nerdexam
Microsoft

SC-401 · Question #236

Drag and Drop Question You have a Microsoft 365 E5 subscription. You need to create the Microsoft Purview insider risk management policies shown in the following table. Which policy template should…

The correct answer is Data theft by departing users; Data leaks by priority users; Data leaks. This question tests the ability to correctly associate Microsoft Purview insider risk management policy descriptions with their most appropriate predefined policy templates.

Manage risks, alerts, and activities

Question

Drag and Drop Question You have a Microsoft 365 E5 subscription. You need to create the Microsoft Purview insider risk management policies shown in the following table. Which policy template should you use for each policy? To answer, drag the appropriate policy templates to the correct policies. Each template may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct selection is worth one point. Answer:

Exhibits

SC-401 question #236 exhibit 1
SC-401 question #236 exhibit 2
SC-401 question #236 exhibit 3

Answer Area

Drag items

Data theft by departing usersData leaks by priority usersSecurity policy violations by priority usersData leaksSecurity policy violations by departing users

Correct arrangement

  • Data theft by departing users
  • Data leaks by priority users
  • Data leaks

Explanation

This question tests the ability to correctly associate Microsoft Purview insider risk management policy descriptions with their most appropriate predefined policy templates.

Approach. To correctly answer this question, the test-taker must carefully read each policy description and match it to the most specific and relevant policy template provided by Microsoft Purview's Insider Risk Management.

  • Policy1: 'Monitors the printing of files by users that submitted their resignation'

    • Key elements: 'printing of files' (a common method of exfiltrating data, often considered theft), and 'users that submitted their resignation' (departing users).
    • Correct template: 'Data theft by departing users'. This template directly addresses the risk of departing employees attempting to steal company data, which printing files for personal gain falls under.
  • Policy2: 'Monitors the accidental sharing of data outside of an organization by users in a priority user group'

    • Key elements: 'accidental sharing of data outside of an organization' (a clear definition of a data leak), and 'users in a priority user group' (identifying the specific user category).
    • Correct template: 'Data leaks by priority users'. This template is designed for scenarios where sensitive data is inadvertently or accidentally shared outside the organization by high-value or critical employees.
  • Policy3: 'Monitors the downloading of files from Microsoft SharePoint Online to personal cloud storage services'

    • Key elements: 'downloading of files from Microsoft SharePoint Online to personal cloud storage services' (a direct action that results in company data leaving the organizational boundary, indicating a data leak). There is no mention of specific user groups like 'departing users' or 'priority users'.
    • Correct template: 'Data leaks'. Since the description does not specify a 'priority user' or 'departing user' group, the general 'Data leaks' template is the most appropriate. While it is also a security policy violation, 'Data leaks' is a more specific classification for the act of data leaving the organization.

Common mistakes.

  • common_mistake. Common mistakes include confusing 'Data leaks' with 'Security policy violations' or misattributing user groups. For example:
  • Using 'Security policy violations' for Policy3: While downloading files to personal cloud storage is a security policy violation, 'Data leaks' is a more specific and accurate template for the act of data leaving the organization's control. The 'Security policy violations' templates are generally broader and might cover actions like accessing prohibited websites or installing unauthorized software, not just data egress.
  • Using 'Data leaks' for Policy1 or Policy2: While Policy1 and Policy2 both involve data leaving the organization (a form of data leak), the provided templates 'Data theft by departing users' and 'Data leaks by priority users' are more specific and tailored to the exact scenarios described, including the user group and the intent (theft vs. accidental leak).
  • Mismatching user groups: Forgetting or misinterpreting the 'departing users' or 'priority users' keywords in the policy descriptions and assigning a general 'Data leaks' policy to a specific user group scenario, or vice versa, would be incorrect. For instance, using 'Data leaks' for Policy2, when 'Data leaks by priority users' is explicitly available and more accurate.

Concept tested. Microsoft Purview Insider Risk Management policy templates, their specific use cases, and the ability to differentiate between various types of insider risks such as data theft, accidental data leaks, and security policy violations, especially in the context of different user groups (departing users, priority users).

Reference. null

Topics

#Microsoft Purview#Insider Risk Management#Policy Templates#Compliance Policies

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice