone does not permit viewing sensitive content |
| Create a specialized DLP job function | Custom Microsoft Purview role group | Allows selected roles to be combined |
| Add users to a Purview role group | Roles and scopes in Microsoft Purview | This is where Purview role-group membership is managed |
| Investigate a DLP event alongside endpoint or identity alerts | Microsoft Defender XDR | Correlates DLP activity with broader security signals |
| Configure sensitivity labels and classification settings | Microsoft Purview Information Protection | Designed for labels, classification, and information protection |
| Perform broad emergency tenant administration | Global Administrator | Provides broad access, but should be used sparingly |
Roles Compared by Job Function
| Job Function | Suggested Access Pattern |
|---|---|
| DLP Policy Engineer | Information Protection Admin or another role group containing DLP Compliance Management |
| Tier 1 SOC Analyst | Security Reader or limited alert-viewing role |
| DLP Investigator | Information Protection Investigator |
| Compliance Auditor | Information Protection Reader |
| Security Operations Lead | Security Administrator or custom role group based on required tasks |
| Purview Role Administrator | Role Management |
| Compliance Program Owner | Compliance Administrator |
| Emergency Tenant Administrator | Global Administrator |
The exact answer in an exam scenario depends on the required action. Select the narrowest role that supports that action.
KQL Notes
The lesson does not introduce Kusto Query Language.
DLP roles and role-group assignments are primarily configured through Microsoft Purview RBAC rather than through KQL.
KQL may still be used elsewhere in Microsoft security operations to investigate related activity, such as:
- Endpoint file events
- Removable-media activity
- Sign-in behavior
- Cloud application activity
- Email activity
- Identity compromise
However, do not select KQL as the method for assigning Purview roles or creating DLP policies.
Common Exam Traps
Trap 1: Selecting Global Administrator for Every DLP Task
Global Administrator may work, but Microsoft generally expects the least-privilege answer.
Choose the narrower compliance, information-protection, security, or custom role when possible.
Trap 2: Confusing Roles With Role Groups
A role grants permissions.
A role group contains roles and members.
Users are commonly added to a role group that contains the permissions needed for their job.
Trap 3: Assuming an Entra Role and a Purview Role Group Are Identical
A similarly named role may appear in both systems, but the permission models and assignment locations are distinct.
Pay attention to whether the question asks for:
- An Entra administrator role
- A Microsoft Purview role
- A Microsoft Purview role group
- A permission contained within a role group
Trap 4: Giving a Reader Policy-Editing Permissions
Security Reader and Information Protection Reader are intended for visibility, not policy administration.
Trap 5: Assuming Alert Access Includes Content Access
An analyst may be able to view and manage an alert without having permission to inspect the matched sensitive content.
Additional content-viewer permissions may be required.
Trap 6: Using Microsoft Purview for Every Investigation Step
Purview is used for policy configuration and compliance reporting.
Microsoft Defender XDR is the recommended location for investigating and managing DLP alerts.
Trap 7: Assuming Security Administrator Always Means DLP Policy Author
A Security Administrator may work with DLP alerts and security operations, but policy creation depends on the underlying DLP Compliance Management permission.
Trap 8: Giving an Analyst Role Management
Role Management allows users to manage role groups.
An analyst does not need permission to grant roles merely to investigate alerts.
Trap 9: Ignoring Least Privilege
When two choices could perform the task, the narrower role is normally the stronger Microsoft security-design answer.
Trap 10: Confusing Reporting With Investigation
Reports summarize patterns and posture.
Alerts represent specific policy matches that require triage and investigation.
Real-World SOC Analyst Notes
Alert Fatigue
DLP policies can produce large numbers of alerts when:
- Conditions are too broad
- Thresholds are too low
- Common business workflows are not excluded
- Policies are placed directly into enforcement
- User exceptions are poorly understood
- Alert aggregation is not configured appropriately
Microsoft Purview supports both individual and aggregated alert patterns. Aggregation can reduce noise when many similar events occur over a defined period.
False Positives
A DLP match does not automatically prove malicious data exfiltration.
False positives may result from:
- Test data
- Templates containing example identifiers
- Internal business transfers
- Approved third-party workflows
- Incorrect sensitive information type confidence
- Content that resembles a regulated identifier
- Poorly scoped policies
Analysts should validate the evidence and business context before escalating.
Evidence Preservation
DLP evidence may include:
- Alert details
- File names
- File hashes
- Sensitive information types
- Email recipients
- Sharing destinations
- Device details
- User override justification
- Audit events
- Endpoint activity
Preserve enough evidence to support the investigation, but avoid unnecessarily copying the protected content.
Escalation Paths
A DLP incident may require coordination with:
- Microsoft 365 administrators
- Endpoint security
- Identity security
- Compliance
- Privacy
- Legal
- Human resources
- Data owners
- Department management
- Incident response
- Insider risk management
The severity of the escalation depends on the data, intent, destination, volume, and business impact.
Automation Safety
Automation can accelerate DLP response, but overly aggressive actions may:
- Disable legitimate users
- Block critical business processes
- Remove authorized file access
- Generate large ticket volumes
- Cause tenant-wide disruption
- Interfere with legal or compliance investigations
High-impact response actions should be tested, documented, and approved through change-control and incident-response procedures.
Access Permissions
Analysts should receive only the access needed to perform their assigned duties.
An analyst who can inspect matched sensitive content may encounter:
- Personal data
- Payment information
- Health information
- Legal documents
- Employee records
- Intellectual property
- Customer data
Access to this content should be logged, limited, and periodically reviewed.
Data Retention
DLP alert visibility may depend on the organization’s audit-log retention configuration. Microsoft notes that audit retention settings control how long an alert remains visible in the console.
Organizations should align retention with:
- Regulatory requirements
- Investigation needs
- Legal-hold requirements
- Internal security policy
- Licensing
- Storage and compliance cost
Licensing Considerations
Some DLP features depend on Microsoft 365 licensing.
Examples include:
- Aggregated alert configuration
- Endpoint DLP
- Teams DLP
- Advanced investigation features
- Longer audit retention
- Access to certain reports or compliance capabilities
Do not assume that a user lacks permission when the underlying issue may be licensing or feature availability.
Change Control
DLP policies can affect many users and workloads.
Before modifying a policy:
- Identify affected locations.
- Review exceptions.
- Test in simulation mode.
- Validate alert volume.
- Confirm business owners.
- Document rollback steps.
- Communicate with support teams.
- Monitor after deployment.
Policy administration should be treated as a controlled production change.
Quick Reference Summary
- Purview permissions use RBAC.
- Roles contain permissions.
- Role groups contain roles and members.
- Entra administrator roles are distinct from Purview role groups.
- DLP policy editing requires DLP Compliance Management.
- Alert-dashboard access requires Manage Alerts plus a DLP management or view-only permission.
- Content preview requires additional content-viewer access.
- Use Purview to configure DLP policies.
- Use Defender XDR to investigate DLP alerts.
- Readers cannot modify policies.
- Avoid Global Administrator when a narrower role works.
- Use custom role groups for specialized least-privilege access.
- Manage Purview role groups under Settings → Roles and scopes.
- Role Management is required to administer role groups.
- Separate policy administration from alert investigation.
Flashcards
Q: What is the difference between a Purview role and a role group?
A: A role grants specific permissions, while a role group combines roles and assigns them to users or groups.
Q: Which permission is required to create or edit a DLP policy?
A: DLP Compliance Management.
Q: Which portal is primarily used to create and edit DLP policies?
A: The Microsoft Purview portal.
Q: Which portal does Microsoft recommend for investigating and managing DLP alerts?
A: Microsoft Defender XDR.
Q: Can a Security Reader create a DLP policy?
A: No. Security Reader is a read-only role.
Q: Can an Information Protection Reader modify DLP policies?
A: No. It provides read-only visibility into reports and information protection data.
Q: Why should Global Administrator not be the default answer to a DLP permission question?
A: It grants excessive access and violates least-privilege principles when a narrower role is available.
Q: What is the purpose of a custom Purview role group?
A: To combine specific roles for a specialized job function without granting unnecessary permissions.
Q: What additional permission may be required to view matched sensitive content?
A: Data Classification Content Viewer, commonly assigned through the Content Explorer Content Viewer role group.
Q: Where are Purview role groups managed?
A: Microsoft Purview portal → Settings → Roles and scopes → Role groups.
Q: What permission allows an administrator to create or modify Purview role groups?
A: Role Management.
Q: Does access to a DLP alert automatically provide access to the sensitive content that triggered it?
A: No. Content-preview permissions are separate.
Q: Which role type is appropriate for an auditor who only needs to review DLP reports?
A: An Information Protection Reader or another appropriate read-only role group.
Q: What is a primary responsibility of an Information Protection Admin?
A: Managing classification, sensitivity labels, information protection settings, and DLP-related configurations.
Q: Why should policy administration and alert investigation be separated?
A: Separation of duties reduces excessive access, conflicts of interest, accidental changes, and unauthorized exposure to sensitive evidence.
Practice Questions
Question 1:
A security analyst must investigate Microsoft Purview DLP alerts but must not create or edit DLP policies. Which permission design best follows least privilege?
A. Assign Global Administrator
B. Assign DLP Compliance Management and Role Management
C. Assign Manage Alerts and View-Only DLP Compliance Management
D. Assign Exchange Administrator
Correct Answer:
C. Assign Manage Alerts and View-Only DLP Compliance Management
Explanation:
Manage Alerts permits alert-management activities, while View-Only DLP Compliance Management provides DLP visibility without policy-editing rights. Global Administrator and full DLP management permissions would grant unnecessary access.
Question 2:
An administrator must create a new DLP policy for Exchange, SharePoint, and OneDrive. Which permission is specifically required?
A. View-Only DLP Compliance Management
B. DLP Compliance Management
C. Security Reader
D. Manage Alerts only
Correct Answer:
B. DLP Compliance Management
Explanation:
Creating and editing DLP policies requires DLP Compliance Management. View-only and alert-management permissions are insufficient.
Question 3:
A SOC analyst receives a DLP alert involving a user who copied confidential files to removable storage. The analyst wants to correlate the activity with endpoint and identity alerts. Which portal should the analyst use?
A. Microsoft Entra admin center
B. Exchange admin center
C. Microsoft Defender XDR
D. Microsoft 365 Apps admin center
Correct Answer:
C. Microsoft Defender XDR
Explanation:
Microsoft Defender XDR is the recommended location for investigating and managing DLP alerts and can correlate the DLP event with endpoint, identity, and other security signals.
Question 4:
A compliance auditor needs to review DLP posture reports but must not modify policies. Which role is the best fit?
A. Global Administrator
B. Information Protection Reader
C. Information Protection Admin
D. Role Management
Correct Answer:
B. Information Protection Reader
Explanation:
Information Protection Reader provides read-only access appropriate for reporting and review. The other options grant administrative permissions that the auditor does not require.
Question 5:
An analyst can open a DLP alert but cannot view the exact sensitive content that caused the policy match. What is the most likely explanation?
A. The DLP policy is disabled
B. Microsoft Sentinel is not connected
C. The analyst lacks data-classification content-viewer permission
D. The analyst must be a Global Administrator
Correct Answer:
C. The analyst lacks data-classification content-viewer permission
Explanation:
Alert access and sensitive-content access are separate. The analyst may require the Data Classification Content Viewer permission, commonly provided through the Content Explorer Content Viewer role group.