Microsoft SC-401 Insider Risk Management Policies Connectors Indicators And Cases Practice Test

 

Skill 3.1 • 85 original questions

This Microsoft SC-401 practice test focuses on insider risk management policies connectors indicators and cases through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.

Question 1

The collaboration services group at Fabrikam is preparing a production rollout involving employee files. They specifically need to manage Insider Risk Management workflow including notice templates. What should be configured first to preserve least privilege? The organization wants to avoid granting broader permissions than the task requires. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The control owner must document the result for governance record SC401-7-001 before widening scope.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: C

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 2

A Microsoft 365 administrator at Wingtip Toys is asked to improve protection of scanned forms. The success criterion is to configure and manage Insider Risk Management settings. What should be done if the implementation must reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Only the users and workloads named in the requirement should be affected during the first production phase. The control owner must document the result for governance record SC401-7-002 before widening scope.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  3. Assign Global Administrator to every investigator.
  4. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: B

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 3

The human resources group at A. Datum is preparing a production rollout involving support tickets. They specifically need to implement roles and permissions for Insider Risk Management. What should be configured first to preserve least privilege? Administrators need evidence they can review after deployment. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The pilot starts with 27 users and expands only after the security team signs off.

  1. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  4. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  5. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Correct answer: D

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

E: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 4

An incident review at Northwind Traders shows that the current process for scanned forms is incomplete. The team now needs to select an appropriate policy template. Which action most directly addresses that need while helping use the narrowest effective control? The team must be able to explain why the selected control addresses the stated risk. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The first phase affects 64 users across two business units and must preserve normal collaboration.

  1. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  4. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  5. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.

Correct answer: D

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 5

Before enabling enforcement at Trey Research, administrators must demonstrate how they will manage insider risk alerts and cases for email messages. Which configuration should they use to reduce false positives? The organization wants to avoid granting broader permissions than the task requires. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 101 policy evaluations to confirm expected behavior.

  1. Assign Global Administrator to every investigator.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  4. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  5. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Correct answer: B

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 6

Blue Yonder Airlines is replacing a manual process used by the legal team for financial workbooks. The replacement must enable and configure insider risk levels for Adaptive Protection. Which choice provides the most direct implementation while helping avoid changing unrelated workloads? The organization wants to avoid granting broader permissions than the task requires. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 138 historical events available for validation before enabling broader enforcement.

  1. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: A

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 7

A production issue at Fabrikam affects the handling of scanned forms. The root requirement is to plan and implement Insider Risk Management connectors. Which remediation best meets that requirement and helps support a phased rollout? The requirement applies to production data rather than a one-time demonstration. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The design review compares outcomes for 175 representative samples before production enablement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: B

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 8

A pilot at Consolidated Messenger involves employee files. The security lead asks for a configuration that will plan and implement integration with Microsoft Defender for Endpoint. Which approach best satisfies the requirement and helps reduce false positives? The team must be able to explain why the selected control addresses the stated risk. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The team has 31 historical events available for validation before enabling broader enforcement.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Assign Global Administrator to every investigator.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Correct answer: D

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 9

A change request from Blue Yonder Airlines’s data governance department affects cloud application files. The stated objective is to enable and configure insider risk levels for Adaptive Protection. Which administrative action is the strongest fit if the team must keep the design auditable? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 68 managed objects and must remain measurable during rollout.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  5. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Correct answer: B

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 10

Before enabling enforcement at Graphic Design Institute, administrators must demonstrate how they will plan and implement Insider Risk Management connectors for contract documents. Which configuration should they use to minimize administrative overhead? The team must be able to explain why the selected control addresses the stated risk. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The pilot starts with 105 users and expands only after the security team signs off.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Correct answer: A

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 11

For a new Microsoft 365 deployment at Adventure Works, the data governance team is responsible for SharePoint documents. They are required to plan and implement integration with Microsoft Defender for Endpoint. Which implementation is correct if they also want to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The design review compares outcomes for 142 representative samples before production enablement.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  3. Assign Global Administrator to every investigator.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Correct answer: E

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 12

A security design workshop at Alpine Ski House focuses on scanned forms. One mandatory capability is to plan and implement Insider Risk Management connectors. Which answer best aligns with Microsoft Purview while helping minimize administrative overhead? The team must be able to explain why the selected control addresses the stated risk. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-7-012 and will be reviewed after the first week.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  3. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: D

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 13

A proof of concept at Blue Yonder Airlines will be accepted only if it can manage forensic evidence settings for cloud application files. The architect also wants to keep policy behavior predictable. Which option should be selected? The control must work with the organization’s existing Microsoft 365 governance model. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The design review compares outcomes for 35 representative samples before production enablement.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: E

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 14

Fabrikam expects the volume of support tickets to increase significantly. The control must scale while allowing the team to enable and configure insider risk levels for Adaptive Protection. Which action best supports that objective and helps support investigation evidence? The requirement applies to production data rather than a one-time demonstration. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The rollout plan requires a measurable checkpoint after 72 protected items have been processed.

  1. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Assign Global Administrator to every investigator.
  4. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  5. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.

Correct answer: A

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 15

The collaboration services team at Margie’s Travel has two competing proposals for financial workbooks. Only one directly enables the tenant to manage Insider Risk Management workflow including notice templates. Which proposal should be chosen to use the narrowest effective control? The team wants the change to be reversible during pilot testing. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The pilot starts with 109 users and expands only after the security team signs off.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: D

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 16

A pilot at Trey Research involves regulated case records. The security lead asks for a configuration that will configure policy indicators. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The design should not depend on users remembering an optional manual step. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The initial scope covers 146 managed objects and must remain measurable during rollout.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  4. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: E

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 17

Following a policy review, Trey Research changes how contract documents is governed. The new requirement is to configure and manage Insider Risk Management settings. Which action is the best fit and will help keep the design auditable? Administrators need evidence they can review after deployment. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 183 policy evaluations to confirm expected behavior.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Assign Global Administrator to every investigator.
  3. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Correct answer: C

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 18

The human resources group at Blue Yonder Airlines is preparing a production rollout involving support tickets. They specifically need to configure policy indicators. What should be configured first to reduce false positives? Administrators need evidence they can review after deployment. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. Only the users and workloads named in the requirement should be affected during the first production phase. The rollout plan requires a measurable checkpoint after 39 protected items have been processed.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: E

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 19

For a new Microsoft 365 deployment at Margie’s Travel, the research team is responsible for SharePoint documents. They are required to manage forensic evidence settings. Which implementation is correct if they also want to avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 76 managed objects and must remain measurable during rollout.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  3. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  4. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: E

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 20

A Microsoft 365 administrator at Adventure Works is asked to improve protection of cloud application files. The success criterion is to manage Insider Risk Management workflow including notice templates. What should be done if the implementation must support investigation evidence? The control must work with the organization’s existing Microsoft 365 governance model. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The pilot starts with 113 users and expands only after the security team signs off.

  1. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  2. Assign Global Administrator to every investigator.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.

Correct answer: A

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 21

An incident review at City Power & Light shows that the current process for cloud application files is incomplete. The team now needs to plan and implement Insider Risk Management connectors. Which action most directly addresses that need while helping avoid changing unrelated workloads? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 150 policy evaluations to confirm expected behavior.

  1. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  2. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: D

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 22

Adventure Works expects the volume of financial workbooks to increase significantly. The control must scale while allowing the team to select an appropriate policy template. Which action best supports that objective and helps avoid changing unrelated workloads? The security lead wants the configuration to align with the supported Microsoft workflow. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The change is tracked under control batch SC401-7-022 and will be reviewed after the first week.

  1. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  2. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Correct answer: B

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 23

A compliance exception at Margie’s Travel can be closed only after the tenant can create and manage Insider Risk Management policies for cloud application files. What should the administrator implement if the goal is to avoid changing unrelated workloads? The requirement applies to production data rather than a one-time demonstration. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Only the users and workloads named in the requirement should be affected during the first production phase. The pilot starts with 43 users and expands only after the security team signs off.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  3. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  4. Assign Global Administrator to every investigator.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: C

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 24

The sales team at Wide World Importers has two competing proposals for scanned forms. Only one directly enables the tenant to configure and manage Insider Risk Management settings. Which proposal should be chosen to support a phased rollout? The design should not depend on users remembering an optional manual step. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The change is tracked under control batch SC401-7-024 and will be reviewed after the first week.

  1. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  4. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  5. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Correct answer: E

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 25

At Alpine Ski House, a review of Teams collaboration content found a gap. The administrator must enable and configure insider risk levels for Adaptive Protection, while the project team wants to use the narrowest effective control. What is the best next step? The requirement applies to production data rather than a one-time demonstration. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The team has 117 historical events available for validation before enabling broader enforcement.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: B

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 26

Alpine Ski House expects the volume of scanned forms to increase significantly. The control must scale while allowing the team to select an appropriate policy template. Which action best supports that objective and helps minimize administrative overhead? The pilot population is small today but the configuration must support a broader rollout. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 154 policy evaluations to confirm expected behavior.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Assign Global Administrator to every investigator.
  3. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  4. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: E

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 27

A compliance exception at Tailspin Toys can be closed only after the tenant can plan and implement Insider Risk Management connectors for Teams collaboration content. What should the administrator implement if the goal is to support a phased rollout? Administrators need evidence they can review after deployment. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 191 protected items have been processed.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: E

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 28

A proof of concept at Proseware will be accepted only if it can create and manage Insider Risk Management policies for engineering designs. The architect also wants to keep policy behavior predictable. Which option should be selected? The control must work with the organization’s existing Microsoft 365 governance model. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 47 users and expands only after the security team signs off.

  1. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: D

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 29

During an audit at Northwind Traders, reviewers ask how the tenant will manage insider risk alerts and cases. The implementation should avoid changing unrelated workloads. Which choice is most appropriate? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The control owner must document the result for governance record SC401-7-029 before widening scope.

  1. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  5. Assign Global Administrator to every investigator.

Correct answer: C

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 30

  1. Datum expects the volume of cloud application files to increase significantly. The control must scale while allowing the team to enable and configure insider risk levels for Adaptive Protection. Which action best supports that objective and helps keep the design auditable? The control must work with the organization’s existing Microsoft 365 governance model. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 121 historical events available for validation before enabling broader enforcement.
  2. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  3. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  4. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  5. Create a tenant-wide mail-flow rule that encrypts every message.
  6. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Correct answer: B

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 31

The legal team at Fourth Coffee has two competing proposals for financial workbooks. Only one directly enables the tenant to plan and implement Insider Risk Management connectors. Which proposal should be chosen to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Only the users and workloads named in the requirement should be affected during the first production phase. The change is tracked under control batch SC401-7-031 and will be reviewed after the first week.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  5. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Correct answer: B

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 32

Fabrikam expects the volume of regulated case records to increase significantly. The control must scale while allowing the team to manage insider risk alerts and cases. Which action best supports that objective and helps reduce false positives? The pilot population is small today but the configuration must support a broader rollout. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The control owner must document the result for governance record SC401-7-032 before widening scope.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Assign Global Administrator to every investigator.
  3. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  4. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  5. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Correct answer: D

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

E: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 33

An incident review at Margie’s Travel shows that the current process for email messages is incomplete. The team now needs to manage Insider Risk Management workflow including notice templates. Which action most directly addresses that need while helping reduce false positives? The pilot population is small today but the configuration must support a broader rollout. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The rollout plan requires a measurable checkpoint after 51 protected items have been processed.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: B

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 34

A compliance exception at Humongous Insurance can be closed only after the tenant can plan and implement Insider Risk Management connectors for cloud application files. What should the administrator implement if the goal is to support investigation evidence? The implementation will be reviewed by both security and compliance stakeholders. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The first phase affects 88 users across two business units and must preserve normal collaboration.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  3. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: A

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

B: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 35

During an audit at Wingtip Toys, reviewers ask how the tenant will implement roles and permissions for Insider Risk Management. The implementation should avoid unnecessary user disruption. Which choice is most appropriate? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 125 protected items have been processed.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Assign Global Administrator to every investigator.
  3. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Correct answer: A

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 36

Before enabling enforcement at Blue Yonder Airlines, administrators must demonstrate how they will configure policy indicators for Teams collaboration content. Which configuration should they use to preserve least privilege? The requirement applies to production data rather than a one-time demonstration. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The pilot starts with 162 users and expands only after the security team signs off.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  3. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Correct answer: D

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 37

During an audit at Consolidated Messenger, reviewers ask how the tenant will configure policy indicators. The implementation should support a phased rollout. Which choice is most appropriate? Administrators need evidence they can review after deployment. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The initial scope covers 199 managed objects and must remain measurable during rollout.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  5. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.

Correct answer: A

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

B: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 38

A pilot at Humongous Insurance involves email messages. The security lead asks for a configuration that will plan and implement integration with Microsoft Defender for Endpoint. Which approach best satisfies the requirement and helps support a phased rollout? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 55 managed objects and must remain measurable during rollout.

  1. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  2. Assign Global Administrator to every investigator.
  3. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Correct answer: E

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 39

The research team at Contoso has two competing proposals for engineering designs. Only one directly enables the tenant to plan and implement integration with Microsoft Defender for Endpoint. Which proposal should be chosen to keep policy behavior predictable? The organization wants to avoid granting broader permissions than the task requires. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. The rollout plan requires a measurable checkpoint after 92 protected items have been processed.

  1. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  2. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.

Correct answer: A

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

B: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 40

Northwind Traders is replacing a manual process used by the collaboration services team for Teams collaboration content. The replacement must create and manage Insider Risk Management policies. Which choice provides the most direct implementation while helping minimize administrative overhead? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 129 protected items have been processed.

  1. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  2. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: A

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 41

City Power & Light is replacing a manual process used by the engineering team for customer records. The replacement must configure policy indicators. Which choice provides the most direct implementation while helping avoid unnecessary user disruption? The requirement applies to production data rather than a one-time demonstration. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The team has 166 historical events available for validation before enabling broader enforcement.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  5. Assign Global Administrator to every investigator.

Correct answer: A

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 42

A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of email messages. The success criterion is to manage forensic evidence settings. What should be done if the implementation must support investigation evidence? The organization wants to avoid granting broader permissions than the task requires. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 22 users across two business units and must preserve normal collaboration.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  4. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: D

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 43

Fabrikam is replacing a manual process used by the human resources team for contract documents. The replacement must create and manage Insider Risk Management policies. Which choice provides the most direct implementation while helping use the narrowest effective control? The control must work with the organization’s existing Microsoft 365 governance model. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The first phase affects 59 users across two business units and must preserve normal collaboration.

  1. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: C

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 44

A production issue at Trey Research affects the handling of email messages. The root requirement is to manage forensic evidence settings. Which remediation best meets that requirement and helps keep policy behavior predictable? The control must work with the organization’s existing Microsoft 365 governance model. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 96 protected items have been processed.

  1. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  4. Assign Global Administrator to every investigator.
  5. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Correct answer: C

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 45

Following a policy review, Margie’s Travel changes how financial workbooks is governed. The new requirement is to manage insider risk alerts and cases. Which action is the best fit and will help keep the design auditable? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. Only the users and workloads named in the requirement should be affected during the first production phase. The design review compares outcomes for 133 representative samples before production enablement.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  5. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Correct answer: B

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 46

A proof of concept at Consolidated Messenger will be accepted only if it can plan and implement integration with Microsoft Defender for Endpoint for contract documents. The architect also wants to preserve least privilege. Which option should be selected? The control must work with the organization’s existing Microsoft 365 governance model. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The initial scope covers 170 managed objects and must remain measurable during rollout.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Correct answer: E

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 47

A production issue at Wide World Importers affects the handling of employee files. The root requirement is to configure policy indicators. Which remediation best meets that requirement and helps reduce false positives? The control must work with the organization’s existing Microsoft 365 governance model. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-7-047 and will be reviewed after the first week.

  1. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  2. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  3. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  4. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  5. Assign Global Administrator to every investigator.

Correct answer: D

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 48

During an audit at City Power & Light, reviewers ask how the tenant will configure and manage Insider Risk Management settings. The implementation should avoid changing unrelated workloads. Which choice is most appropriate? The pilot population is small today but the configuration must support a broader rollout. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Administrators must be able to tune the configuration later without redesigning the entire protection model. The pilot starts with 63 users and expands only after the security team signs off.

  1. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  2. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: A

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

B: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 49

At Tailspin Toys, a review of customer records found a gap. The administrator must implement roles and permissions for Insider Risk Management, while the project team wants to preserve least privilege. What is the best next step? The organization wants to avoid granting broader permissions than the task requires. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The team has 100 historical events available for validation before enabling broader enforcement.

  1. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: D

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 50

A Microsoft 365 administrator at Litware is asked to improve protection of employee files. The success criterion is to manage Insider Risk Management workflow including notice templates. What should be done if the implementation must minimize administrative overhead? The design should not depend on users remembering an optional manual step. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 137 users and expands only after the security team signs off.

  1. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  2. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  3. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Assign Global Administrator to every investigator.

Correct answer: D

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 51

Northwind Traders’s research team is updating controls for cloud application files. The requirement is to select an appropriate policy template. The solution must also keep policy behavior predictable. Which action should the administrator take? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The implementation will be tested against 174 representative files or events before sign-off.

  1. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  2. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  3. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.

Correct answer: C

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 52

City Power & Light is standardizing protection for support tickets. The design must manage insider risk alerts and cases, and operations wants to keep policy behavior predictable. What should the information security administrator do? The design should not depend on users remembering an optional manual step. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The team has 30 historical events available for validation before enabling broader enforcement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.

Correct answer: B

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 53

Alpine Ski House expects the volume of cloud application files to increase significantly. The control must scale while allowing the team to create and manage Insider Risk Management policies. Which action best supports that objective and helps keep the design auditable? The security lead wants the configuration to align with the supported Microsoft workflow. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 67 managed objects and must remain measurable during rollout.

  1. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  2. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  3. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  4. Assign Global Administrator to every investigator.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: B

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 54

Following a policy review, Fabrikam changes how Teams collaboration content is governed. The new requirement is to manage Insider Risk Management workflow including notice templates. Which action is the best fit and will help minimize administrative overhead? The security lead wants the configuration to align with the supported Microsoft workflow. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The pilot starts with 104 users and expands only after the security team signs off.

  1. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  4. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: A

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 55

A compliance exception at Margie’s Travel can be closed only after the tenant can plan and implement Insider Risk Management connectors for support tickets. What should the administrator implement if the goal is to keep the design auditable? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. Only the users and workloads named in the requirement should be affected during the first production phase. The pilot starts with 141 users and expands only after the security team signs off.

  1. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: D

Why: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

Option review:

A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This directly matches the requirement in the scenario.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Question 56

Following a policy review, Margie’s Travel changes how Teams collaboration content is governed. The new requirement is to manage forensic evidence settings. Which action is the best fit and will help preserve least privilege? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The rollout plan requires a measurable checkpoint after 178 protected items have been processed.

  1. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  2. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  3. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  4. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  5. Assign Global Administrator to every investigator.

Correct answer: B

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 57

A change request from Northwind Traders’s compliance department affects customer records. The stated objective is to configure and manage Insider Risk Management settings. Which administrative action is the strongest fit if the team must keep policy behavior predictable? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 34 representative samples before production enablement.

  1. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  2. Create a tenant-wide mail-flow rule that encrypts every message.
  3. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  4. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  5. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Correct answer: E

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

C: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 58

Margie’s Travel is replacing a manual process used by the sales team for financial workbooks. The replacement must configure and manage Insider Risk Management settings. Which choice provides the most direct implementation while helping avoid unnecessary user disruption? The team must be able to explain why the selected control addresses the stated risk. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 71 protected items have been processed.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  3. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  4. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  5. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.

Correct answer: B

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 59

A change request from Tailspin Toys’s engineering department affects financial workbooks. The stated objective is to manage forensic evidence settings. Which administrative action is the strongest fit if the team must support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The design review compares outcomes for 108 representative samples before production enablement.

  1. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
  2. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  3. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  4. Assign Global Administrator to every investigator.
  5. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Correct answer: B

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 60

The governance board at City Power & Light approves a control for customer records on the condition that administrators can select an appropriate policy template. What should the team do to keep policy behavior predictable? The team must be able to explain why the selected control addresses the stated risk. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The control owner must document the result for governance record SC401-7-060 before widening scope.

  1. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  2. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  5. Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.

Correct answer: A

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 61

Proseware’s data governance team is updating controls for contract documents. The requirement is to enable and configure insider risk levels for Adaptive Protection. The solution must also support investigation evidence. Which action should the administrator take? Administrators need evidence they can review after deployment. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The team has 182 historical events available for validation before enabling broader enforcement.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  4. Replace Purview investigation with a generic Azure Monitor alert.
  5. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Correct answer: E

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

E: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 62

A security design workshop at Northwind Traders focuses on SharePoint documents. One mandatory capability is to implement roles and permissions for Insider Risk Management. Which answer best aligns with Microsoft Purview while helping keep policy behavior predictable? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The design review compares outcomes for 38 representative samples before production enablement.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  4. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  5. Assign Global Administrator to every investigator.

Correct answer: A

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 63

A proof of concept at Contoso will be accepted only if it can select an appropriate policy template for support tickets. The architect also wants to support a phased rollout. Which option should be selected? The implementation will be reviewed by both security and compliance stakeholders. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 75 policy evaluations to confirm expected behavior.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Correct answer: E

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 64

The governance board at City Power & Light approves a control for financial workbooks on the condition that administrators can plan and implement integration with Microsoft Defender for Endpoint. What should the team do to keep the design auditable? The implementation will be reviewed by both security and compliance stakeholders. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-7-064 and will be reviewed after the first week.

  1. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: D

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 65

An incident review at Alpine Ski House shows that the current process for cloud application files is incomplete. The team now needs to implement roles and permissions for Insider Risk Management. Which action most directly addresses that need while helping avoid changing unrelated workloads? The team must be able to explain why the selected control addresses the stated risk. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The control owner must document the result for governance record SC401-7-065 before widening scope.

  1. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  2. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  3. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  4. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  5. Assign Global Administrator to every investigator.

Correct answer: C

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 66

Proseware’s collaboration services team is updating controls for Teams collaboration content. The requirement is to configure policy indicators. The solution must also use the narrowest effective control. Which action should the administrator take? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The rollout plan requires a measurable checkpoint after 186 protected items have been processed.

  1. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Create a tenant-wide mail-flow rule that encrypts every message.
  5. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.

Correct answer: A

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Question 67

A security design workshop at Northwind Traders focuses on SharePoint documents. One mandatory capability is to manage insider risk alerts and cases. Which answer best aligns with Microsoft Purview while helping avoid unnecessary user disruption? The organization wants to avoid granting broader permissions than the task requires. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-7-067 and will be reviewed after the first week.

  1. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
  2. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  3. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  4. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: D

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 68

An incident review at Wide World Importers shows that the current process for regulated case records is incomplete. The team now needs to enable and configure insider risk levels for Adaptive Protection. Which action most directly addresses that need while helping keep the design auditable? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. A support team will observe the first 79 policy evaluations to confirm expected behavior.

  1. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Assign Global Administrator to every investigator.
  4. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: B

Why: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

Option review:

A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This directly matches the requirement in the scenario.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.

Question 69

Following a policy review, Litware changes how customer records is governed. The new requirement is to plan and implement integration with Microsoft Defender for Endpoint. Which action is the best fit and will help support a phased rollout? Administrators need evidence they can review after deployment. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 116 representative samples before production enablement.

  1. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  2. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: B

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 70

Trey Research’s research team is updating controls for customer records. The requirement is to implement roles and permissions for Insider Risk Management. The solution must also keep policy behavior predictable. Which action should the administrator take? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The pilot starts with 153 users and expands only after the security team signs off.

  1. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  2. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Correct answer: E

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 71

A proof of concept at Wide World Importers will be accepted only if it can manage insider risk alerts and cases for email messages. The architect also wants to minimize administrative overhead. Which option should be selected? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 190 users across two business units and must preserve normal collaboration.

  1. Assign Global Administrator to every investigator.
  2. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  3. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  4. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  5. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.

Correct answer: C

Why: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

Option review:

A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This directly matches the requirement in the scenario.

D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.

Question 72

The governance board at Graphic Design Institute approves a control for support tickets on the condition that administrators can manage forensic evidence settings. What should the team do to minimize administrative overhead? Administrators need evidence they can review after deployment. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. Only the users and workloads named in the requirement should be affected during the first production phase. A support team will observe the first 46 policy evaluations to confirm expected behavior.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  5. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Correct answer: E

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 73

The collaboration services group at Alpine Ski House is preparing a production rollout involving scanned forms. They specifically need to configure and manage Insider Risk Management settings. What should be configured first to support investigation evidence? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The first phase affects 83 users across two business units and must preserve normal collaboration.

  1. Replace Purview investigation with a generic Azure Monitor alert.
  2. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  3. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.
  4. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  5. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Correct answer: C

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

D: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 74

A security design workshop at Margie’s Travel focuses on contract documents. One mandatory capability is to plan and implement integration with Microsoft Defender for Endpoint. Which answer best aligns with Microsoft Purview while helping support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-7-074 and will be reviewed after the first week.

  1. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  2. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  3. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  4. Assign Global Administrator to every investigator.
  5. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.

Correct answer: C

Why: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

Option review:

A: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This directly matches the requirement in the scenario.

D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

E: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.

Question 75

The governance board at Humongous Insurance approves a control for Teams collaboration content on the condition that administrators can create and manage Insider Risk Management policies. What should the team do to reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 157 protected items have been processed.

  1. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  2. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  3. Create a tenant-wide mail-flow rule that encrypts every message.
  4. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: B

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

D: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 76

A production issue at City Power & Light affects the handling of support tickets. The root requirement is to select an appropriate policy template. Which remediation best meets that requirement and helps keep the design auditable? The pilot population is small today but the configuration must support a broader rollout. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. A support team will observe the first 194 policy evaluations to confirm expected behavior.

  1. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  2. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.
  3. Replace Purview investigation with a generic Azure Monitor alert.
  4. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: D

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 77

The research group at Proseware is preparing a production rollout involving email messages. They specifically need to configure and manage Insider Risk Management settings. What should be configured first to preserve least privilege? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Only the users and workloads named in the requirement should be affected during the first production phase. The first phase affects 50 users across two business units and must preserve normal collaboration.

  1. Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
  2. Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
  3. Assign Global Administrator to every investigator.
  4. Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
  5. Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Correct answer: E

Why: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Option review:

A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

D: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This directly matches the requirement in the scenario.

Learning point: Configure Insider Risk Management settings such as analytics, privacy, alert thresholds, intelligent detections, exclusions, and policy time windows to match the organization’s investigation model.

Question 78

A pilot at Wingtip Toys involves email messages. The security lead asks for a configuration that will manage forensic evidence settings. Which approach best satisfies the requirement and helps use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The implementation will be tested against 87 representative files or events before sign-off.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Triage the insider-risk alert, review the user timeline and contributing signals, then dismiss it or promote it to a case for deeper investigation and documented actions.
  3. Use DSPM for AI posture views, risk indicators, activity insights, and related Purview investigation data to monitor how sensitive data is being exposed to or used with AI services.
  4. Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.
  5. Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.

Correct answer: D

Why: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This directly matches the requirement in the scenario.

E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Configure forensic evidence only for the approved users, devices, activities, and capture limits, with the required legal and privacy governance, before enabling evidence collection.

Question 79

A Microsoft 365 administrator at Alpine Ski House is asked to improve protection of support tickets. The success criterion is to implement roles and permissions for Insider Risk Management. What should be done if the implementation must avoid changing unrelated workloads? The control must work with the organization’s existing Microsoft 365 governance model. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The initial scope covers 124 managed objects and must remain measurable during rollout.

  1. Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  4. Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
  5. Configure the required Insider Risk Management data connector when the policy needs signals from an external or supported business source that is not collected natively.

Correct answer: C

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 80

A security design workshop at Northwind Traders focuses on Teams collaboration content. One mandatory capability is to create and manage Insider Risk Management policies. Which answer best aligns with Microsoft Purview while helping avoid changing unrelated workloads? The implementation will be reviewed by both security and compliance stakeholders. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The control owner must document the result for governance record SC401-7-080 before widening scope.

  1. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  4. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  5. Assign Global Administrator to every investigator.

Correct answer: C

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 81

Following a policy review, Wide World Importers changes how customer records is governed. The new requirement is to select an appropriate policy template. Which action is the best fit and will help use the narrowest effective control? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The first phase affects 198 users across two business units and must preserve normal collaboration.

  1. Create a tenant-wide mail-flow rule that encrypts every message.
  2. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  3. Configure DSPM for AI policies around the identified risk objectives, such as oversharing or data exfiltration to AI apps, then scope and tune the policies to the organization’s approved AI usage.
  4. Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.
  5. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.

Correct answer: D

Why: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

Option review:

A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This directly matches the requirement in the scenario.

E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

Learning point: Choose the Insider Risk Management policy template whose triggering event and risk scenario best match the organization’s use case before customizing indicators and thresholds.

Question 82

A compliance exception at Litware can be closed only after the tenant can create and manage Insider Risk Management policies for regulated case records. What should the administrator implement if the goal is to keep policy behavior predictable? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The first phase affects 54 users across two business units and must preserve normal collaboration.

  1. Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.
  2. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  3. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  4. Reduce oversharing in Microsoft 365 by correcting site, group, file, and sharing permissions and applying appropriate sensitivity and DLP controls before relying on AI experiences that can surface that content.
  5. Replace Purview investigation with a generic Azure Monitor alert.

Correct answer: A

Why: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

Option review:

A: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This directly matches the requirement in the scenario.

B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

Learning point: Create the insider-risk policy from the appropriate template, scope users or groups, configure triggers, indicators, thresholds, and review windows, then validate alerts and tune the policy.

Question 83

A security design workshop at Trey Research focuses on contract documents. One mandatory capability is to implement roles and permissions for Insider Risk Management. Which answer best aligns with Microsoft Purview while helping avoid changing unrelated workloads? The security lead wants the configuration to align with the supported Microsoft workflow. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 91 managed objects and must remain measurable during rollout.

  1. Use Purview classification, sensitivity labels, DLP, insider-risk, and data-security controls to prevent sensitive organizational content from being overshared or inappropriately used by AI services.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.
  4. Enable Adaptive Protection and map insider-risk levels to the downstream protection controls that should become more restrictive as user risk increases.
  5. Assign Global Administrator to every investigator.

Correct answer: C

Why: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

Option review:

A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This directly matches the requirement in the scenario.

D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.

Learning point: Assign the specific Insider Risk Management role group needed for configuration, analysis, or investigation while separating administrators from investigators where duties require it.

Question 84

A pilot at Northwind Traders involves cloud application files. The security lead asks for a configuration that will manage Insider Risk Management workflow including notice templates. Which approach best satisfies the requirement and helps keep policy behavior predictable? The design should not depend on users remembering an optional manual step. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The pilot starts with 128 users and expands only after the security team signs off.

  1. Satisfy the required Purview licensing, permissions, data connections, and supported Microsoft 365 or AI service prerequisites before enabling DSPM for AI insights and controls.
  2. Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
  3. Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.
  4. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  5. Create a tenant-wide mail-flow rule that encrypts every message.

Correct answer: C

Why: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This directly matches the requirement in the scenario.

D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.

Learning point: Use the Insider Risk Management workflow and approved notice templates to document investigation steps and communicate with users consistently when policy and legal processes require a notice.

Question 85

An incident review at Alpine Ski House shows that the current process for engineering designs is incomplete. The team now needs to configure policy indicators. Which action most directly addresses that need while helping preserve least privilege? The team must be able to explain why the selected control addresses the stated risk. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The design review compares outcomes for 165 representative samples before production enablement.

  1. Grant the least-privileged DSPM for AI or Purview security/compliance role needed for the user’s task, and add content-viewing roles only when item-level file details are required.
  2. Replace Purview investigation with a generic Azure Monitor alert.
  3. Enable the supported Defender for Endpoint integration when insider-risk policies need device security signals and endpoint activity context from Defender.
  4. Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
  5. Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Correct answer: E

Why: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Option review:

A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.

C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.

E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This directly matches the requirement in the scenario.

Learning point: Enable only the relevant insider-risk indicators and set thresholds that reflect the risky behavior the policy is intended to detect.

Popular posts

img