nerdexam
Microsoft

SC-401 · Question #207

You have a Microsoft 365 E5 subscription. You plan to use insider risk management to collect and investigate forensic evidence. You need to enable forensic evidence capturing. What should you do…

The correct answer is B. Claim capacity. Enabling forensic evidence capturing in Microsoft Purview Insider Risk Management requires claiming storage capacity as a mandatory first step before any configuration options become available.

Manage risks, alerts, and activities

Question

You have a Microsoft 365 E5 subscription. You plan to use insider risk management to collect and investigate forensic evidence. You need to enable forensic evidence capturing. What should you do first?

Options

  • AConfigure the information protection scanner.
  • BClaim capacity
  • CEnable Adaptive Protection
  • DCreate priority user groups.

How the community answered

(36 responses)
  • B
    92% (33)
  • C
    6% (2)
  • D
    3% (1)

Why each option

Enabling forensic evidence capturing in Microsoft Purview Insider Risk Management requires claiming storage capacity as a mandatory first step before any configuration options become available.

AConfigure the information protection scanner.

The information protection scanner is used to discover and classify sensitive data in on-premises file repositories and is entirely unrelated to enabling forensic evidence capturing in Insider Risk Management.

BClaim capacityCorrect

Forensic evidence capturing in Insider Risk Management requires dedicated organizational storage capacity that must be explicitly claimed in the Microsoft Purview settings before the feature can be enabled or policies configured. Claiming capacity allocates the resources needed to store captured screen activity and recordings. Without completing this step, the forensic evidence configuration options in policy setup remain locked and inaccessible.

CEnable Adaptive Protection

Adaptive Protection adjusts DLP enforcement dynamically based on a user's insider risk level and is a separate feature that is not a prerequisite for forensic evidence configuration.

DCreate priority user groups.

Creating priority user groups designates specific users for heightened monitoring within risk policies but is not a prerequisite step required before forensic evidence capturing can be enabled.

Concept tested: Forensic evidence capacity claiming prerequisite in Insider Risk Management

Source: https://learn.microsoft.com/en-us/purview/insider-risk-management-forensic-evidence-configure

Topics

#Insider Risk Management#Forensic Evidence#Microsoft Purview#Capacity Management

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice