Microsoft SC-401 Protecting Data Used By AI And DSPM For AI Practice Test

 

Skill 3.3 • 46 original questions

This Microsoft SC-401 practice test focuses on protecting data used by ai and dspm for ai through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

A pilot at Graphic Design Institute involves email messages. The security lead asks for a configuration that will implement prerequisites for Data Security Posture Management DSPM for AI. Which approach best satisfies the requirement and helps keep policy behavior predictable? The security lead wants the configuration to align with the supported Microsoft workflow. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-9-001 before widening scope.

  1. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  2. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: A

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

B: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 2

A Microsoft 365 administrator at Northwind Traders is asked to improve protection of employee files. The success criterion is to implement prerequisites for Data Security Posture Management DSPM for AI. What should be done if the implementation must use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The initial scope covers 193 managed objects and must remain measurable during rollout.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  5. Assign Global Administrator to every investigator.

Correct answer: D

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 3

A proof of concept at Blue Yonder Airlines will be accepted only if it can implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services for contract documents. The architect also wants to preserve least privilege. Which option should be selected? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 49 historical events available for validation before enabling broader enforcement.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: D

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 4

The IT operations group at Humongous Insurance is preparing a production rollout involving financial workbooks. They specifically need to manage roles and permissions for DSPM for AI. What should be configured first to keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The design review compares outcomes for 86 representative samples before production enablement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  3. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Correct answer: A

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 5

At City Power & Light, a review of SharePoint documents found a gap. The administrator must implement prerequisites for Data Security Posture Management DSPM for AI, while the project team wants to avoid changing unrelated workloads. What is the best next step? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 123 policy evaluations to confirm expected behavior.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  3. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  4. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  5. Assign Global Administrator to every investigator.

Correct answer: D

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 6

The IT operations team at Alpine Ski House has two competing proposals for engineering designs. Only one directly enables the tenant to manage roles and permissions for DSPM for AI. Which proposal should be chosen to keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 160 protected items have been processed.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: A

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 7

A proof of concept at Woodgrove Bank will be accepted only if it can implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services for financial workbooks. The architect also wants to keep the design auditable. Which option should be selected? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. A support team will observe the first 197 policy evaluations to confirm expected behavior.

  1. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  2. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: A

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 8

The governance board at Litware approves a control for support tickets on the condition that administrators can implement prerequisites for Data Security Posture Management DSPM for AI. What should the team do to support investigation evidence? Administrators need evidence they can review after deployment. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The design review compares outcomes for 53 representative samples before production enablement.

  1. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  2. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  3. Assign Global Administrator to every investigator.
  4. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  5. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Correct answer: B

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 9

A Microsoft 365 administrator at Consolidated Messenger is asked to improve protection of financial workbooks. The success criterion is to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. What should be done if the implementation must avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 90 historical events available for validation before enabling broader enforcement.

  1. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  2. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  3. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  4. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: A

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 10

A security design workshop at Alpine Ski House focuses on email messages. One mandatory capability is to implement controls in Microsoft Purview to protect content in an environment that uses AI services. Which answer best aligns with Microsoft Purview while helping use the narrowest effective control? The requirement applies to production data rather than a one-time demonstration. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-9-010 and will be reviewed after the first week.

  1. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: D

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 11

At Tailspin Toys, a review of scanned forms found a gap. The administrator must implement controls in Microsoft Purview to protect content in an environment that uses AI services, while the project team wants to keep policy behavior predictable. What is the best next step? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The initial scope covers 164 managed objects and must remain measurable during rollout.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Assign Global Administrator to every investigator.
  3. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Correct answer: D

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 12

Consolidated Messenger is replacing a manual process used by the collaboration services team for financial workbooks. The replacement must implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. Which choice provides the most direct implementation while helping keep the design auditable? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The design review compares outcomes for 20 representative samples before production enablement.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: B

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 13

For a new Microsoft 365 deployment at Margie’s Travel, the security operations team is responsible for support tickets. They are required to configure DSPM for AI policies. Which implementation is correct if they also want to use the narrowest effective control? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 57 representative samples before production enablement.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: C

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 14

A pilot at Margie’s Travel involves regulated case records. The security lead asks for a configuration that will configure DSPM for AI policies. Which approach best satisfies the requirement and helps support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The design review compares outcomes for 94 representative samples before production enablement.

  1. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  2. Assign Global Administrator to every investigator.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: D

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 15

A compliance exception at City Power & Light can be closed only after the tenant can monitor activities in DSPM for AI for contract documents. What should the administrator implement if the goal is to avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The rollout plan requires a measurable checkpoint after 131 protected items have been processed.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Correct answer: C

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Question 16

A change request from Wide World Importers’s finance department affects SharePoint documents. The stated objective is to monitor activities in DSPM for AI. Which administrative action is the strongest fit if the team must minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 168 representative samples before production enablement.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: E

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Question 17

The governance board at Consolidated Messenger approves a control for email messages on the condition that administrators can manage roles and permissions for DSPM for AI. What should the team do to support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-9-017 before widening scope.

  1. Assign Global Administrator to every investigator.
  2. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: B

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 18

Contoso expects the volume of email messages to increase significantly. The control must scale while allowing the team to implement controls in Microsoft Purview to protect content in an environment that uses AI services. Which action best supports that objective and helps keep policy behavior predictable? Administrators need evidence they can review after deployment. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 61 policy evaluations to confirm expected behavior.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: A

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 19

For a new Microsoft 365 deployment at Blue Yonder Airlines, the finance team is responsible for cloud application files. They are required to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. Which implementation is correct if they also want to support investigation evidence? The organization wants to avoid granting broader permissions than the task requires. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-9-019 before widening scope.

  1. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  5. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Correct answer: C

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

D: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 20

A change request from Alpine Ski House’s IT operations department affects regulated case records. The stated objective is to implement prerequisites for Data Security Posture Management DSPM for AI. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 135 protected items have been processed.

  1. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  2. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  3. Assign Global Administrator to every investigator.
  4. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: B

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 21

A compliance exception at Tailspin Toys can be closed only after the tenant can implement prerequisites for Data Security Posture Management DSPM for AI for financial workbooks. What should the administrator implement if the goal is to use the narrowest effective control? The team must be able to explain why the selected control addresses the stated risk. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 172 protected items have been processed.

  1. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  4. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  5. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Correct answer: A

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 22

A compliance exception at Litware can be closed only after the tenant can manage roles and permissions for DSPM for AI for employee files. What should the administrator implement if the goal is to support investigation evidence? Administrators need evidence they can review after deployment. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The change is tracked under control batch SC401-9-022 and will be reviewed after the first week.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Correct answer: B

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 23

A compliance exception at Graphic Design Institute can be closed only after the tenant can configure DSPM for AI policies for regulated case records. What should the administrator implement if the goal is to support investigation evidence? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The implementation will be tested against 65 representative files or events before sign-off.

  1. Assign Global Administrator to every investigator.
  2. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: C

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 24

A production issue at Humongous Insurance affects the handling of scanned forms. The root requirement is to manage roles and permissions for DSPM for AI. Which remediation best meets that requirement and helps support investigation evidence? The requirement applies to production data rather than a one-time demonstration. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-9-024 before widening scope.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  3. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Correct answer: C

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 25

An incident review at Graphic Design Institute shows that the current process for regulated case records is incomplete. The team now needs to monitor activities in DSPM for AI. Which action most directly addresses that need while helping use the narrowest effective control? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-9-025 and will be reviewed after the first week.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: C

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Question 26

A security design workshop at Alpine Ski House focuses on SharePoint documents. One mandatory capability is to configure DSPM for AI policies. Which answer best aligns with Microsoft Purview while helping keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The team has 176 historical events available for validation before enabling broader enforcement.

  1. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  2. Assign Global Administrator to every investigator.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  5. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Correct answer: A

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 27

City Power & Light is replacing a manual process used by the risk management team for support tickets. The replacement must configure DSPM for AI policies. Which choice provides the most direct implementation while helping support investigation evidence? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 32 protected items have been processed.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  5. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Correct answer: C

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 28

Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services for support tickets. Which configuration should they use to avoid unnecessary user disruption? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The control owner must document the result for governance record SC401-9-028 before widening scope.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  3. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: D

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 29

An incident review at A. Datum shows that the current process for SharePoint documents is incomplete. The team now needs to manage roles and permissions for DSPM for AI. Which action most directly addresses that need while helping support investigation evidence? The security lead wants the configuration to align with the supported Microsoft workflow. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 106 users across two business units and must preserve normal collaboration.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Assign Global Administrator to every investigator.
  4. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: A

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 30

An incident review at Contoso shows that the current process for engineering designs is incomplete. The team now needs to monitor activities in DSPM for AI. Which action most directly addresses that need while helping avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 143 protected items have been processed.

  1. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: B

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Question 31

Before enabling enforcement at Humongous Insurance, administrators must demonstrate how they will implement controls in Microsoft Purview to protect content in an environment that uses AI services for engineering designs. Which configuration should they use to use the narrowest effective control? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 180 historical events available for validation before enabling broader enforcement.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  4. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  5. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Correct answer: E

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 32

A Microsoft 365 administrator at A. Datum is asked to improve protection of financial workbooks. The success criterion is to implement controls in Microsoft Purview to protect content in an environment that uses AI services. What should be done if the implementation must use the narrowest effective control? The control must work with the organization’s existing Microsoft 365 governance model. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 36 representative files or events before sign-off.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Assign Global Administrator to every investigator.
  4. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: B

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 33

A proof of concept at Litware will be accepted only if it can implement controls in Microsoft Purview to protect content in an environment that uses AI services for support tickets. The architect also wants to support a phased rollout. Which option should be selected? Administrators need evidence they can review after deployment. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 73 users and expands only after the security team signs off.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Correct answer: A

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 34

A change request from Humongous Insurance’s engineering department affects regulated case records. The stated objective is to implement prerequisites for Data Security Posture Management DSPM for AI. Which administrative action is the strongest fit if the team must keep the design auditable? The control must work with the organization’s existing Microsoft 365 governance model. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 110 policy evaluations to confirm expected behavior.

  1. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: E

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 35

  1. Datum’s security operations team is updating controls for regulated case records. The requirement is to monitor activities in DSPM for AI. The solution must also keep the design auditable. Which action should the administrator take? The pilot population is small today but the configuration must support a broader rollout. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The change is tracked under control batch SC401-9-035 and will be reviewed after the first week.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  4. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  5. Assign Global Administrator to every investigator.
  6. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Correct answer: A

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Question 36

The risk management team at Alpine Ski House has two competing proposals for cloud application files. Only one directly enables the tenant to monitor activities in DSPM for AI. Which proposal should be chosen to keep policy behavior predictable? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 184 protected items have been processed.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  5. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Correct answer: C

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Question 37

The human resources group at Adventure Works is preparing a production rollout involving cloud application files. They specifically need to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. What should be configured first to use the narrowest effective control? Administrators need evidence they can review after deployment. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The implementation will be tested against 40 representative files or events before sign-off.

  1. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: C

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 38

City Power & Light is standardizing protection for contract documents. The design must manage roles and permissions for DSPM for AI, and operations wants to keep the design auditable. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. A support team will observe the first 77 policy evaluations to confirm expected behavior.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  3. Assign Global Administrator to every investigator.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: B

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 39

During an audit at Alpine Ski House, reviewers ask how the tenant will implement prerequisites for Data Security Posture Management DSPM for AI. The implementation should keep the design auditable. Which choice is most appropriate? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-9-039 before widening scope.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  3. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  4. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: D

Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Question 40

Margie’s Travel’s collaboration services team is updating controls for scanned forms. The requirement is to configure DSPM for AI policies. The solution must also reduce false positives. Which action should the administrator take? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Administrators must be able to tune the configuration later without redesigning the entire protection model. The control owner must document the result for governance record SC401-9-040 before widening scope.

  1. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  2. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: C

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 41

Following a policy review, Fabrikam changes how employee files is governed. The new requirement is to implement controls in Microsoft Purview to protect content in an environment that uses AI services. Which action is the best fit and will help keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 188 historical events available for validation before enabling broader enforcement.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  3. Assign Global Administrator to every investigator.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: D

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 42

A proof of concept at Fourth Coffee will be accepted only if it can manage roles and permissions for DSPM for AI for employee files. The architect also wants to minimize administrative overhead. Which option should be selected? Administrators need evidence they can review after deployment. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. A support team will observe the first 44 policy evaluations to confirm expected behavior.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: A

Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Question 43

Before enabling enforcement at Wide World Importers, administrators must demonstrate how they will configure DSPM for AI policies for SharePoint documents. Which configuration should they use to avoid unnecessary user disruption? Administrators need evidence they can review after deployment. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The team has 81 historical events available for validation before enabling broader enforcement.

  1. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: B

Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Question 44

An incident review at Northwind Traders shows that the current process for contract documents is incomplete. The team now needs to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. Which action most directly addresses that need while helping reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-9-044 and will be reviewed after the first week.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Assign Global Administrator to every investigator.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: C

Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.

D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Question 45

During an audit at Margie’s Travel, reviewers ask how the tenant will implement controls in Microsoft Purview to protect content in an environment that uses AI services. The implementation should support a phased rollout. Which choice is most appropriate? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The first phase affects 155 users across two business units and must preserve normal collaboration.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.

Correct answer: D

Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.

E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Question 46

For a new Microsoft 365 deployment at Margie’s Travel, the security operations team is responsible for SharePoint documents. They are required to monitor activities in DSPM for AI. Which implementation is correct if they also want to avoid changing unrelated workloads? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The initial scope covers 192 managed objects and must remain measurable during rollout.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: E

Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.

Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Popular posts

img