nerdexam
Microsoft

SC-401 · Question #186

You have a Microsoft 365 subscription that contains the devices shown in the following table. From which devices can Microsoft Purview Insider Risk Management capture forensic evidence?

The correct answer is B. Device2 only. Microsoft Purview Insider Risk Management forensic evidence capture has strict device requirements: the device must run Windows 10 or Windows 11 AND be onboarded to the Microsoft Purview compliance portal via Endpoint DLP. Based on the device table in this question, Device2 is…

Manage risks, alerts, and activities

Question

You have a Microsoft 365 subscription that contains the devices shown in the following table. From which devices can Microsoft Purview Insider Risk Management capture forensic evidence?

Exhibit

SC-401 question #186 exhibit

Options

  • ADevice1 only
  • BDevice2 only
  • CDevice1 and Device2 only
  • DDevice2 and Device3 only
  • EDevice1, Device2, and Device3

How the community answered

(58 responses)
  • B
    91% (53)
  • C
    5% (3)
  • D
    2% (1)
  • E
    2% (1)

Explanation

Microsoft Purview Insider Risk Management forensic evidence capture has strict device requirements: the device must run Windows 10 or Windows 11 AND be onboarded to the Microsoft Purview compliance portal via Endpoint DLP. Based on the device table in this question, Device2 is the only device that satisfies both conditions simultaneously. Device1 and Device3 fail one or both requirements - common disqualifiers include running macOS or Linux, running an unsupported Windows version, or not being onboarded to Microsoft Purview compliance. Forensic evidence is a Windows-only, onboarded-device-only capability.

Topics

#Insider Risk Management#Forensic Evidence#Microsoft Defender for Endpoint#Endpoint Monitoring

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice