Microsoft SC-401 Protecting Data Used By AI And DSPM For AI Practice Test
Skill 3.3 • 46 original questions
This Microsoft SC-401 practice test focuses on protecting data used by ai and dspm for ai through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.
A pilot at Graphic Design Institute involves email messages. The security lead asks for a configuration that will implement prerequisites for Data Security Posture Management DSPM for AI. Which approach best satisfies the requirement and helps keep policy behavior predictable? The security lead wants the configuration to align with the supported Microsoft workflow. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-9-001 before widening scope.
Correct answer: A
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
B: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
A Microsoft 365 administrator at Northwind Traders is asked to improve protection of employee files. The success criterion is to implement prerequisites for Data Security Posture Management DSPM for AI. What should be done if the implementation must use the narrowest effective control? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The initial scope covers 193 managed objects and must remain measurable during rollout.
Correct answer: D
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
A proof of concept at Blue Yonder Airlines will be accepted only if it can implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services for contract documents. The architect also wants to preserve least privilege. Which option should be selected? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 49 historical events available for validation before enabling broader enforcement.
Correct answer: D
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
The IT operations group at Humongous Insurance is preparing a production rollout involving financial workbooks. They specifically need to manage roles and permissions for DSPM for AI. What should be configured first to keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The design review compares outcomes for 86 representative samples before production enablement.
Correct answer: A
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
At City Power & Light, a review of SharePoint documents found a gap. The administrator must implement prerequisites for Data Security Posture Management DSPM for AI, while the project team wants to avoid changing unrelated workloads. What is the best next step? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 123 policy evaluations to confirm expected behavior.
Correct answer: D
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
The IT operations team at Alpine Ski House has two competing proposals for engineering designs. Only one directly enables the tenant to manage roles and permissions for DSPM for AI. Which proposal should be chosen to keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 160 protected items have been processed.
Correct answer: A
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
A proof of concept at Woodgrove Bank will be accepted only if it can implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services for financial workbooks. The architect also wants to keep the design auditable. Which option should be selected? The team wants the change to be reversible during pilot testing. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. A support team will observe the first 197 policy evaluations to confirm expected behavior.
Correct answer: A
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
The governance board at Litware approves a control for support tickets on the condition that administrators can implement prerequisites for Data Security Posture Management DSPM for AI. What should the team do to support investigation evidence? Administrators need evidence they can review after deployment. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The design review compares outcomes for 53 representative samples before production enablement.
Correct answer: B
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
A Microsoft 365 administrator at Consolidated Messenger is asked to improve protection of financial workbooks. The success criterion is to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. What should be done if the implementation must avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 90 historical events available for validation before enabling broader enforcement.
Correct answer: A
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
A security design workshop at Alpine Ski House focuses on email messages. One mandatory capability is to implement controls in Microsoft Purview to protect content in an environment that uses AI services. Which answer best aligns with Microsoft Purview while helping use the narrowest effective control? The requirement applies to production data rather than a one-time demonstration. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-9-010 and will be reviewed after the first week.
Correct answer: D
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
At Tailspin Toys, a review of scanned forms found a gap. The administrator must implement controls in Microsoft Purview to protect content in an environment that uses AI services, while the project team wants to keep policy behavior predictable. What is the best next step? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The initial scope covers 164 managed objects and must remain measurable during rollout.
Correct answer: D
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
Consolidated Messenger is replacing a manual process used by the collaboration services team for financial workbooks. The replacement must implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. Which choice provides the most direct implementation while helping keep the design auditable? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The design review compares outcomes for 20 representative samples before production enablement.
Correct answer: B
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
For a new Microsoft 365 deployment at Margie’s Travel, the security operations team is responsible for support tickets. They are required to configure DSPM for AI policies. Which implementation is correct if they also want to use the narrowest effective control? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 57 representative samples before production enablement.
Correct answer: C
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
A pilot at Margie’s Travel involves regulated case records. The security lead asks for a configuration that will configure DSPM for AI policies. Which approach best satisfies the requirement and helps support a phased rollout? The pilot population is small today but the configuration must support a broader rollout. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The design review compares outcomes for 94 representative samples before production enablement.
Correct answer: D
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
A compliance exception at City Power & Light can be closed only after the tenant can monitor activities in DSPM for AI for contract documents. What should the administrator implement if the goal is to avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The rollout plan requires a measurable checkpoint after 131 protected items have been processed.
Correct answer: C
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
A change request from Wide World Importers’s finance department affects SharePoint documents. The stated objective is to monitor activities in DSPM for AI. Which administrative action is the strongest fit if the team must minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 168 representative samples before production enablement.
Correct answer: E
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
The governance board at Consolidated Messenger approves a control for email messages on the condition that administrators can manage roles and permissions for DSPM for AI. What should the team do to support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The control owner must document the result for governance record SC401-9-017 before widening scope.
Correct answer: B
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
Contoso expects the volume of email messages to increase significantly. The control must scale while allowing the team to implement controls in Microsoft Purview to protect content in an environment that uses AI services. Which action best supports that objective and helps keep policy behavior predictable? Administrators need evidence they can review after deployment. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 61 policy evaluations to confirm expected behavior.
Correct answer: A
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
For a new Microsoft 365 deployment at Blue Yonder Airlines, the finance team is responsible for cloud application files. They are required to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. Which implementation is correct if they also want to support investigation evidence? The organization wants to avoid granting broader permissions than the task requires. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-9-019 before widening scope.
Correct answer: C
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
D: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
A change request from Alpine Ski House’s IT operations department affects regulated case records. The stated objective is to implement prerequisites for Data Security Posture Management DSPM for AI. Which administrative action is the strongest fit if the team must avoid unnecessary user disruption? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 135 protected items have been processed.
Correct answer: B
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
A compliance exception at Tailspin Toys can be closed only after the tenant can implement prerequisites for Data Security Posture Management DSPM for AI for financial workbooks. What should the administrator implement if the goal is to use the narrowest effective control? The team must be able to explain why the selected control addresses the stated risk. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The rollout plan requires a measurable checkpoint after 172 protected items have been processed.
Correct answer: A
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
A compliance exception at Litware can be closed only after the tenant can manage roles and permissions for DSPM for AI for employee files. What should the administrator implement if the goal is to support investigation evidence? Administrators need evidence they can review after deployment. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The change is tracked under control batch SC401-9-022 and will be reviewed after the first week.
Correct answer: B
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
A compliance exception at Graphic Design Institute can be closed only after the tenant can configure DSPM for AI policies for regulated case records. What should the administrator implement if the goal is to support investigation evidence? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The implementation will be tested against 65 representative files or events before sign-off.
Correct answer: C
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
A production issue at Humongous Insurance affects the handling of scanned forms. The root requirement is to manage roles and permissions for DSPM for AI. Which remediation best meets that requirement and helps support investigation evidence? The requirement applies to production data rather than a one-time demonstration. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-9-024 before widening scope.
Correct answer: C
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
An incident review at Graphic Design Institute shows that the current process for regulated case records is incomplete. The team now needs to monitor activities in DSPM for AI. Which action most directly addresses that need while helping use the narrowest effective control? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The change is tracked under control batch SC401-9-025 and will be reviewed after the first week.
Correct answer: C
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
A security design workshop at Alpine Ski House focuses on SharePoint documents. One mandatory capability is to configure DSPM for AI policies. Which answer best aligns with Microsoft Purview while helping keep policy behavior predictable? The pilot population is small today but the configuration must support a broader rollout. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The team has 176 historical events available for validation before enabling broader enforcement.
Correct answer: A
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
City Power & Light is replacing a manual process used by the risk management team for support tickets. The replacement must configure DSPM for AI policies. Which choice provides the most direct implementation while helping support investigation evidence? The implementation will be reviewed by both security and compliance stakeholders. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 32 protected items have been processed.
Correct answer: C
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services for support tickets. Which configuration should they use to avoid unnecessary user disruption? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The control owner must document the result for governance record SC401-9-028 before widening scope.
Correct answer: D
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
B: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
An incident review at A. Datum shows that the current process for SharePoint documents is incomplete. The team now needs to manage roles and permissions for DSPM for AI. Which action most directly addresses that need while helping support investigation evidence? The security lead wants the configuration to align with the supported Microsoft workflow. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 106 users across two business units and must preserve normal collaboration.
Correct answer: A
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
An incident review at Contoso shows that the current process for engineering designs is incomplete. The team now needs to monitor activities in DSPM for AI. Which action most directly addresses that need while helping avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 143 protected items have been processed.
Correct answer: B
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
Before enabling enforcement at Humongous Insurance, administrators must demonstrate how they will implement controls in Microsoft Purview to protect content in an environment that uses AI services for engineering designs. Which configuration should they use to use the narrowest effective control? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 180 historical events available for validation before enabling broader enforcement.
Correct answer: E
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
A Microsoft 365 administrator at A. Datum is asked to improve protection of financial workbooks. The success criterion is to implement controls in Microsoft Purview to protect content in an environment that uses AI services. What should be done if the implementation must use the narrowest effective control? The control must work with the organization’s existing Microsoft 365 governance model. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 36 representative files or events before sign-off.
Correct answer: B
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
A proof of concept at Litware will be accepted only if it can implement controls in Microsoft Purview to protect content in an environment that uses AI services for support tickets. The architect also wants to support a phased rollout. Which option should be selected? Administrators need evidence they can review after deployment. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 73 users and expands only after the security team signs off.
Correct answer: A
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
A change request from Humongous Insurance’s engineering department affects regulated case records. The stated objective is to implement prerequisites for Data Security Posture Management DSPM for AI. Which administrative action is the strongest fit if the team must keep the design auditable? The control must work with the organization’s existing Microsoft 365 governance model. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 110 policy evaluations to confirm expected behavior.
Correct answer: E
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
Correct answer: A
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
The risk management team at Alpine Ski House has two competing proposals for cloud application files. Only one directly enables the tenant to monitor activities in DSPM for AI. Which proposal should be chosen to keep policy behavior predictable? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 184 protected items have been processed.
Correct answer: C
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
The human resources group at Adventure Works is preparing a production rollout involving cloud application files. They specifically need to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. What should be configured first to use the narrowest effective control? Administrators need evidence they can review after deployment. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The implementation will be tested against 40 representative files or events before sign-off.
Correct answer: C
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
City Power & Light is standardizing protection for contract documents. The design must manage roles and permissions for DSPM for AI, and operations wants to keep the design auditable. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. A support team will observe the first 77 policy evaluations to confirm expected behavior.
Correct answer: B
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
During an audit at Alpine Ski House, reviewers ask how the tenant will implement prerequisites for Data Security Posture Management DSPM for AI. The implementation should keep the design auditable. Which choice is most appropriate? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The control owner must document the result for governance record SC401-9-039 before widening scope.
Correct answer: D
Why: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This directly matches the requirement in the scenario.
E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
Margie’s Travel’s collaboration services team is updating controls for scanned forms. The requirement is to configure DSPM for AI policies. The solution must also reduce false positives. Which action should the administrator take? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Administrators must be able to tune the configuration later without redesigning the entire protection model. The control owner must document the result for governance record SC401-9-040 before widening scope.
Correct answer: C
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
Following a policy review, Fabrikam changes how employee files is governed. The new requirement is to implement controls in Microsoft Purview to protect content in an environment that uses AI services. Which action is the best fit and will help keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The team has 188 historical events available for validation before enabling broader enforcement.
Correct answer: D
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
A proof of concept at Fourth Coffee will be accepted only if it can manage roles and permissions for DSPM for AI for employee files. The architect also wants to minimize administrative overhead. Which option should be selected? Administrators need evidence they can review after deployment. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. A support team will observe the first 44 policy evaluations to confirm expected behavior.
Correct answer: A
Why: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This directly matches the requirement in the scenario.
B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
Before enabling enforcement at Wide World Importers, administrators must demonstrate how they will configure DSPM for AI policies for SharePoint documents. Which configuration should they use to avoid unnecessary user disruption? Administrators need evidence they can review after deployment. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The team has 81 historical events available for validation before enabling broader enforcement.
Correct answer: B
Why: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
Option review:
A: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This directly matches the requirement in the scenario.
C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
An incident review at Northwind Traders shows that the current process for contract documents is incomplete. The team now needs to implement controls in Microsoft 365 productivity workloads to protect content in an environment that uses AI services. Which action most directly addresses that need while helping reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. Administrators must be able to tune the configuration later without redesigning the entire protection model. The change is tracked under control batch SC401-9-044 and will be reviewed after the first week.
Correct answer: C
Why: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This directly matches the requirement in the scenario.
D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
During an audit at Margie’s Travel, reviewers ask how the tenant will implement controls in Microsoft Purview to protect content in an environment that uses AI services. The implementation should support a phased rollout. Which choice is most appropriate? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The first phase affects 155 users across two business units and must preserve normal collaboration.
Correct answer: D
Why: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This directly matches the requirement in the scenario.
E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
For a new Microsoft 365 deployment at Margie’s Travel, the security operations team is responsible for SharePoint documents. They are required to monitor activities in DSPM for AI. Which implementation is correct if they also want to avoid changing unrelated workloads? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The initial scope covers 192 managed objects and must remain measurable during rollout.
Correct answer: E
Why: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Option review:
A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
B: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This directly matches the requirement in the scenario.
Learning point: Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
Popular posts
Recent Posts
