ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 257 - MS-700 discussion

Report
Export

You have a Microsoft 365 E3 subscription that contains 500 users. All the users have computers that run Windows 10 and are joined to Azure AD. Vou need to generate a report that identifies which documents the users copied from Microsoft Teams to USB devices. What should you do first?

A.

Onboard the Windows 10 computers to Endpoint data loss prevention (Endpoint DLP).

Answers
A.

Onboard the Windows 10 computers to Endpoint data loss prevention (Endpoint DLP).

B.

Assign the Microsoft 365 ES compliance add-on to each user.

Answers
B.

Assign the Microsoft 365 ES compliance add-on to each user.

C.

Create a custom data loss prevention (DLP) policy.

Answers
C.

Create a custom data loss prevention (DLP) policy.

D.

Assign the Enterprise Mobility + Security ES add-on to each user.

Answers
D.

Assign the Enterprise Mobility + Security ES add-on to each user.

Suggested answer: B

Explanation:

According to the Microsoft documentation1, to generate a report that identifies which documents the users copied from Teams to USB devices, you need to use advanced hunting on Microsoft Defender ATP. Advanced hunting lets you run queries to find threat activity involving USB devices, such as mounting and unmounting of USB drives or copying of files2. To use advanced hunting, you need to have one of the following roles:

Security administrator

Security reader

Security operator

Global administrator

The Groups Administrator role does not have access to advanced hunting or Microsoft Defender ATP.

Therefore, based on this information, the correct answer is B. Assign the Microsoft 365 E5 compliance add-on to each user. This add-on includes Microsoft Defender ATP and allows you to use advanced hunting features3. Alternatively, you can request one of the roles that have access to advanced hunting, such as Security administrator or Global administrator.

asked 05/10/2024
Thomas Schmitt
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first