โ† All SC-900 Flashcard Decks

Capabilities of Microsoft Purview Insider Risk Management Flashcards

6 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Capabilities of Microsoft Purview Insider Risk Management flashcards as text
  1. What is the primary purpose of Microsoft Purview Insider Risk Management?

    Answer: To detect, investigate, and act on risky activities by users within the organization.

    Insider Risk Management is designed to help organizations minimize internal risks by detecting, investigating, and acting on malicious and inadvertent activities by users. It leverages signals from various Microsoft 365 services to identify potential risks like data theft or security policy violations.

  2. Which of the following is a key prerequisite for enabling and using Microsoft Purview Insider Risk Management?

    Answer: A Microsoft 365 E5 license or an equivalent add-on.

    Microsoft Purview Insider Risk Management is a premium feature included in specific high-tier licenses. The Microsoft 365 E5 license (or the E5 Compliance / E5 Insider Risk Management add-ons) is required to access the advanced signals and capabilities needed for the service to function.

  3. An administrator wants to create a policy to detect potential data theft by employees who have recently resigned. How can this be accomplished in Insider Risk Management?

    Answer: By using a pre-configured policy template for departing users.

    Insider Risk Management provides several pre-configured policy templates for common risk scenarios, including 'Data theft by departing users'. These templates simplify setup by pre-selecting relevant indicators and triggers, such as connecting to the HR system for termination dates.

  4. What is the purpose of the 'anonymization' feature within the Insider Risk Management console?

    Answer: To hide the real names of users associated with alerts to protect their privacy during investigation.

    The anonymization feature is a crucial privacy control. It replaces usernames with pseudonyms (e.g., 'Anonymous user 123') in the alerts and cases, helping investigators focus on the risky activity itself without initial bias and protecting user privacy until a deeper investigation is warranted.

  5. Insider Risk Management relies on signals from various sources to detect risky behavior. Which service is the primary source for user activity signals like 'File downloaded' or 'File shared externally'?

    Answer: Microsoft 365 unified audit log

    Insider Risk Management is built upon the signals captured in the Microsoft 365 unified audit log. This log records a wide range of user and admin activities across services like SharePoint Online, OneDrive for Business, and Exchange Online, which are then analyzed to detect risky patterns.

  6. When an Insider Risk Management policy generates a high-severity alert, what is the typical next step in the built-in workflow?

    Answer: The alert is triaged, and an investigator can create a case for deeper analysis.

    The standard workflow is designed for systematic investigation. An analyst or investigator first reviews (triages) the generated alert. If the alert is deemed credible and requires further action, it is promoted to a case, which allows for in-depth analysis, evidence gathering, and collaboration.