Microsoft 365 Copilot AB-900 Compliance Manager Data Explorer And Insider Risk Management Practice Test

 

Skills 2.3 • 30 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on compliance manager data explorer and insider risk management through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

For a tenant cleanup at Humongous Insurance, which Microsoft 365 approach correctly addresses the need to map compliance requirements to improvement actions and scores? The team needs a direct administrative answer, not a broad redesign.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: D

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 2

The identity administrator at Adventure Works is asked to explore sensitive data locations and classification details. What is the most appropriate next step? The administrator wants an action that is easy to audit later.

  1. Run the appropriate Data access governance report from the SharePoint admin center
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted

Correct answer: D

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

E: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 3

Blue Yonder Airlines has validated the surrounding services. The remaining requirement is to investigate potentially risky user behavior that could indicate insider data risk. Which choice is correct? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  2. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: E

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 4

Which statement best explains how Microsoft 365 should address this requirement at Relecloud: map compliance requirements to improvement actions and scores? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  2. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content

Correct answer: D

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

E: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 5

A design review at Lamna Healthcare identifies one specific goal: explore sensitive data locations and classification details. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  2. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria

Correct answer: D

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

E: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 6

The IT team at Proseware wants to investigate potentially risky user behavior that could indicate insider data risk. Which Microsoft 365 capability should it use? The team will validate the result immediately after the change.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  3. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  4. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  5. Use Microsoft Purview Communication Compliance to review policy violations in supported communications

Correct answer: D

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

E: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 7

While handling a production readiness check, the Copilot administrator needs to map compliance requirements to improvement actions and scores. Which answer most directly addresses the stated need? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action

Correct answer: D

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

E: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 8

Which statement best explains how Microsoft 365 should address this requirement at City Power & Light: explore sensitive data locations and classification details? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access

Correct answer: D

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

E: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 9

Northwind Traders is preparing a compliance assessment. The team needs to investigate potentially risky user behavior that could indicate insider data risk. What should the IT administrator choose? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Run the appropriate Data access governance report from the SharePoint admin center

Correct answer: A

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 10

A support case at Fourth Coffee says administrators must map compliance requirements to improvement actions and scores. Which option is the best fit? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  2. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  3. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions

Correct answer: E

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

E: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 11

For a data protection review at Alpine Ski House, which Microsoft 365 approach correctly addresses the need to explore sensitive data locations and classification details? The team needs a direct administrative answer, not a broad redesign.

  1. Run the appropriate Data access governance report from the SharePoint admin center
  2. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  3. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  4. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  5. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content

Correct answer: B

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

C: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

E: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 12

Which statement best explains how Microsoft 365 should address this requirement at Contoso: investigate potentially risky user behavior that could indicate insider data risk? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  2. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: E

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 13

Litware has validated the surrounding services. The remaining requirement is to map compliance requirements to improvement actions and scores. Which choice is correct? The solution should preserve least privilege and existing governance where possible.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears

Correct answer: D

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

E: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 14

An administrator reviewing governance workshop for Trey Research must explore sensitive data locations and classification details. Which Microsoft 365 control or object should be used? The team wants the smallest change that directly addresses the requirement.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  3. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users

Correct answer: D

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

E: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 15

A design review at Consolidated Messenger identifies one specific goal: investigate potentially risky user behavior that could indicate insider data risk. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access

Correct answer: B

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 16

Which statement best explains how Microsoft 365 should address this requirement at Woodgrove Bank: map compliance requirements to improvement actions and scores? The team will validate the result immediately after the change.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  4. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: B

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

C: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 17

While handling a Copilot adoption project, the IT administrator needs to explore sensitive data locations and classification details. Which answer most directly addresses the stated need? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: C

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 18

During a identity hardening effort at Southridge Video, the identity administrator must investigate potentially risky user behavior that could indicate insider data risk. Which Microsoft 365 action or concept most directly satisfies the requirement? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  4. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  5. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears

Correct answer: C

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

D: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 19

Fabrikam is preparing a new-user onboarding. The team needs to map compliance requirements to improvement actions and scores. What should the SharePoint administrator choose? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  2. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  3. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: D

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 20

Which statement best explains how Microsoft 365 should address this requirement at Wingtip Toys: explore sensitive data locations and classification details? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  2. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  5. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action

Correct answer: A

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

B: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

E: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 21

For a service desk escalation at VanArsdel, which Microsoft 365 approach correctly addresses the need to investigate potentially risky user behavior that could indicate insider data risk? The team needs a direct administrative answer, not a broad redesign.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: E

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 22

The service desk lead at Bellows College is asked to map compliance requirements to improvement actions and scores. What is the most appropriate next step? The administrator wants an action that is easy to audit later.

  1. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: B

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 23

Tailspin Toys has validated the surrounding services. The remaining requirement is to explore sensitive data locations and classification details. Which choice is correct? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  2. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  5. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot

Correct answer: B

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

E: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 24

Which statement best explains how Microsoft 365 should address this requirement at Coho Winery: investigate potentially risky user behavior that could indicate insider data risk? The team wants the smallest change that directly addresses the requirement.

  1. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  2. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: B

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 25

A design review at Humongous Insurance identifies one specific goal: map compliance requirements to improvement actions and scores. Which option best matches that goal? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: D

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 26

The IT team at Adventure Works wants to explore sensitive data locations and classification details. Which Microsoft 365 capability should it use? The team will validate the result immediately after the change.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content

Correct answer: C

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

E: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 27

While handling a admin-center audit, the SharePoint administrator needs to investigate potentially risky user behavior that could indicate insider data risk. Which answer most directly addresses the stated need? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  4. Run the appropriate Data access governance report from the SharePoint admin center
  5. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action

Correct answer: A

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

E: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Question 28

Which statement best explains how Microsoft 365 should address this requirement at Relecloud: map compliance requirements to improvement actions and scores? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  3. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  4. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  5. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted

Correct answer: C

Why: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

B: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

C: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This directly addresses the stated requirement.

D: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

E: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to map compliance requirements to improvement actions and scores.

Learning point: Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions. Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring.

Question 29

Lamna Healthcare is preparing a governance workshop. The team needs to explore sensitive data locations and classification details. What should the security administrator choose? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access

Correct answer: D

Why: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

Option review:

A: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

C: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This directly addresses the stated requirement.

E: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to explore sensitive data locations and classification details.

Learning point: Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears. Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection.

Question 30

A support case at Proseware says administrators must investigate potentially risky user behavior that could indicate insider data risk. Which option is the best fit? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  4. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  5. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot

Correct answer: D

Why: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

Option review:

A: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

C: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

D: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This directly addresses the stated requirement.

E: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to investigate potentially risky user behavior that could indicate insider data risk.

Learning point: Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity. Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review.

Popular posts

img