Microsoft 365 Mobility and Security (legacy) — Question 12
You have a Microsoft 365 subscription.
You configure a data loss prevention (DLP) policy.
You discover that users are incorrectly marking content as false positive and bypassing the DLP policy.
You need to prevent the users from bypassing the DLP policy.
What should you configure?
Answer options
- A. incident reports
- B. actions
- C. exceptions
- D. user overrides
Correct answer: D
Explanation
Configuring 'user overrides' prevents users from bypassing the DLP policy by disallowing them to mark items as false positives. 'Incident reports' are used for tracking but do not prevent bypassing. 'Actions' dictate what happens when a policy is violated, while 'exceptions' allow certain conditions to be excluded, which could enable bypassing the policy.