Monitor and investigate data and activities Flashcards
What are the functionalities of Content Search? (2)
Search and export
What are the functionalities of eDiscovery Standard? (3)
All of Content Search + case management and legal holds
What are the functionalities of eDiscovery Premium? (8)
All of eDiscovery Standard +
1) Assign case to people outside of your organization
2) legal hold notification
3) advanced indexing
4) tagging
5) analytics e.g., ML-based predictive coding
6) end-to-end workflow
7) OCR
8) review sets
What is the functionality that helps reducing the number of content match to the most useful one?
ML based predictive coding
What are the limitations of Content Search in a hybrid Exchange set-up?
You cannot search on-premise
What is the maximum number of conditions in a Content Search query?
100
What is a Review Set?
A secure Microsoft-provided Azure storage location where the the result of a search can be added. It is possible to export to customer owner location. This is a eDiscovery Premium feature.
What are the two things you need to open exported search results?
1) Export Key 2) eDiscovery Export Tool
What are the search preview limitations? (3)
1000 files or max 100/location (whichever is smaller), Other elements than Emails in Outlook (calendar items, tasks, contacts, folders, lists)
On which standards is the M365 Baseline Score based on? (3)
NIST CSF, ISO and FedRAMP
What can you add in addition to users when adding people that will be able to manage an ediscovery case?
Role groups
How long does it take for a eDiscovery hold to take effect?
Up to 24 hours
When creating a eDiscovery hold, for which location do you need to select the specific locations where it will apply?
Exchange (specific mailboxes) and SharePoint (specific sites)
What are the two options to download a eDiscovery case?
1) Using a Microsoft provided Azure space to export outside of the organization 2) Using eDiscovery Export Tool to download locally
How is the compliance score determined?
It is the sum of the improvement actions scores, which depend on whether the action is mandatory/discretionary and if it is preventive/detective/corrective.
What is the difference between technical and non-technical remediation actions in how they affect the compliance score?
Non-technical are counted only once per Group, while technical are counted once
To which format is data from a Content Search exported?
Email: PST
SharePoint/OneDrive: Native document format
What are the 3 technical requirements to be able to export Content Search?
1) Latest Windows or .NET Framework
2) Edge
3) being connected to the temporary Azure space where the files will be stored temporarily
How long are results of a Content Search stored for?
2 weeks
Why should you protect the Export Key?
Because it can be used by anyone to download search results
What other information does an export from Content Search contains? (4)
1) Summary
2) Errors
3) Skipped items reports
4) trace log about the export process
Note that it is also possible to only download these reports
What are three tips to speed the download of the Content Search exports?
1) Disabled anti-virus scanning
2) Download only to internal drive (no network/external drive or OneDrive)
3) Download to different folders for concurrent download jobs
What is Search Permission Filers?
It limits what an eDiscovery manager is able to search for (content/location)
What is the PowerShell command to limit what an eDiscovery Manager is able to search for?
New-ComplianceSecurityFilter
What does the New-ComplianceSecurityFilter do?
It limits what an eDiscovery manager is able to search for (content/location)
What role group must you be part of in order to use New-ComplianceSecurityFilter?
Organization Management
What are the limitations when deleting content identified via a Content Search? (4)
1) Other locations than Exchange Online mailboxes and public folders.
2) Max 10 items per mailbox at a time
3) Max 50’000 mailboxes
4) Content in a review set (i.e., only content from live system can be deleted)
What should you do if you want to delete content from more than 50k mailboxes?
Use Search Permission Filters to reduce the scope of the search to e.g., one department
What are the steps to search and delete content? What is the PowerShell command to delete?
1) Connect to the Securit&Compliance module in PowerShell
2) Run the search (in PowerShell or in Purview)
3) Delete using New-ComplianceSearch Action -Purge
What does the Assessment tab of the Compliance Manager area contains?
List of compliance/security/privacy standard and underlying controls
How can you update the improvement actions from the Compliance Manager?
By downloading them into a ExportActions.xlsx file and updating them in Excel
Is 10-year audit retention included in E5 license?
No, this has to be purchased as an add-on license for each user
When creating an alert based on unusual activity, how long does it take for the baseline to be created?
7 days
When implementing an improvement action, how long does it take for the Compliance Manager portal to be updated?
Up to 24 hours
What can a eDiscovery Manager do? (5)
1) Create/manage eDiscovery cases
2) Add/remove members/custodians to a case
3) Place hold
4) Create/edit searche
5) Export content
What can a eDiscovery Administrator do that a eDiscovery Manager can’t? (2)
1) View and manage any case
2) Remove members of any eDiscovery cases