Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.
Actual exam question for Microsoft's SC-401 exam Question #: 258 Topic #: 3
DRAG DROP You have a Microsoft 365 subscription that contains 20 data loss prevention (DLP) policies. You need to identify the following: # Rules that are applied without triggering a policy alert # The top 10 files that have matched DLP policies # Alerts that are miscategorized Which report should you use for each requirement? To answer, drag the appropriate reports to the correct requirements. Each report may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point.
Suggested Answer:
Explanation: The False positive and override report helps identify rules that were applied but did not generate an actual policy alert, which means they were overridden or deemed false positives. The DLP policy matches report provides details on files that matched DLP policies, including the top 10 files. The Incident reports report helps analyze and review alerts, including those that may have been miscategorized.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up / login
(it's free).
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).