nerdexam
MicrosoftMicrosoft

SC-401 · Question #186

SC-401 Question #186: Real Exam Question with Answer & Explanation

The correct answer is B: Device2 only. {"question_number": 1, "correct_answer": "B", "explanation": "Microsoft Purview Insider Risk Management forensic evidence capture has strict device requirements: the device must run Windows 10 or Windows 11 AND be onboarded to the Microsoft Purview compliance portal via Endpoint

Manage risks, alerts, and activities

Question

You have a Microsoft 365 subscription that contains the devices shown in the following table. From which devices can Microsoft Purview Insider Risk Management capture forensic evidence?

Options

  • ADevice1 only
  • BDevice2 only
  • CDevice1 and Device2 only
  • DDevice2 and Device3 only
  • EDevice1, Device2, and Device3

Explanation

{"question_number": 1, "correct_answer": "B", "explanation": "Microsoft Purview Insider Risk Management forensic evidence capture has strict device requirements: the device must run Windows 10 or Windows 11 AND be onboarded to the Microsoft Purview compliance portal via Endpoint DLP. Based on the device table in this question, Device2 is the only device that satisfies both conditions simultaneously. Device1 and Device3 fail one or both requirements - common disqualifiers include running macOS or Linux, running an unsupported Windows version, or not being onboarded to Microsoft Purview compliance. Forensic evidence is a Windows-only, onboarded-device-only capability.", "generated_by": "claude-sonnet", "llm_judge_score": 4}

Topics

#Insider Risk Management#Forensic Evidence#Microsoft Defender for Endpoint#Endpoint Monitoring

Community Discussion

No community discussion yet for this question.

Full SC-401 PracticeBrowse All SC-401 Questions