Microsoft 365 Copilot AB-900 SharePoint Oversharing Data Access Governance Practice Test

 

Skills 2.4 • 25 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on sharepoint oversharing data access governance and restricted access control through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

An administrator reviewing tenant cleanup for Woodgrove Bank must find the source of excessive SharePoint sharing before changing permissions. Which Microsoft 365 control or object should be used? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  5. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users

Correct answer: B

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

E: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 2

A design review at Wide World Importers identifies one specific goal: collect a SharePoint governance report before remediating oversharing. Which option best matches that goal? The team needs a direct administrative answer, not a broad redesign.

  1. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Run the appropriate Data access governance report from the SharePoint admin center
  5. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted

Correct answer: D

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

E: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 3

The IT team at Southridge Video wants to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link. Which Microsoft 365 capability should it use? The administrator wants an action that is easy to audit later.

  1. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  2. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  5. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks

Correct answer: C

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

D: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

E: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 4

Which Microsoft 365 concept is the strongest match for the following need at Fabrikam: find the source of excessive SharePoint sharing before changing permissions? The solution should preserve least privilege and existing governance where possible.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  5. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears

Correct answer: C

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

D: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

E: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 5

During a oversharing investigation at Wingtip Toys, the service desk lead must collect a SharePoint governance report before remediating oversharing. Which Microsoft 365 action or concept most directly satisfies the requirement? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  2. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  3. Run the appropriate Data access governance report from the SharePoint admin center
  4. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  5. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot

Correct answer: C

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

C: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

D: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

E: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 6

VanArsdel is preparing a service desk escalation. The team needs to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link. What should the Copilot administrator choose? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: A

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 7

A support case at Bellows College says administrators must find the source of excessive SharePoint sharing before changing permissions. Which option is the best fit? The team will validate the result immediately after the change.

  1. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  2. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears

Correct answer: D

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

E: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 8

Which Microsoft 365 concept is the strongest match for the following need at Tailspin Toys: collect a SharePoint governance report before remediating oversharing? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Run the appropriate Data access governance report from the SharePoint admin center

Correct answer: E

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

E: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 9

The identity administrator at Coho Winery is asked to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link. What is the most appropriate next step? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Run the appropriate Data access governance report from the SharePoint admin center
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  4. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  5. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content

Correct answer: D

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

D: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

E: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 10

Humongous Insurance has validated the surrounding services. The remaining requirement is to find the source of excessive SharePoint sharing before changing permissions. Which choice is correct? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: D

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 11

An administrator reviewing data protection review for Adventure Works must collect a SharePoint governance report before remediating oversharing. Which Microsoft 365 control or object should be used? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  2. Run the appropriate Data access governance report from the SharePoint admin center
  3. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  4. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: B

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

C: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 12

Which Microsoft 365 concept is the strongest match for the following need at Blue Yonder Airlines: prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link? The team needs a direct administrative answer, not a broad redesign.

  1. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  2. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  3. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  4. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  5. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions

Correct answer: D

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

D: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

E: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 13

The IT team at Relecloud wants to find the source of excessive SharePoint sharing before changing permissions. Which Microsoft 365 capability should it use? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users

Correct answer: D

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

E: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 14

While handling a governance workshop, the Copilot administrator needs to collect a SharePoint governance report before remediating oversharing. Which answer most directly addresses the stated need? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  2. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  3. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  4. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  5. Run the appropriate Data access governance report from the SharePoint admin center

Correct answer: E

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

C: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

E: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 15

During a pilot rollout at Proseware, the compliance administrator must prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link. Which Microsoft 365 action or concept most directly satisfies the requirement? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  5. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action

Correct answer: D

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

D: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

E: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 16

Which Microsoft 365 concept is the strongest match for the following need at Lucerne Publishing: find the source of excessive SharePoint sharing before changing permissions? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  5. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks

Correct answer: C

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

D: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

E: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 17

A support case at City Power & Light says administrators must collect a SharePoint governance report before remediating oversharing. Which option is the best fit? The team will validate the result immediately after the change.

  1. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Run the appropriate Data access governance report from the SharePoint admin center
  5. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot

Correct answer: D

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

E: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 18

For a identity hardening effort at Northwind Traders, which Microsoft 365 approach correctly addresses the need to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link? No unrelated tenant settings should be changed.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content

Correct answer: B

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

E: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 19

The Microsoft 365 administrator at Fourth Coffee is asked to find the source of excessive SharePoint sharing before changing permissions. What is the most appropriate next step? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  2. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data

Correct answer: A

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

B: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

E: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 20

Which Microsoft 365 concept is the strongest match for the following need at Alpine Ski House: collect a SharePoint governance report before remediating oversharing? The choice should follow normal Microsoft 365 administrative practice.

  1. Run the appropriate Data access governance report from the SharePoint admin center
  2. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  5. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content

Correct answer: A

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

B: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

E: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 21

An administrator reviewing service desk escalation for Contoso must prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link. Which Microsoft 365 control or object should be used? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  2. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: C

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 22

A design review at Litware identifies one specific goal: find the source of excessive SharePoint sharing before changing permissions. Which option best matches that goal? The team needs a direct administrative answer, not a broad redesign.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  5. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access

Correct answer: B

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

E: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Question 23

The IT team at Trey Research wants to collect a SharePoint governance report before remediating oversharing. Which Microsoft 365 capability should it use? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  2. Run the appropriate Data access governance report from the SharePoint admin center
  3. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  4. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  5. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users

Correct answer: B

Why: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

Option review:

A: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

B: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This directly addresses the stated requirement.

C: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

D: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

E: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to collect a SharePoint governance report before remediating oversharing.

Learning point: Run the appropriate Data access governance report from the SharePoint admin center. SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns.

Question 24

Which Microsoft 365 concept is the strongest match for the following need at Consolidated Messenger: prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  3. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users

Correct answer: E

Why: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

B: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

C: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent users outside an approved group from accessing a sensitive SharePoint site even if they previously had a sharing link.

E: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This directly addresses the stated requirement.

Learning point: Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users. Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist.

Question 25

During a agent governance review at Woodgrove Bank, the identity administrator must find the source of excessive SharePoint sharing before changing permissions. Which Microsoft 365 action or concept most directly satisfies the requirement? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  2. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  3. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data

Correct answer: D

Why: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

Option review:

A: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

B: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

C: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This directly addresses the stated requirement.

E: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to find the source of excessive SharePoint sharing before changing permissions.

Learning point: Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content. Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites.

Popular posts

img