Microsoft SC-401 Purview Audit Activity Explorer Alerts Defender XDR And eDiscovery Practice Test
Skill 3.2 • 69 original questions
This Microsoft SC-401 practice test focuses on purview audit activity explorer alerts defender xdr and ediscovery through original scenario-based questions aligned to the active July 28, 2026 Microsoft Learn blueprint. Use the complete ExamSnap SC-401 collection for practice across information protection, DLP and retention, insider risk, investigations, and AI data security. For broader exam preparation, review the Microsoft SC-401 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; every option includes a reason it is or is not the best fit.
A pilot at Trey Research involves engineering designs. The security lead asks for a configuration that will respond to Purview alerts in Microsoft Defender XDR. Which approach best satisfies the requirement and helps minimize administrative overhead? Administrators need evidence they can review after deployment. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. A support team will observe the first 145 policy evaluations to confirm expected behavior.
Correct answer: A
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
D: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
A security design workshop at Proseware focuses on employee files. One mandatory capability is to perform searches by using eDiscovery. Which answer best aligns with Microsoft Purview while helping reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 182 representative files or events before sign-off.
Correct answer: D
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
A compliance exception at Wingtip Toys can be closed only after the tenant can configure audit retention policies for employee files. What should the administrator implement if the goal is to minimize administrative overhead? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-8-003 and will be reviewed after the first week.
Correct answer: A
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
A compliance exception at Trey Research can be closed only after the tenant can assign Microsoft Purview Audit Premium user licenses for customer records. What should the administrator implement if the goal is to minimize administrative overhead? The team wants the change to be reversible during pilot testing. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The first phase affects 75 users across two business units and must preserve normal collaboration.
Correct answer: A
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
Margie’s Travel’s IT operations team is updating controls for financial workbooks. The requirement is to investigate activities by using Microsoft Purview Audit. The solution must also reduce false positives. Which action should the administrator take? The pilot population is small today but the configuration must support a broader rollout. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 112 protected items have been processed.
Correct answer: D
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
Before enabling enforcement at Consolidated Messenger, administrators must demonstrate how they will assign Microsoft Purview Audit Premium user licenses for Teams collaboration content. Which configuration should they use to keep the design auditable? The design should not depend on users remembering an optional manual step. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The team has 149 historical events available for validation before enabling broader enforcement.
Correct answer: C
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
Following a policy review, Northwind Traders changes how financial workbooks is governed. The new requirement is to analyze Purview activities by using Activity explorer. Which action is the best fit and will help avoid changing unrelated workloads? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The rollout plan requires a measurable checkpoint after 186 protected items have been processed.
Correct answer: D
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
Consolidated Messenger is standardizing protection for employee files. The design must investigate insider risk activities by using the Microsoft Purview portal, and operations wants to keep the design auditable. What should the information security administrator do? The security lead wants the configuration to align with the supported Microsoft workflow. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 42 users across two business units and must preserve normal collaboration.
Correct answer: C
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
D: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
Before enabling enforcement at City Power & Light, administrators must demonstrate how they will perform searches by using eDiscovery for engineering designs. Which configuration should they use to minimize administrative overhead? The design should not depend on users remembering an optional manual step. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 79 historical events available for validation before enabling broader enforcement.
Correct answer: A
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
The data governance team at A. Datum has two competing proposals for contract documents. Only one directly enables the tenant to respond to data loss prevention alerts in the Microsoft Purview portal. Which proposal should be chosen to keep policy behavior predictable? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 116 representative samples before production enablement.
Correct answer: B
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
An incident review at Fourth Coffee shows that the current process for support tickets is incomplete. The team now needs to analyze Purview activities by using Activity explorer. Which action most directly addresses that need while helping minimize administrative overhead? The team must be able to explain why the selected control addresses the stated risk. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The rollout plan requires a measurable checkpoint after 153 protected items have been processed.
Correct answer: A
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
An incident review at Litware shows that the current process for engineering designs is incomplete. The team now needs to assign Microsoft Purview Audit Premium user licenses. Which action most directly addresses that need while helping keep the design auditable? The design should not depend on users remembering an optional manual step. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 190 representative files or events before sign-off.
Correct answer: A
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
The IT operations team at Woodgrove Bank has two competing proposals for regulated case records. Only one directly enables the tenant to investigate insider risk activities by using the Microsoft Purview portal. Which proposal should be chosen to keep the design auditable? The control must work with the organization’s existing Microsoft 365 governance model. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. Only the users and workloads named in the requirement should be affected during the first production phase. The first phase affects 46 users across two business units and must preserve normal collaboration.
Correct answer: A
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
A compliance exception at A. Datum can be closed only after the tenant can respond to Purview alerts in Microsoft Defender XDR for customer records. What should the administrator implement if the goal is to preserve least privilege? The team wants the change to be reversible during pilot testing. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The pilot starts with 83 users and expands only after the security team signs off.
Correct answer: B
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
Humongous Insurance is replacing a manual process used by the finance team for employee files. The replacement must configure audit retention policies. Which choice provides the most direct implementation while helping minimize administrative overhead? The team wants the change to be reversible during pilot testing. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The control owner must document the result for governance record SC401-8-015 before widening scope.
Correct answer: A
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
At Consolidated Messenger, a review of customer records found a gap. The administrator must investigate insider risk activities by using the Microsoft Purview portal, while the project team wants to avoid changing unrelated workloads. What is the best next step? The design should not depend on users remembering an optional manual step. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The implementation will be tested against 157 representative files or events before sign-off.
Correct answer: B
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
Consolidated Messenger’s research team is updating controls for SharePoint documents. The requirement is to analyze Purview activities by using Activity explorer. The solution must also reduce false positives. Which action should the administrator take? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. Only the users and workloads named in the requirement should be affected during the first production phase. The team has 194 historical events available for validation before enabling broader enforcement.
Correct answer: E
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
Fabrikam’s finance team is updating controls for Teams collaboration content. The requirement is to investigate activities by using Microsoft Purview Audit. The solution must also minimize administrative overhead. Which action should the administrator take? The design should not depend on users remembering an optional manual step. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The design review compares outcomes for 50 representative samples before production enablement.
Correct answer: E
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
Following a policy review, Trey Research changes how contract documents is governed. The new requirement is to configure audit retention policies. Which action is the best fit and will help preserve least privilege? The design should not depend on users remembering an optional manual step. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The team has 87 historical events available for validation before enabling broader enforcement.
Correct answer: C
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
An incident review at Tailspin Toys shows that the current process for support tickets is incomplete. The team now needs to perform searches by using eDiscovery. Which action most directly addresses that need while helping support a phased rollout? The control must work with the organization’s existing Microsoft 365 governance model. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The rollout plan requires a measurable checkpoint after 124 protected items have been processed.
Correct answer: A
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
B: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
City Power & Light is standardizing protection for email messages. The design must respond to data loss prevention alerts in the Microsoft Purview portal, and operations wants to avoid changing unrelated workloads. What should the information security administrator do? The team wants the change to be reversible during pilot testing. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The pilot starts with 161 users and expands only after the security team signs off.
Correct answer: E
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
Fabrikam expects the volume of cloud application files to increase significantly. The control must scale while allowing the team to configure audit retention policies. Which action best supports that objective and helps keep the design auditable? The design should not depend on users remembering an optional manual step. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The rollout plan requires a measurable checkpoint after 198 protected items have been processed.
Correct answer: A
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
B: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
A production issue at Fabrikam affects the handling of employee files. The root requirement is to respond to Purview alerts in Microsoft Defender XDR. Which remediation best meets that requirement and helps support a phased rollout? The design should not depend on users remembering an optional manual step. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 54 representative samples before production enablement.
Correct answer: D
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
Margie’s Travel is standardizing protection for support tickets. The design must respond to Defender for Cloud Apps file policy alerts, and operations wants to avoid unnecessary user disruption. What should the information security administrator do? The team wants the change to be reversible during pilot testing. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. Only the users and workloads named in the requirement should be affected during the first production phase. The initial scope covers 91 managed objects and must remain measurable during rollout.
Correct answer: C
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
The finance group at A. Datum is preparing a production rollout involving financial workbooks. They specifically need to perform searches by using eDiscovery. What should be configured first to keep policy behavior predictable? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 128 representative files or events before sign-off.
Correct answer: D
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
The governance board at Tailspin Toys approves a control for scanned forms on the condition that administrators can investigate insider risk activities by using the Microsoft Purview portal. What should the team do to support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. A support team will observe the first 165 policy evaluations to confirm expected behavior.
Correct answer: C
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
A Microsoft 365 administrator at Humongous Insurance is asked to improve protection of support tickets. The success criterion is to analyze Purview activities by using Activity explorer. What should be done if the implementation must support a phased rollout? Administrators need evidence they can review after deployment. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 21 policy evaluations to confirm expected behavior.
Correct answer: E
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
Trey Research is standardizing protection for support tickets. The design must perform searches by using eDiscovery, and operations wants to avoid changing unrelated workloads. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The control owner must document the result for governance record SC401-8-028 before widening scope.
Correct answer: C
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
Following a policy review, Trey Research changes how cloud application files is governed. The new requirement is to analyze Purview activities by using Activity explorer. Which action is the best fit and will help avoid unnecessary user disruption? The design should not depend on users remembering an optional manual step. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The initial scope covers 95 managed objects and must remain measurable during rollout.
Correct answer: C
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
Margie’s Travel is standardizing protection for engineering designs. The design must investigate activities by using Microsoft Purview Audit, and operations wants to reduce false positives. What should the information security administrator do? The implementation will be reviewed by both security and compliance stakeholders. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. A support team will observe the first 132 policy evaluations to confirm expected behavior.
Correct answer: E
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
Following a policy review, A. Datum changes how SharePoint documents is governed. The new requirement is to assign Microsoft Purview Audit Premium user licenses. Which action is the best fit and will help support investigation evidence? The team must be able to explain why the selected control addresses the stated risk. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-8-031 before widening scope.
Correct answer: B
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
During an audit at Fabrikam, reviewers ask how the tenant will investigate insider risk activities by using the Microsoft Purview portal. The implementation should use the narrowest effective control. Which choice is most appropriate? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The governance board has rejected broad tenant-wide changes when a narrower supported scope can meet the same requirement. The pilot starts with 25 users and expands only after the security team signs off.
Correct answer: C
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI depends on tenant prerequisites and connected data signals; missing licensing, permissions, or service integration prevents complete posture visibility and policy operation. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
A security design workshop at Woodgrove Bank focuses on email messages. One mandatory capability is to configure audit retention policies. Which answer best aligns with Microsoft Purview while helping preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The support team needs clear evidence of what matched, which control acted, and what the user experienced. A support team will observe the first 62 policy evaluations to confirm expected behavior.
Correct answer: E
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
Woodgrove Bank is standardizing protection for SharePoint documents. The design must respond to data loss prevention alerts in the Microsoft Purview portal, and operations wants to keep policy behavior predictable. What should the information security administrator do? The team must be able to explain why the selected control addresses the stated risk. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The first phase affects 99 users across two business units and must preserve normal collaboration.
Correct answer: C
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
A compliance exception at Northwind Traders can be closed only after the tenant can perform searches by using eDiscovery for SharePoint documents. What should the administrator implement if the goal is to keep policy behavior predictable? The team wants the change to be reversible during pilot testing. The organization is preparing for an external audit and must demonstrate that the selected feature matches the specific risk rather than an adjacent capability. Administrators must be able to tune the configuration later without redesigning the entire protection model. The design review compares outcomes for 136 representative samples before production enablement.
Correct answer: A
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
Humongous Insurance is standardizing protection for Teams collaboration content. The design must analyze Purview activities by using Activity explorer, and operations wants to avoid unnecessary user disruption. What should the information security administrator do? The team wants the change to be reversible during pilot testing. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The rollout plan requires a measurable checkpoint after 173 protected items have been processed.
Correct answer: D
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
E: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
For a new Microsoft 365 deployment at Trey Research, the IT operations team is responsible for scanned forms. They are required to investigate insider risk activities by using the Microsoft Purview portal. Which implementation is correct if they also want to reduce false positives? The implementation will be reviewed by both security and compliance stakeholders. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The pilot starts with 29 users and expands only after the security team signs off.
Correct answer: A
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
For a new Microsoft 365 deployment at Proseware, the legal team is responsible for cloud application files. They are required to respond to Purview alerts in Microsoft Defender XDR. Which implementation is correct if they also want to minimize administrative overhead? The pilot population is small today but the configuration must support a broader rollout. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The team has 66 historical events available for validation before enabling broader enforcement.
Correct answer: D
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
A proof of concept at Wide World Importers will be accepted only if it can investigate activities by using Microsoft Purview Audit for contract documents. The architect also wants to avoid unnecessary user disruption. Which option should be selected? Administrators need evidence they can review after deployment. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The team has 103 historical events available for validation before enabling broader enforcement.
Correct answer: D
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
At Tailspin Toys, a review of customer records found a gap. The administrator must assign Microsoft Purview Audit Premium user licenses, while the project team wants to preserve least privilege. What is the best next step? The security lead wants the configuration to align with the supported Microsoft workflow. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The design review compares outcomes for 140 representative samples before production enablement.
Correct answer: D
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
For a new Microsoft 365 deployment at Contoso, the finance team is responsible for scanned forms. They are required to perform searches by using eDiscovery. Which implementation is correct if they also want to support a phased rollout? The team wants the change to be reversible during pilot testing. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The pilot starts with 177 users and expands only after the security team signs off.
Correct answer: B
Why: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
Option review:
A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This directly matches the requirement in the scenario.
C: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Microsoft Purview eDiscovery to define the case and custodians or data sources, create a search query, estimate and review results, and export or preserve content when the legal workflow requires it.
At Fourth Coffee, a review of SharePoint documents found a gap. The administrator must investigate activities by using Microsoft Purview Audit, while the project team wants to reduce false positives. What is the best next step? Administrators need evidence they can review after deployment. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 33 users and expands only after the security team signs off.
Correct answer: C
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
D: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
The IT operations team at Alpine Ski House has two competing proposals for Teams collaboration content. Only one directly enables the tenant to configure audit retention policies. Which proposal should be chosen to use the narrowest effective control? The implementation will be reviewed by both security and compliance stakeholders. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The pilot starts with 70 users and expands only after the security team signs off.
Correct answer: E
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
For a new Microsoft 365 deployment at Margie’s Travel, the legal team is responsible for financial workbooks. They are required to respond to data loss prevention alerts in the Microsoft Purview portal. Which implementation is correct if they also want to preserve least privilege? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The change is tracked under control batch SC401-8-044 and will be reviewed after the first week.
Correct answer: A
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Templates provide scenario-specific defaults for cases such as departing users or data leaks; matching the template to the risk scenario gives the policy the correct starting logic. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
The governance board at Litware approves a control for email messages on the condition that administrators can respond to data loss prevention alerts in the Microsoft Purview portal. What should the team do to avoid unnecessary user disruption? The pilot population is small today but the configuration must support a broader rollout. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 144 policy evaluations to confirm expected behavior.
Correct answer: A
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
A security design workshop at Graphic Design Institute focuses on SharePoint documents. One mandatory capability is to respond to data loss prevention alerts in the Microsoft Purview portal. Which answer best aligns with Microsoft Purview while helping preserve least privilege? The pilot population is small today but the configuration must support a broader rollout. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The initial scope covers 181 managed objects and must remain measurable during rollout.
Correct answer: C
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
Before enabling enforcement at Alpine Ski House, administrators must demonstrate how they will investigate insider risk activities by using the Microsoft Purview portal for customer records. Which configuration should they use to preserve least privilege? Administrators need evidence they can review after deployment. A cloud-adoption project is moving a manual compliance process into Purview and needs a control that can be operated by delegated administrators. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-8-047 and will be reviewed after the first week.
Correct answer: C
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
During an audit at City Power & Light, reviewers ask how the tenant will respond to Defender for Cloud Apps file policy alerts. The implementation should minimize administrative overhead. Which choice is most appropriate? The requirement applies to production data rather than a one-time demonstration. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The control owner must document the result for governance record SC401-8-048 before widening scope.
Correct answer: E
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
A production issue at City Power & Light affects the handling of Teams collaboration content. The root requirement is to configure audit retention policies. Which remediation best meets that requirement and helps keep policy behavior predictable? The requirement applies to production data rather than a one-time demonstration. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The first phase affects 111 users across two business units and must preserve normal collaboration.
Correct answer: B
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
B: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
C: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
For a new Microsoft 365 deployment at A. Datum, the security operations team is responsible for support tickets. They are required to respond to Defender for Cloud Apps file policy alerts. Which implementation is correct if they also want to reduce false positives? The pilot population is small today but the configuration must support a broader rollout. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. A support team will observe the first 148 policy evaluations to confirm expected behavior.
Correct answer: C
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
A change request from Trey Research’s research department affects email messages. The stated objective is to assign Microsoft Purview Audit Premium user licenses. Which administrative action is the strongest fit if the team must reduce false positives? Administrators need evidence they can review after deployment. A regional migration moved legacy records into Microsoft 365 and exposed inconsistent handling between teams. The change window is limited, so the team prefers a native Purview capability over a custom automation layer. The change is tracked under control batch SC401-8-051 and will be reviewed after the first week.
Correct answer: C
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
For a new Microsoft 365 deployment at Wingtip Toys, the security operations team is responsible for employee files. They are required to respond to Defender for Cloud Apps file policy alerts. Which implementation is correct if they also want to reduce false positives? The requirement applies to production data rather than a one-time demonstration. A privacy review requires the security team to minimize unnecessary exposure of item-level content while still proving the control works. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The implementation will be tested against 41 representative files or events before sign-off.
Correct answer: E
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
The engineering team at Margie’s Travel has two competing proposals for contract documents. Only one directly enables the tenant to respond to data loss prevention alerts in the Microsoft Purview portal. Which proposal should be chosen to avoid unnecessary user disruption? The requirement applies to production data rather than a one-time demonstration. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 78 managed objects and must remain measurable during rollout.
Correct answer: E
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: Insider Risk Management exposes dedicated role groups so policy management and case investigation can be delegated without unnecessary access to sensitive investigations. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
D: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
A pilot at Fabrikam involves scanned forms. The security lead asks for a configuration that will analyze Purview activities by using Activity explorer. Which approach best satisfies the requirement and helps avoid unnecessary user disruption? The security lead wants the configuration to align with the supported Microsoft workflow. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The change is tracked under control batch SC401-8-054 and will be reviewed after the first week.
Correct answer: A
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Forensic evidence can capture sensitive user activity, so scope, permissions, capture settings, and organizational approval must be tightly controlled. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
A change request from Humongous Insurance’s finance department affects email messages. The stated objective is to respond to Defender for Cloud Apps file policy alerts. Which administrative action is the strongest fit if the team must reduce false positives? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The team needs a configuration that can be justified from Microsoft-supported product behavior rather than an undocumented workaround. The pilot starts with 152 users and expands only after the security team signs off.
Correct answer: A
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
B: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
Woodgrove Bank’s legal team is updating controls for regulated case records. The requirement is to investigate activities by using Microsoft Purview Audit. The solution must also avoid unnecessary user disruption. Which action should the administrator take? The design should not depend on users remembering an optional manual step. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. Administrators must be able to tune the configuration later without redesigning the entire protection model. The implementation will be tested against 189 representative files or events before sign-off.
Correct answer: C
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
D: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
E: The integration enriches insider-risk analysis with supported endpoint and security signals so user risk can be evaluated with additional device context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
Following a policy review, Fourth Coffee changes how SharePoint documents is governed. The new requirement is to investigate insider risk activities by using the Microsoft Purview portal. Which action is the best fit and will help support investigation evidence? The control must work with the organization’s existing Microsoft 365 governance model. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The implementation will be tested against 45 representative files or events before sign-off.
Correct answer: E
Why: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The Purview insider-risk investigation views correlate the activities that contributed to risk and provide the timeline and evidence needed for a case decision. This directly matches the requirement in the scenario.
Learning point: Use the insider-risk alert or case experience to review the user timeline, risk indicators, related activities, and evidence while respecting role-based privacy controls.
At Blue Yonder Airlines, a review of support tickets found a gap. The administrator must investigate activities by using Microsoft Purview Audit, while the project team wants to preserve least privilege. What is the best next step? The team must be able to explain why the selected control addresses the stated risk. A business acquisition introduced a second set of collaboration sites with different permissions and data-handling habits. The control owner will compare pilot telemetry with baseline activity before deciding whether to expand scope. The design review compares outcomes for 82 representative samples before production enablement.
Correct answer: E
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
C: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
A pilot at Wide World Importers involves customer records. The security lead asks for a configuration that will assign Microsoft Purview Audit Premium user licenses. Which approach best satisfies the requirement and helps avoid changing unrelated workloads? The pilot population is small today but the configuration must support a broader rollout. The incident response team wants future events to include enough telemetry to distinguish a true policy violation from normal business activity. The organization also requires separation of duties between policy authors and investigators wherever the product supports it. The implementation will be tested against 119 representative files or events before sign-off.
Correct answer: D
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
Following a policy review, Graphic Design Institute changes how SharePoint documents is governed. The new requirement is to respond to Defender for Cloud Apps file policy alerts. Which action is the best fit and will help support investigation evidence? The pilot population is small today but the configuration must support a broader rollout. A regulatory assessment requires the organization to show both the technical control and evidence that administrators can review later. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The change is tracked under control batch SC401-8-060 and will be reviewed after the first week.
Correct answer: B
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
B: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
A production issue at Graphic Design Institute affects the handling of employee files. The root requirement is to assign Microsoft Purview Audit Premium user licenses. Which remediation best meets that requirement and helps reduce false positives? The security lead wants the configuration to align with the supported Microsoft workflow. A new data-governance standard requires the configuration to work consistently across departments that have very different content volumes. The final design will be reviewed against least-privilege and data-minimization principles before broad enablement. The change is tracked under control batch SC401-8-061 and will be reviewed after the first week.
Correct answer: B
Why: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
Option review:
A: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
B: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This directly matches the requirement in the scenario.
C: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Assign the required Audit Premium-capable license to the users whose enhanced audit features and longer or advanced auditing capabilities must be available.
The research team at Woodgrove Bank has two competing proposals for cloud application files. Only one directly enables the tenant to respond to Purview alerts in Microsoft Defender XDR. Which proposal should be chosen to minimize administrative overhead? The organization wants to avoid granting broader permissions than the task requires. An executive review asks the security team to reduce risk without blocking ordinary work that has a documented business purpose. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The design review compares outcomes for 49 representative samples before production enablement.
Correct answer: D
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
B: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
E: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
A production issue at Adventure Works affects the handling of customer records. The root requirement is to respond to Purview alerts in Microsoft Defender XDR. Which remediation best meets that requirement and helps use the narrowest effective control? The organization wants to avoid granting broader permissions than the task requires. Security testing found that the current design produces too many manual escalations and gives investigators little useful context. The rollout plan calls for simulation or observation first whenever the feature provides a supported way to do so. The first phase affects 86 users across two business units and must preserve normal collaboration.
Correct answer: B
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
C: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: A production insider-risk policy combines scope, triggering events, indicators, thresholds, and time windows so alerts correspond to the organization’s defined risk scenario. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
At Blue Yonder Airlines, a review of scanned forms found a gap. The administrator must respond to Purview alerts in Microsoft Defender XDR, while the project team wants to keep the design auditable. What is the best next step? The design should not depend on users remembering an optional manual step. The service desk reports repeated user confusion about which protection step should occur before content leaves its normal workspace. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The implementation will be tested against 123 representative files or events before sign-off.
Correct answer: E
Why: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Option review:
A: The workflow supports repeatable investigation and remediation, while notice templates standardize approved communications without exposing unnecessary case details. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Adaptive Protection exposes dynamically calculated insider-risk levels so services such as DLP can apply controls that change with current risk. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
D: Policy indicators determine which activities contribute to risk scoring; selecting relevant indicators and thresholds improves signal quality and reduces noise. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This directly matches the requirement in the scenario.
Learning point: Use the Defender XDR incident and alert experience to correlate the Purview alert with related identities, devices, and security evidence, then follow the incident response workflow.
City Power & Light is standardizing protection for scanned forms. The design must respond to data loss prevention alerts in the Microsoft Purview portal, and operations wants to avoid changing unrelated workloads. What should the information security administrator do? The requirement applies to production data rather than a one-time demonstration. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. The security architect wants the implementation to remain understandable to operations staff after the project team leaves. The change is tracked under control batch SC401-8-065 and will be reviewed after the first week.
Correct answer: C
Why: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
Option review:
A: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Alerts are initial risk signals; cases provide the investigation workspace for evidence, notes, user activity, and resolution when additional review is warranted. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DLP alert response requires validating the policy match and business context before choosing remediation, escalation, or closure. This directly matches the requirement in the scenario.
D: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
Learning point: Open the DLP alert in Purview, review the matched event and evidence, validate the user and content context, then assign, remediate, or resolve the alert according to the incident process.
Before enabling enforcement at Contoso, administrators must demonstrate how they will investigate activities by using Microsoft Purview Audit for Teams collaboration content. Which configuration should they use to use the narrowest effective control? The team wants the change to be reversible during pilot testing. The organization is consolidating several pilot configurations and wants one supported pattern before retiring the temporary controls. The selected approach must preserve existing collaboration behavior unless the stated risk condition is actually present. The implementation will be tested against 197 representative files or events before sign-off.
Correct answer: B
Why: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
Option review:
A: AI services inherit the risk of the data they can access; Purview controls reduce that risk by classifying sensitive data and enforcing handling and sharing requirements around it. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Purview Audit is the authoritative search experience for many Microsoft 365 activity records and supports filtering by actors, operations, services, and time. This directly matches the requirement in the scenario.
C: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
E: AI experiences can surface content a user is already entitled to access, so least-privilege permissions and workload-level sharing controls are fundamental to protecting data used by AI. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Run a Purview Audit search with the relevant time range, users, activities, workloads, and record details, then export or correlate the results as needed for the investigation.
A compliance exception at Northwind Traders can be closed only after the tenant can respond to Defender for Cloud Apps file policy alerts for email messages. What should the administrator implement if the goal is to use the narrowest effective control? The security lead wants the configuration to align with the supported Microsoft workflow. A recent internal audit found that the documented control exists on paper but is not consistently implemented in the tenant. Administrators must be able to tune the configuration later without redesigning the entire protection model. The initial scope covers 53 managed objects and must remain measurable during rollout.
Correct answer: A
Why: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
Option review:
A: File policy alerts contain the cloud-file context needed to decide whether to quarantine, change sharing, label, notify, or otherwise remediate the risky file. This directly matches the requirement in the scenario.
B: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
C: DSPM for AI policies convert posture findings into targeted protections and should be aligned with the AI applications, users, and data risks the organization has approved. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Azure Monitor does not provide the Purview-specific user, content, policy, case, and data-security context required by this objective.
E: Connectors bring additional signal sources into Insider Risk Management so policy indicators and risk scoring can incorporate the required business context. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Investigate the Defender for Cloud Apps file policy alert, review the file, owner, sharing context, and matched policy, then apply the appropriate governance or remediation action.
The governance board at Humongous Insurance approves a control for scanned forms on the condition that administrators can configure audit retention policies. What should the team do to reduce false positives? The requirement applies to production data rather than a one-time demonstration. The tenant has accumulated several overlapping policies, so the next change must have an unambiguous purpose and measurable outcome. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The design review compares outcomes for 90 representative samples before production enablement.
Correct answer: C
Why: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
Option review:
A: DSPM for AI separates posture administration, read-only visibility, and content access; role assignment should match the user’s job function and minimize exposure of sensitive data. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Broad Global Administrator access violates least privilege and is not required for the specialized Purview investigation or data-security task.
C: Audit retention policies determine how long selected audit data is preserved and can be scoped so higher-value records are retained for the required period. This directly matches the requirement in the scenario.
D: DSPM for AI monitoring helps security teams identify risky AI data interactions, track posture trends, and prioritize remediation based on observed activity and data sensitivity. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Defender XDR can surface and correlate Purview signals with other security alerts, giving responders broader incident context than a single compliance event. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
Learning point: Create an audit retention policy that targets the required users, record types, and retention duration so the necessary audit records are kept for the compliance period.
A proof of concept at Graphic Design Institute will be accepted only if it can analyze Purview activities by using Activity explorer for engineering designs. The architect also wants to support investigation evidence. Which option should be selected? The design should not depend on users remembering an optional manual step. A pilot group uses a mixture of Office files, browser workflows, and collaboration sites, which makes a generic one-size-fits-all control unsuitable. The support team needs clear evidence of what matched, which control acted, and what the user experienced. The change is tracked under control batch SC401-8-069 and will be reviewed after the first week.
Correct answer: E
Why: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Option review:
A: eDiscovery is designed for case-based search and legal investigation workflows across Microsoft 365 content, with controls for sources, queries, review, hold, and export. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
B: Blanket message encryption does not implement the requested insider-risk, audit, alert, eDiscovery, or AI data-security workflow.
C: Advanced auditing capabilities depend on licensing for the users whose activity must receive the premium audit treatment, so licensing should be validated before relying on those features. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
D: Tenant-level settings determine how signals are processed, anonymized, thresholded, and surfaced, so they should be aligned with the organization’s legal and operational requirements. This is a valid Purview-related action, but it addresses a different objective than the one the scenario requires.
E: Activity Explorer provides investigation-focused visibility into Purview events and is well suited to analyzing how protection controls are being triggered across the environment. This directly matches the requirement in the scenario.
Learning point: Use Activity Explorer to filter and analyze Purview events such as labeling, DLP, and endpoint activities across users, locations, actions, and policy matches.
Popular posts
Recent Posts
