Information Protection Basics Flashcards
Confidence level link to false positive
The lower, the more false positive
Three ways to create a custom SIT
1) Regex, function, keyword list or dictionary
2) Document fingerprinting
3) Exact data match
Document fingerprinting limitation (5)
Max 50 fingerprints per tenants, password protected files, file that contain only images, files greater than 4MB, dotx files
Number of documents to train a classifier
Between 50 and 500
Number of documents to test a classifier
200
Location where documents for training/testing a trainable classifier need to be
SharePoint Online folder
Permission restriction for trainable classifier
Only the user who created the classifier can train and review predictions made by that classifier
Timeline for trainable classifier
1) Initiate the training classifier that will start by scanning all the content (7-14 days)
2) Train documents (up to 24h)
3) Testing (up to 10 days)
4) Publish
Format limitation of trainable classifier
Encrypted files and name file extensions not supported by SP Online
Downstream inheritance of sensitivity labels
When data is used to generate reports, these reports are also protected by the same sensitivity label
Capabilities of sensitivity labels (2)
1) Encryption
2) Mark documents (header, footer, watermark)
Pre-requisite to start creating sensitivity label policies
Have auditing turned on
Where are sensitivity labels published to?
Users and Groups (incl. distribution and mail-enabled Security Groups)
Where are retention labels published to?
Locations (OneDrive, SharePoint, Exchange,…)
Which portal can you use to enable sensitivity labels for SharePoint and OneDrive?
1) Purview
2) PowerShell
What is Purview Information Protection Scanner used for?
To apply labels on-premise (SP librairies/folders and UNC paths)
Where is Purview Information Protection Scanner installed and configured?
Installed on Windows Server but configured in the Azure portal
Pre-requisite to start applying sensitivity label in SP/Teams
Perform some commands in PowerShell
If you apply a sensitivity label to an email with attachement, does the attachment inherit the sensitivity label?
Only if the attachement has a label without encryption but the email has a label that requires encryptions. If the attachement has no label, no label will be applied.
What is the difference between the Content Explorer and the Activity Explorer?
The Content Explorer shows the content for each label across locations, while the Activity Explorer shows all activities that were performed e.g., which labels applied and by whom
How many days does the Activity Explorer shows history for?
30 days
Can you directly turn on an auto-labelling policy?
No, you need to run it in simulation mode first
What are the three types of email encryption that Microsoft offers?
(1) Microsoft Purview Message Encryption (old name = OME) (2) Information Right Management (3) S/MIME
What are the limitation of Microsoft Purview Message encryption? (2)
.doc, .xls, .ppt and files larger than 25MB.
What are the technology supporting Microsoft Purview Message Encryption?
Azure RMS (Right Management) and IRM (Information Right Management)
Which email encryption mechanism support external email domain (e.g., gmail)?
Only Purview Encryption and S/MIME
Which email encryption mechanism offers more functionalities than just encryption?
IRM and Purview Message Encryption - it is also possible to defined usage restrictions e.g., not possible to print or forward an email
Which email encryption mechanism requires the use of keys?
S/MIME - you must have the public key of the recipient
What are the limitation of IRM email encryption?
Only internal recipients are allowed.
What are the limitations of S/MIME (2)?
It requires managing the key (more complex usage) and it does not allow encrypted messages to be scanned for malware/spam
How does BitLocker encryption works (key management)?
Data is encrypted with Full Volume Encryption Key, which is itself encrypted with a Volume Master Key, which is itself protected by a Trusted Platform module.
What are the additional functionalities of Advanced Purview Message Encryption? (4)
(1) Message expiration (2) Multiple branding templates (3) Message revocation (4) Encrypted message portal activity logs
Where is the expiration time for protected messages being defined?
In the custom branded template
Where is the custom branding being created?
In PowerShell or in DLP
What is the PowerShell command to create a new branding template?
New-OMEConfiguration