Microsoft SC-401 Purview Audit Activity Explorer Alerts Defender XDR And eDiscovery Practice Test

 

Skill 3.2 • 69 original questions

This Microsoft SC-401 practice test focuses on purview audit activity explorer alerts defender xdr and ediscovery through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

A pilot at Trey Research involves engineering designs. The security lead asks for a configuration that will respond to Purview alerts in Microsoft Defender XDR. Which approach best satisfies the requirement and helps minimize administrative overhead? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. A support team will observe the first 145 policy evaluations to confirm expected behavior.

  1. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  5. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Correct answer: A

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 2

A security design workshop at Proseware focuses on employee files. One mandatory capability is to perform searches by using eDiscovery. Which answer best aligns with Microsoft Purview while helping reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 182 representative files or events before sign-off.

  1. Assign Global Administrator to every investigator.
  2. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  3. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: D

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 3

A compliance exception at Wingtip Toys can be closed only after the tenant can configure audit retention policies for employee files. What should the administrator implement if the goal is to minimize administrative overhead? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-8-003 and will be reviewed after the first week.

  1. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: A

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 4

A compliance exception at Trey Research can be closed only after the tenant can assign Microsoft Purview Audit Premium user licenses for customer records. What should the administrator implement if the goal is to minimize administrative overhead? The team wants the change to be reversible during pilot testing. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 75 users across two business units and must preserve normal collaboration.

  1. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  2. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: A

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 5

Margie’s Travel’s IT operations team is updating controls for financial workbooks. The requirement is to investigate activities by using Microsoft Purview Audit. The solution must also reduce false positives. Which action should the administrator take? The pilot population is small today but the configuration must support a broader rollout. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 112 protected items have been processed.

  1. Assign Global Administrator to every investigator.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  4. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: D

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 6

Before enabling enforcement at Consolidated Messenger, administrators must demonstrate how they will assign Microsoft Purview Audit Premium user licenses for Teams collaboration content. Which configuration should they use to keep the design auditable? The design should not depend on users remembering an optional manual step. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 149 historical events available for validation before enabling broader enforcement.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  5. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Correct answer: C

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 7

Following a policy review, Northwind Traders changes how financial workbooks is governed. The new requirement is to analyze Purview activities by using Activity explorer. Which action is the best fit and will help avoid changing unrelated workloads? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The rollout plan requires a measurable checkpoint after 186 protected items have been processed.

  1. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  5. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Correct answer: D

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 8

Consolidated Messenger is standardizing protection for employee files. The design must investigate insider risk activities by using the Microsoft Purview portal, and operations wants to keep the design auditable. What should the information security administrator do? The security lead wants the configuration to align with the supported Microsoft workflow. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 42 users across two business units and must preserve normal collaboration.

  1. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  2. Assign Global Administrator to every investigator.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  5. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Correct answer: C

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 9

Before enabling enforcement at City Power & Light, administrators must demonstrate how they will perform searches by using eDiscovery for engineering designs. Which configuration should they use to minimize administrative overhead? The design should not depend on users remembering an optional manual step. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 79 historical events available for validation before enabling broader enforcement.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: A

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 10

The data governance team at A. Datum has two competing proposals for contract documents. Only one directly enables the tenant to respond to data loss prevention alerts in the Microsoft Purview portal. Which proposal should be chosen to keep policy behavior predictable? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 116 representative samples before production enablement.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  3. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: B

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 11

An incident review at Fourth Coffee shows that the current process for support tickets is incomplete. The team now needs to analyze Purview activities by using Activity explorer. Which action most directly addresses that need while helping minimize administrative overhead? The team must be able to explain why the selected control addresses the stated risk. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 153 protected items have been processed.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Assign Global Administrator to every investigator.
  3. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: A

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 12

An incident review at Litware shows that the current process for engineering designs is incomplete. The team now needs to assign Microsoft Purview Audit Premium user licenses. Which action most directly addresses that need while helping keep the design auditable? The design should not depend on users remembering an optional manual step. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 190 representative files or events before sign-off.

  1. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  2. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Correct answer: A

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 13

The IT operations team at Woodgrove Bank has two competing proposals for regulated case records. Only one directly enables the tenant to investigate insider risk activities by using the Microsoft Purview portal. Which proposal should be chosen to keep the design auditable? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Only the users and workloads named in the requirement should be affected during the first production phase. The first phase affects 46 users across two business units and must preserve normal collaboration.

  1. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Correct answer: A

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 14

A compliance exception at A. Datum can be closed only after the tenant can respond to Purview alerts in Microsoft Defender XDR for customer records. What should the administrator implement if the goal is to preserve least privilege? The team wants the change to be reversible during pilot testing. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The pilot starts with 83 users and expands only after the security team signs off.

  1. Assign Global Administrator to every investigator.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Correct answer: B

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 15

Humongous Insurance is replacing a manual process used by the finance team for employee files. The replacement must configure audit retention policies. Which choice provides the most direct implementation while helping minimize administrative overhead? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The control owner must document the result for governance record SC401-8-015 before widening scope.

  1. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  4. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  5. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Correct answer: A

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 16

At Consolidated Messenger, a review of customer records found a gap. The administrator must investigate insider risk activities by using the Microsoft Purview portal, while the project team wants to avoid changing unrelated workloads. What is the best next step? The design should not depend on users remembering an optional manual step. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 157 representative files or events before sign-off.

  1. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: B

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 17

Consolidated Messenger’s research team is updating controls for SharePoint documents. The requirement is to analyze Purview activities by using Activity explorer. The solution must also reduce false positives. Which action should the administrator take? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 194 historical events available for validation before enabling broader enforcement.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  3. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  4. Assign Global Administrator to every investigator.
  5. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Correct answer: E

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 18

Fabrikam’s finance team is updating controls for Teams collaboration content. The requirement is to investigate activities by using Microsoft Purview Audit. The solution must also minimize administrative overhead. Which action should the administrator take? The design should not depend on users remembering an optional manual step. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The design review compares outcomes for 50 representative samples before production enablement.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  3. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Correct answer: E

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 19

Following a policy review, Trey Research changes how contract documents is governed. The new requirement is to configure audit retention policies. Which action is the best fit and will help preserve least privilege? The design should not depend on users remembering an optional manual step. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 87 historical events available for validation before enabling broader enforcement.

  1. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: C

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 20

An incident review at Tailspin Toys shows that the current process for support tickets is incomplete. The team now needs to perform searches by using eDiscovery. Which action most directly addresses that need while helping support a phased rollout? The control must work with the organization’s existing Microsoft 365 governance model. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 124 protected items have been processed.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Assign Global Administrator to every investigator.

Correct answer: A

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

B: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 21

City Power & Light is standardizing protection for email messages. The design must respond to data loss prevention alerts in the Microsoft Purview portal, and operations wants to avoid changing unrelated workloads. What should the information security administrator do? The team wants the change to be reversible during pilot testing. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The pilot starts with 161 users and expands only after the security team signs off.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  4. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: E

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 22

Fabrikam expects the volume of cloud application files to increase significantly. The control must scale while allowing the team to configure audit retention policies. Which action best supports that objective and helps keep the design auditable? The design should not depend on users remembering an optional manual step. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 198 protected items have been processed.

  1. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  2. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  5. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Correct answer: A

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 23

A production issue at Fabrikam affects the handling of employee files. The root requirement is to respond to Purview alerts in Microsoft Defender XDR. Which remediation best meets that requirement and helps support a phased rollout? The design should not depend on users remembering an optional manual step. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 54 representative samples before production enablement.

  1. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Assign Global Administrator to every investigator.

Correct answer: D

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 24

Margie’s Travel is standardizing protection for support tickets. The design must respond to Defender for Cloud Apps file policy alerts, and operations wants to avoid unnecessary user disruption. What should the information security administrator do? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 91 managed objects and must remain measurable during rollout.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  5. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Correct answer: C

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 25

The finance group at A. Datum is preparing a production rollout involving financial workbooks. They specifically need to perform searches by using eDiscovery. What should be configured first to keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 128 representative files or events before sign-off.

  1. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  2. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: D

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 26

The governance board at Tailspin Toys approves a control for scanned forms on the condition that administrators can investigate insider risk activities by using the Microsoft Purview portal. What should the team do to support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. A support team will observe the first 165 policy evaluations to confirm expected behavior.

  1. Assign Global Administrator to every investigator.
  2. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  5. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Correct answer: C

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 27

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of support tickets. The success criterion is to analyze Purview activities by using Activity explorer. What should be done if the implementation must support a phased rollout? Administrators need evidence they can review after deployment. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 21 policy evaluations to confirm expected behavior.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  3. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Correct answer: E

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 28

Trey Research is standardizing protection for support tickets. The design must perform searches by using eDiscovery, and operations wants to avoid changing unrelated workloads. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The control owner must document the result for governance record SC401-8-028 before widening scope.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Correct answer: C

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 29

Following a policy review, Trey Research changes how cloud application files is governed. The new requirement is to analyze Purview activities by using Activity explorer. Which action is the best fit and will help avoid unnecessary user disruption? The design should not depend on users remembering an optional manual step. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The initial scope covers 95 managed objects and must remain measurable during rollout.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  4. Assign Global Administrator to every investigator.
  5. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Correct answer: C

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 30

Margie’s Travel is standardizing protection for engineering designs. The design must investigate activities by using Microsoft Purview Audit, and operations wants to reduce false positives. What should the information security administrator do? The implementation will be reviewed by both security and compliance stakeholders. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 132 policy evaluations to confirm expected behavior.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  3. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  4. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  5. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Correct answer: E

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 31

Following a policy review, A. Datum changes how SharePoint documents is governed. The new requirement is to assign Microsoft Purview Audit Premium user licenses. Which action is the best fit and will help support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-8-031 before widening scope.

  1. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  2. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  3. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: B

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 32

During an audit at Fabrikam, reviewers ask how the tenant will investigate insider risk activities by using the Microsoft Purview portal. The implementation should use the narrowest effective control. Which choice is most appropriate? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 25 users and expands only after the security team signs off.

  1. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Assign Global Administrator to every investigator.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: C

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 33

A security design workshop at Woodgrove Bank focuses on email messages. One mandatory capability is to configure audit retention policies. Which answer best aligns with Microsoft Purview while helping preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The support team needs clear evidence of what matched, which control acted, and what the user experienced. A support team will observe the first 62 policy evaluations to confirm expected behavior.

  1. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Correct answer: E

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 34

Woodgrove Bank is standardizing protection for SharePoint documents. The design must respond to data loss prevention alerts in the Microsoft Purview portal, and operations wants to keep policy behavior predictable. What should the information security administrator do? The team must be able to explain why the selected control addresses the stated risk. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 99 users across two business units and must preserve normal collaboration.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: C

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 35

A compliance exception at Northwind Traders can be closed only after the tenant can perform searches by using eDiscovery for SharePoint documents. What should the administrator implement if the goal is to keep policy behavior predictable? The team wants the change to be reversible during pilot testing. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 136 representative samples before production enablement.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  5. Assign Global Administrator to every investigator.

Correct answer: A

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 36

Humongous Insurance is standardizing protection for Teams collaboration content. The design must analyze Purview activities by using Activity explorer, and operations wants to avoid unnecessary user disruption. What should the information security administrator do? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 173 protected items have been processed.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  5. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Correct answer: D

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

E: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 37

For a new Microsoft 365 deployment at Trey Research, the IT operations team is responsible for scanned forms. They are required to investigate insider risk activities by using the Microsoft Purview portal. Which implementation is correct if they also want to reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The pilot starts with 29 users and expands only after the security team signs off.

  1. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: A

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 38

For a new Microsoft 365 deployment at Proseware, the legal team is responsible for cloud application files. They are required to respond to Purview alerts in Microsoft Defender XDR. Which implementation is correct if they also want to minimize administrative overhead? The pilot population is small today but the configuration must support a broader rollout. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The team has 66 historical events available for validation before enabling broader enforcement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Assign Global Administrator to every investigator.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: D

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 39

A proof of concept at Wide World Importers will be accepted only if it can investigate activities by using Microsoft Purview Audit for contract documents. The architect also wants to avoid unnecessary user disruption. Which option should be selected? Administrators need evidence they can review after deployment. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The team has 103 historical events available for validation before enabling broader enforcement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: D

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 40

At Tailspin Toys, a review of customer records found a gap. The administrator must assign Microsoft Purview Audit Premium user licenses, while the project team wants to preserve least privilege. What is the best next step? The security lead wants the configuration to align with the supported Microsoft workflow. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 140 representative samples before production enablement.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  5. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Correct answer: D

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 41

For a new Microsoft 365 deployment at Contoso, the finance team is responsible for scanned forms. They are required to perform searches by using eDiscovery. Which implementation is correct if they also want to support a phased rollout? The team wants the change to be reversible during pilot testing. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The pilot starts with 177 users and expands only after the security team signs off.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  3. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  4. Assign Global Administrator to every investigator.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: B

Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.

C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Question 42

At Fourth Coffee, a review of SharePoint documents found a gap. The administrator must investigate activities by using Microsoft Purview Audit, while the project team wants to reduce false positives. What is the best next step? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 33 users and expands only after the security team signs off.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  3. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  4. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  5. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Correct answer: C

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 43

The IT operations team at Alpine Ski House has two competing proposals for Teams collaboration content. Only one directly enables the tenant to configure audit retention policies. Which proposal should be chosen to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 70 users and expands only after the security team signs off.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Correct answer: E

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 44

For a new Microsoft 365 deployment at Margie’s Travel, the legal team is responsible for financial workbooks. They are required to respond to data loss prevention alerts in the Microsoft Purview portal. Which implementation is correct if they also want to preserve least privilege? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The change is tracked under control batch SC401-8-044 and will be reviewed after the first week.

  1. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  2. Assign Global Administrator to every investigator.
  3. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: A

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 45

The governance board at Litware approves a control for email messages on the condition that administrators can respond to data loss prevention alerts in the Microsoft Purview portal. What should the team do to avoid unnecessary user disruption? The pilot population is small today but the configuration must support a broader rollout. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 144 policy evaluations to confirm expected behavior.

  1. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: A

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 46

A security design workshop at Graphic Design Institute focuses on SharePoint documents. One mandatory capability is to respond to data loss prevention alerts in the Microsoft Purview portal. Which answer best aligns with Microsoft Purview while helping preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The initial scope covers 181 managed objects and must remain measurable during rollout.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Correct answer: C

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 47

Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will investigate insider risk activities by using the Microsoft Purview portal for customer records. Which configuration should they use to preserve least privilege? Administrators need evidence they can review after deployment. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-8-047 and will be reviewed after the first week.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Assign Global Administrator to every investigator.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: C

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 48

During an audit at City Power & Light, reviewers ask how the tenant will respond to Defender for Cloud Apps file policy alerts. The implementation should minimize administrative overhead. Which choice is most appropriate? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-8-048 before widening scope.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Correct answer: E

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 49

A production issue at City Power & Light affects the handling of Teams collaboration content. The root requirement is to configure audit retention policies. Which remediation best meets that requirement and helps keep policy behavior predictable? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The first phase affects 111 users across two business units and must preserve normal collaboration.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  3. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: B

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 50

For a new Microsoft 365 deployment at A. Datum, the security operations team is responsible for support tickets. They are required to respond to Defender for Cloud Apps file policy alerts. Which implementation is correct if they also want to reduce false positives? The pilot population is small today but the configuration must support a broader rollout. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 148 policy evaluations to confirm expected behavior.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Assign Global Administrator to every investigator.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: C

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 51

A change request from Trey Research’s research department affects email messages. The stated objective is to assign Microsoft Purview Audit Premium user licenses. Which administrative action is the strongest fit if the team must reduce false positives? Administrators need evidence they can review after deployment. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-8-051 and will be reviewed after the first week.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: C

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 52

For a new Microsoft 365 deployment at Wingtip Toys, the security operations team is responsible for employee files. They are required to respond to Defender for Cloud Apps file policy alerts. Which implementation is correct if they also want to reduce false positives? The requirement applies to production data rather than a one-time demonstration. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The implementation will be tested against 41 representative files or events before sign-off.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Correct answer: E

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 53

The engineering team at Margie’s Travel has two competing proposals for contract documents. Only one directly enables the tenant to respond to data loss prevention alerts in the Microsoft Purview portal. Which proposal should be chosen to avoid unnecessary user disruption? The requirement applies to production data rather than a one-time demonstration. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 78 managed objects and must remain measurable during rollout.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Assign Global Administrator to every investigator.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: E

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 54

A pilot at Fabrikam involves scanned forms. The security lead asks for a configuration that will analyze Purview activities by using Activity explorer. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The change is tracked under control batch SC401-8-054 and will be reviewed after the first week.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: A

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Question 55

A change request from Humongous Insurance’s finance department affects email messages. The stated objective is to respond to Defender for Cloud Apps file policy alerts. Which administrative action is the strongest fit if the team must reduce false positives? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The pilot starts with 152 users and expands only after the security team signs off.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Correct answer: A

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 56

Woodgrove Bank’s legal team is updating controls for regulated case records. The requirement is to investigate activities by using Microsoft Purview Audit. The solution must also avoid unnecessary user disruption. Which action should the administrator take? The design should not depend on users remembering an optional manual step. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Administrators must be able to tune the configuration later without redesigning the entire protection model. The implementation will be tested against 189 representative files or events before sign-off.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  3. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  4. Assign Global Administrator to every investigator.
  5. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Correct answer: C

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 57

Following a policy review, Fourth Coffee changes how SharePoint documents is governed. The new requirement is to investigate insider risk activities by using the Microsoft Purview portal. Which action is the best fit and will help support investigation evidence? The control must work with the organization’s existing Microsoft 365 governance model. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The implementation will be tested against 45 representative files or events before sign-off.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Correct answer: E

Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.

Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Question 58

At Blue Yonder Airlines, a review of support tickets found a gap. The administrator must investigate activities by using Microsoft Purview Audit, while the project team wants to preserve least privilege. What is the best next step? The team must be able to explain why the selected control addresses the stated risk. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 82 representative samples before production enablement.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  5. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Correct answer: E

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 59

A pilot at Wide World Importers involves customer records. The security lead asks for a configuration that will assign Microsoft Purview Audit Premium user licenses. Which approach best satisfies the requirement and helps avoid changing unrelated workloads? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 119 representative files or events before sign-off.

  1. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  4. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  5. Assign Global Administrator to every investigator.

Correct answer: D

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 60

Following a policy review, Graphic Design Institute changes how SharePoint documents is governed. The new requirement is to respond to Defender for Cloud Apps file policy alerts. Which action is the best fit and will help support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The change is tracked under control batch SC401-8-060 and will be reviewed after the first week.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: B

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 61

A production issue at Graphic Design Institute affects the handling of employee files. The root requirement is to assign Microsoft Purview Audit Premium user licenses. Which remediation best meets that requirement and helps reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The change is tracked under control batch SC401-8-061 and will be reviewed after the first week.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: B

Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Question 62

The research team at Woodgrove Bank has two competing proposals for cloud application files. Only one directly enables the tenant to respond to Purview alerts in Microsoft Defender XDR. Which proposal should be chosen to minimize administrative overhead? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The design review compares outcomes for 49 representative samples before production enablement.

  1. Assign Global Administrator to every investigator.
  2. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Correct answer: D

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 63

A production issue at Adventure Works affects the handling of customer records. The root requirement is to respond to Purview alerts in Microsoft Defender XDR. Which remediation best meets that requirement and helps use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 86 users across two business units and must preserve normal collaboration.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: B

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 64

At Blue Yonder Airlines, a review of scanned forms found a gap. The administrator must respond to Purview alerts in Microsoft Defender XDR, while the project team wants to keep the design auditable. What is the best next step? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The implementation will be tested against 123 representative files or events before sign-off.

  1. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Correct answer: E

Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Option review:

A: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.

Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Question 65

City Power & Light is standardizing protection for scanned forms. The design must respond to data loss prevention alerts in the Microsoft Purview portal, and operations wants to avoid changing unrelated workloads. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-8-065 and will be reviewed after the first week.

  1. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Assign Global Administrator to every investigator.

Correct answer: C

Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

Option review:

A: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Question 66

Before enabling enforcement at Contoso, administrators must demonstrate how they will investigate activities by using Microsoft Purview Audit for Teams collaboration content. Which configuration should they use to use the narrowest effective control? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The implementation will be tested against 197 representative files or events before sign-off.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Correct answer: B

Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Question 67

A compliance exception at Northwind Traders can be closed only after the tenant can respond to Defender for Cloud Apps file policy alerts for email messages. What should the administrator implement if the goal is to use the narrowest effective control? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 53 managed objects and must remain measurable during rollout.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: A

Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Question 68

The governance board at Humongous Insurance approves a control for scanned forms on the condition that administrators can configure audit retention policies. What should the team do to reduce false positives? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The design review compares outcomes for 90 representative samples before production enablement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Assign Global Administrator to every investigator.
  3. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  4. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  5. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Correct answer: C

Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.

D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Question 69

A proof of concept at Graphic Design Institute will be accepted only if it can analyze Purview activities by using Activity explorer for engineering designs. The architect also wants to support investigation evidence. Which option should be selected? The design should not depend on users remembering an optional manual step. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-8-069 and will be reviewed after the first week.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  5. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Correct answer: E

Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.

Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Popular posts

img