Monitor and investigate data and activities Flashcards

1
Q

What are the functionalities of Content Search? (2)

A

Search and export

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the functionalities of eDiscovery Standard? (3)

A

All of Content Search + case management and legal holds

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the functionalities of eDiscovery Premium? (8)

A

All of eDiscovery Standard +
1) Assign case to people outside of your organization
2) legal hold notification
3) advanced indexing
4) tagging
5) analytics e.g., ML-based predictive coding
6) end-to-end workflow
7) OCR
8) review sets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the functionality that helps reducing the number of content match to the most useful one?

A

ML based predictive coding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the limitations of Content Search in a hybrid Exchange set-up?

A

You cannot search on-premise

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the maximum number of conditions in a Content Search query?

A

100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Review Set?

A

A secure Microsoft-provided Azure storage location where the the result of a search can be added. It is possible to export to customer owner location. This is a eDiscovery Premium feature.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the two things you need to open exported search results?

A

1) Export Key 2) eDiscovery Export Tool

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the search preview limitations? (3)

A

1000 files or max 100/location (whichever is smaller), Other elements than Emails in Outlook (calendar items, tasks, contacts, folders, lists)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

On which standards is the M365 Baseline Score based on? (3)

A

NIST CSF, ISO and FedRAMP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What can you add in addition to users when adding people that will be able to manage an ediscovery case?

A

Role groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How long does it take for a eDiscovery hold to take effect?

A

Up to 24 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When creating a eDiscovery hold, for which location do you need to select the specific locations where it will apply?

A

Exchange (specific mailboxes) and SharePoint (specific sites)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the two options to download a eDiscovery case?

A

1) Using a Microsoft provided Azure space to export outside of the organization 2) Using eDiscovery Export Tool to download locally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How is the compliance score determined?

A

It is the sum of the improvement actions scores, which depend on whether the action is mandatory/discretionary and if it is preventive/detective/corrective.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the difference between technical and non-technical remediation actions in how they affect the compliance score?

A

Non-technical are counted only once per Group, while technical are counted once

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

To which format is data from a Content Search exported?

A

Email: PST
SharePoint/OneDrive: Native document format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What are the 3 technical requirements to be able to export Content Search?

A

1) Latest Windows or .NET Framework
2) Edge
3) being connected to the temporary Azure space where the files will be stored temporarily

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

How long are results of a Content Search stored for?

A

2 weeks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

Why should you protect the Export Key?

A

Because it can be used by anyone to download search results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What other information does an export from Content Search contains? (4)

A

1) Summary
2) Errors
3) Skipped items reports
4) trace log about the export process
Note that it is also possible to only download these reports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are three tips to speed the download of the Content Search exports?

A

1) Disabled anti-virus scanning
2) Download only to internal drive (no network/external drive or OneDrive)
3) Download to different folders for concurrent download jobs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is Search Permission Filers?

A

It limits what an eDiscovery manager is able to search for (content/location)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is the PowerShell command to limit what an eDiscovery Manager is able to search for?

A

New-ComplianceSecurityFilter

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What does the New-ComplianceSecurityFilter do?

A

It limits what an eDiscovery manager is able to search for (content/location)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What role group must you be part of in order to use New-ComplianceSecurityFilter?

A

Organization Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What are the limitations when deleting content identified via a Content Search? (4)

A

1) Other locations than Exchange Online mailboxes and public folders.
2) Max 10 items per mailbox at a time
3) Max 50’000 mailboxes
4) Content in a review set (i.e., only content from live system can be deleted)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What should you do if you want to delete content from more than 50k mailboxes?

A

Use Search Permission Filters to reduce the scope of the search to e.g., one department

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What are the steps to search and delete content? What is the PowerShell command to delete?

A

1) Connect to the Securit&Compliance module in PowerShell
2) Run the search (in PowerShell or in Purview)
3) Delete using New-ComplianceSearch Action -Purge

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What does the Assessment tab of the Compliance Manager area contains?

A

List of compliance/security/privacy standard and underlying controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

How can you update the improvement actions from the Compliance Manager?

A

By downloading them into a ExportActions.xlsx file and updating them in Excel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

Is 10-year audit retention included in E5 license?

A

No, this has to be purchased as an add-on license for each user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

When creating an alert based on unusual activity, how long does it take for the baseline to be created?

A

7 days

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

When implementing an improvement action, how long does it take for the Compliance Manager portal to be updated?

A

Up to 24 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What can a eDiscovery Manager do? (5)

A

1) Create/manage eDiscovery cases
2) Add/remove members/custodians to a case
3) Place hold
4) Create/edit searche
5) Export content

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What can a eDiscovery Administrator do that a eDiscovery Manager can’t? (2)

A

1) View and manage any case
2) Remove members of any eDiscovery cases

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

Which role groups can create cases?

A

eDiscovery Manager/Admin and Organization Management

38
Q

What is the maximum number of keywords in a combined hold + search query?

A

500

39
Q

What happens if the maximum number of keywords in a combined hold + search query is reached?

A

The entire mailbox is searched

40
Q

How long does it take for a hold removal to take effect and how is this called?

A

30 days - Delay hold

41
Q

What is the difference between closed and deleted cases?

A

A closed case only means that the holds are turned off, but it is still possible to create/export searches and to re-open it, while a deleted case removes all data associated to it (no re-open possible)

42
Q

How long does it take for the closing or re-opening process of an ediscovery case to complete?

A

60 min

43
Q

What should you pay attention to when re-opening a case?

A

It does not automatically re-activate the holds

44
Q

What should you pay attention to when deleting a case?

A

You must first delete all the holds, else you will get an error

45
Q

If you add a Group to a search settings, what will be searched?

A

The Group mailbox only, NOT the mailboxes of the group members

46
Q

What additional functionalities does Audit Premium offers compared to Audit Standard? (5)

A

1) Audit log retention policies up to 10 years
2) Intelligent insights
3) More capabilities for searches e.g., more events to search
4) Higher bandwidth for searches through the O365 Management APO
5) 1 year default retention policy instead of 180 days for OneDrive, Exchange, SharePoint and Entra

47
Q

What is the baseline bandwidth for searches?

A

2000 researches/minute

48
Q

Which role group is able to turn on and off automated remediation action for all actions globally?

A

Global Admin, and it is the only one

49
Q

What actions are you able to perform on history of users working on remediation actions? (3)

A

Export, re-assign and delete

50
Q

Which model does the built-in workflow for eDiscovery alignes with?

A

Electronic Discovery Reference Model

51
Q

What are Data Custodians?

A

Users of interest that can be added to a case

52
Q

Which of these require a M365 E5 licence: data custodians, users added as manager/lawyers of an eDiscovery case?

A

Only the data custodians

53
Q

What is advanced re-indexing?

A

It re-indexes the content associated to a custodian, to allow the content to be easily searchable

54
Q

What should you pay attention to when associating other data sources to a data custodian?

A

For Teams and Viva, you need to add both the mailbox and the site (adding one does not automatically add the other)

55
Q

What is the maximum number of documents that can be added to a case?

A

40 millions

56
Q

What is the maximum volume of data that can be collected in a single collection?

A

1TB

57
Q

What is the maximum volume of data that can be put in a review set (pre-expansion)?

A

1TB

58
Q

In which format are the Teams/Viva conversations stored?

A

HTML

59
Q

What is the maximum capacity supported by the export job?

A

Min (500GB : 5 million documents)

60
Q

What are 3 data analysis tools proposed in eDiscovery Premium?

A

1) Near duplicate detection
2) Email threading
3) Theme (i.e, assigning a dominent theme to a conversation)h

61
Q

What is a pivot?

A

When performing near duplicate detection, Microsoft groups textually similar documents and defines a pivot, which is the document that all other documents within the near duplicate group are compared to.

62
Q

What are the 4 categories in which email messages are divided into?

A

1) Inclusive
2) Inclusive minus
3) Inclusive copy
4) None

63
Q

What does the “Inclusive” email message type entails?

A

The final email message in an email threat, which contains all the previous content of that email thread

64
Q

What does the “Inclusive minus” email message type entails?

A

An email message that has one or more attachments associated with it

65
Q

What does the “Inclusive copy” email message type entails?

A

An email message that is an exact copy of an Inclusive or Inclusive minus message

65
Q

What does the “None” email message type entails?

A

An email message whose content is wholly contained in at least one other email message marked as Inclusive or Inclusive minus

66
Q

What is the PoweShell command to search audit events?

A

Search-UnifiedAuditLog

67
Q

What is the role required to search audit log?

A

View-Only Audit Log

68
Q

How can you search multiple audit events in PowerShell?

A

As the Search-UnifiedAuditLog supports only one event per query, you need to append the second query to the the first CSV search results

69
Q

How many user and admin activities are being logged?

A

Over 100

70
Q

How many events can be returned in one audit search?

A

Max 50k

71
Q

The IP field of my search result is blank, why? (2)

A

Because the activity that was logged was performed by
1) an admin
2) a system account of Microsoft Entra related event

72
Q

The IP field of my search result is not that of the user who performed the action, why?

A

When a trust application is calling a service on behalf of a user, its IP address is logged instead of the one from the user

73
Q

What does the AuditData column of the audit export data CSV contains?

A

Additional information about the event in JSON format (field are event-specific)ow

74
Q

How can you extract the AuditData JSON into columns in Excel, and what you should pay attention to when performing this?

A

Using PoweQuery Editor, but it will only look at the properties of the first 1000 rows

75
Q

What is one limitation of mailbox auditing?

A

It does not record activities performed by delegate users

76
Q

What are the two possible commands to search mailbox audit for specific users?

A

Search-MailboxAuditLog
New Mailbox Audit Log Search

77
Q

To use Audit Premium functionalities, is it sufficient that the person performing the audit has an E5 license?

A

No, the user whose data you want to retain or use E5 functionalities for such as special types of events needs an E5 license

78
Q

What are the new events that can be recorded in Audit Premium? And which of these first require to be enabled in PoweShell before they are logged?

A

MailItemAccessed
Send
SearchQueryInitiatedExchange => need to be enabled in PowerShell
SearchQueryInitatedSharePoint => need to be enabled in PowerShell

79
Q

What is the event name corresponding to “MailItemAccessed” cmdlet?

A

Accessed mailbox items

80
Q

What is the event name corresponding to “Send” cmdlet?

A

Sent message (incl. reply, forward, send email)

81
Q

What is the event name corresponding to “SearchQueryInitiatedExchange” cmdlet?

A

Performed email search

82
Q

How does bandwidth of the API using Audit Premium differs from Audit Standard?

A

Standard: Publisher-level limit
Premium: Tenant-level limit
Baseline is 2000 requests/minute in both cases, that can automatically increase based on the org seat count and license (for Premium it can increase more, as the limit is at tenant level)

83
Q

How many audit log retention policies can you define?

A

Max 50

84
Q

Is it possible to edit the default audit log retention policy?

A

No, and it is not display. Custom retention policies take precedence over the default one.

85
Q

What is the PowerShell command to set an audit log retention policy?

A

New-UnifiedAuditLogRetentionPolicy

86
Q

What is the PowerShell command to 1) view 2) Edit 3) Delete an audit log retention policy?

A

1) Get 2) Set 3) Remove

87
Q

What is the difference between sync and bind MailItemAccessed?

A

Bind: Individual access to email message (one event per mail item)
Sync: Desktop version of Outlook accessing the mailbox (only one event per sync, not per mail item)

88
Q

What is the limitation of bind audit log generation?

A

It stops generating bind audit log if there are more than 1000 records created in less than 24 hours

89
Q
A