SC-401 · Question #42
You have a Microsoft 365 subscription. Users have devices that run Windows 11. You plan to create a Microsoft Purview insider risk management policy that will detect when a user performs the…
The correct answer is D. Onboard the devices to Microsoft Purview. The insider risk management policy described monitors device-level activities: deleting files from the device, copying files to USB drives, and printing files. All of these are endpoint signals that Microsoft Purview collects only from devices that have been onboarded to…
Question
You have a Microsoft 365 subscription. Users have devices that run Windows 11. You plan to create a Microsoft Purview insider risk management policy that will detect when a user performs the following actions:
- Deletes files that contain a sensitive information type (SIT) from
their device
- Copies files that contain a SIT to a USB drive
- Prints files that contain a SIT
You need to prepare the environment to support the policy. What should you do?
Options
- AConfigure the physical badging connector.
- BConfigure the HR data connector.
- CCreate a Microsoft Purview communication compliance policy.
- DOnboard the devices to Microsoft Purview.
How the community answered
(21 responses)- C5% (1)
- D95% (20)
Explanation
The insider risk management policy described monitors device-level activities: deleting files from the device, copying files to USB drives, and printing files. All of these are endpoint signals that Microsoft Purview collects only from devices that have been onboarded to Microsoft Purview (via Endpoint DLP onboarding). Without onboarding, Purview has no visibility into local device file operations. The physical badging connector provides office entry/exit signals, the HR connector provides employment data signals, and communication compliance monitors communications-none of these address the device-activity monitoring requirement.
Topics
Community Discussion
No community discussion yet for this question.