Configuring File Policy in Microsoft Cloud App Security | SC-400 Exam Preparation

Configuring File Policy in Microsoft Cloud App Security

Question

Note: This question is part of a series of questions that present the same scenario.

Each question in the series contains a unique solution that might meet the stated goals.

Some question sets might have more than one correct solution, while others might not have a correct solution.

After you answer a question in this section, you will NOT be able to return to it.

As a result, these questions will not appear in the review screen.

You are configuring a file policy in Microsoft Cloud App Security.

You need to configure the policy to apply to all files.

Alerts must be sent to every file owner who is affected by the policy.

The policy must scan for credit card numbers, and alerts must be sent to the Microsoft Teams site of the affected department.

Solution: You use the Built-in DLP inspection method and send alerts to Microsoft Power Automate.

Does this meet the goal?

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B.

A.

https://docs.microsoft.com/en-us/cloud-app-security/content-inspection-built-in https://docs.microsoft.com/en-us/cloud-app-security/flow-integration

The solution provided of using the Built-in DLP inspection method and sending alerts to Microsoft Power Automate may not fully meet the stated goals of the scenario.

While the Built-in DLP inspection method can scan for credit card numbers in files, it may not be able to apply the policy to all files. It only works with a limited set of file types, including Microsoft Office files, PDFs, and zip archives. Therefore, if there are other file types that need to be scanned, this solution may not be sufficient.

Additionally, the solution sends alerts to Microsoft Power Automate instead of sending alerts to every file owner who is affected by the policy. While Power Automate can be used to automate certain tasks, it may not be the most appropriate tool for sending alerts to file owners. Instead, alerts should be sent directly to affected file owners or a designated team responsible for the files.

Lastly, the solution states that alerts must be sent to the Microsoft Teams site of the affected department. However, it does not specify how this will be achieved. Depending on how the Microsoft Teams site is set up, it may not be possible to send alerts directly to the site.

Therefore, the solution provided may not fully meet the stated goals of the scenario. It is possible that an alternative solution, such as using a custom DLP policy that can scan all file types and integrating with a tool that can send alerts directly to file owners or a designated team, may be a better fit.