Information Protection and Governance Flashcards

1
Q

What are the four key pillars of Microsoft Purview’s Information Protection and Governance?

A

The four key pillars are:

Know your data
Protect your data
Prevent data loss
Govern your data

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can Microsoft Purview help you understand your data landscape?

A

Microsoft Purview helps you understand your data landscape by using tools like Trainable Classifiers and Sensitive Information Types (SITs), which enable better understanding and classification of your data across its various locations and formats.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do Sensitivity Labels help protect your data in Microsoft Purview?

A

Sensitivity Labels allow you to classify, label, and protect data across your data residencies. They control the protection of your data through measures like encryption, watermarking, headers and footers, and requiring justification for downgrading labels. These labels can also enforce access controls based on classification.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can admins monitor and respond to label usage activities in Microsoft Purview? If yes, how?

A

Yes, admins can monitor and respond to label usage activities through the Purview Portal, where reports and analytics are available for tracking label application and other security activities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How do Data Loss Prevention (DLP) policies help prevent data leakage?

A

DLP policies prevent intentional or unintentional data leakage by identifying, monitoring, and protecting sensitive data across different data environments. Pre-built policies, aligned with geographical regulations like UKFP or HIPAA, help enforce these protections.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Can you create custom DLP policies in Microsoft Purview?

A

Yes, you can create custom DLP policies using Sensitive Information Types (SITs), Sensitivity Labels, and Retention Labels to tailor data loss prevention to your organization’s specific needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does Microsoft Purview help in governing data across an organisation’s data estate?

A

Microsoft Purview enables governance across an organisation’s data estate by using Retention Policies to manage data over time. This includes defining how long data is retained in systems like Exchange and SharePoint. For more granular control, Retention Labels can be used to manage exceptions to broader retention policies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the role of Sensitive Information Types (SITs) in data classification?

A

Sensitive Information Types (SITs) use pattern matching via regular expressions (RegEx) to detect and classify sensitive information, such as credit card numbers or personal identification numbers. You can use pre-built SITs or create custom ones tailored to your organisation’s specific data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are Trainable Classifiers, and how do they work?

A

Trainable Classifiers use machine learning models to categorise data objects. They can be pre-built classifiers trained by Microsoft (e.g., to recognise resumes or invoices) or custom classifiers that you train to recognise specific types of data relevant to your organisation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the purpose of the Content Explorer in Microsoft Purview?

A

The Content Explorer in the Compliance Portal allows you to deep dive into the content of labeled documents and review data that has been flagged or highlighted in compliance dashboards for further investigation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does the Activity Explorer help manage labels and data?

A

The Activity Explorer tracks and manages label activity across your data landscape, helping you make data-driven decisions about the effectiveness of policies. For example, you can monitor how many “Highly Confidential” labels have been downgraded to “Public” and adjust policies if needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Can Sensitivity Labels be published without Label Policies?

A

No, Sensitivity Labels can only be published through Label Policies. These policies define who can access and apply specific labels and can enforce default labels for particular groups, such as Payroll or Sales.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What additional settings can Label Policies configure?

A

Label Policies can also configure settings like who has access to certain labels, default labels for different user groups, and can even include links to custom help pages for label guidance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which environments can Microsoft Purview DLP policies cover?

A

Microsoft Purview DLP policies can identify, monitor, and protect sensitive data across a variety of environments, including on-premises systems, 3rd party systems, OneDrive, SharePoint, Exchange, Teams, Power BI, Office, and the cloud.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What role does the Compliance Manager play in DLP?

A

The Compliance Manager provides assessments and recommendations on your organisation’s compliance posture, helping you ensure that your data loss prevention policies are aligned with regulatory requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the difference between Retention Policies and Retention Labels?

A

Retention Policies are used to manage data retention for large data groups based on time, such as emails in Exchange or files in SharePoint, to ensure compliance with regulations. Retention Labels, on the other hand, deal with exceptions within these policies and provide more granular control over specific data items.

17
Q

What are the three main components of Microsoft Purview’s Unified Data Governance Solution?

A

The three main components are:

Data Map – Registers data sources to capture metadata.
Data Catalogue – Enables users to search through the data.
Data Estate Insights – Provides a high-level view of sensitive data, its classification, and its lineage.

18
Q

What is the primary use of Sensitivity Labels in Microsoft Purview?

A

Sensitivity Labels are primarily used for classifying, labeling, and protecting information by applying measures like encryption and access controls.

19
Q

How are Sensitive Information Types (SITs) used in Microsoft Purview?

A

Sensitive Information Types (SITs) are used to identify and detect sensitive information based on pattern matching. They are commonly used in Data Loss Prevention (DLP) policies and automatic classification workflows, and can trigger the application of Sensitivity Labels.