nerdexam
Microsoft

SC-401 · Question #38

You have a Microsoft 365 E5 subscription. You plan to implement insider risk management for users that manage sensitive data associated with a project. You need to create a protection policy for the…

The correct answer is B. From the Microsoft Entra admin center, create a security group. The first step is to create a security group in the Microsoft Entra admin center containing only the project users who manage the sensitive data. When you then create the insider risk management policy in Microsoft Purview, you scope it to that security group-ensuring only…

Manage risks, alerts, and activities

Question

You have a Microsoft 365 E5 subscription. You plan to implement insider risk management for users that manage sensitive data associated with a project. You need to create a protection policy for the users. The solution must meet the following requirements:

  • Minimize the impact on users who are NOT part of the project.
  • Minimize administrative effort.

What should you do first?

Options

  • AFrom the Microsoft Purview portal, create an insider risk management policy.
  • BFrom the Microsoft Entra admin center, create a security group.
  • CFrom the Microsoft Entra admin center, create a User risk policy.
  • DFrom the Microsoft Purview portal, create a priority user group.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    81% (26)
  • C
    6% (2)
  • D
    9% (3)

Explanation

The first step is to create a security group in the Microsoft Entra admin center containing only the project users who manage the sensitive data. When you then create the insider risk management policy in Microsoft Purview, you scope it to that security group-ensuring only those users are monitored, which minimizes impact on users outside the project. This approach also minimizes administrative effort because group membership automatically controls policy scope; adding or removing users from the group updates policy coverage without reconfiguring the policy itself. Creating a priority user group (option D) is for elevated-risk monitoring, not for scoping a policy to a defined project team.

Topics

#Insider Risk Management#Microsoft Purview#Microsoft Entra ID#Security Groups

Community Discussion

No community discussion yet for this question.

Full SC-401 Practice