A risk analyst is explaining when to use Microsoft Purview Insider Risk Management instead of only relying on DLP and audit logs.
Complete the sentence:
“Use Microsoft Purview Insider Risk Management when you need to ______.”
The latest changes and updates from the administration for this exam.
Latest Update: Jun 14 2026
All questions are working fine.
A risk analyst is explaining when to use Microsoft Purview Insider Risk Management instead of only relying on DLP and audit logs.
Complete the sentence:
“Use Microsoft Purview Insider Risk Management when you need to ______.”
“Activity explorer lets you see who has accessed or modified sensitive and labeled content and also shows label-related actions (such as labels applied, changed, or removed), giving you a history of how protected data is being used over time.”
Your organisation has enabled SharePoint Advanced Management. A junior administrator says:
“Data access governance reports give us near real-time analytics, and they include both SharePoint and OneDrive, so we can run them many times a day to check oversharing.”
Is this statement True or False?
You’re asked to explain the difference between authentication and authorization to a junior admin.
Complete the sentence:
“In Microsoft 365 and Microsoft Entra ID, authorization is the process that ______.”
Your security team is reviewing how an internal line-of-business app accesses data in Microsoft 365. The app is registered in Microsoft Entra ID and uses the Microsoft Graph API.
You’re asked:
“Which of these changes is specifically an authorization decision, not an authentication change?”
Which action best represents authorization?
Contoso is preparing to roll out Microsoft 365 Copilot. The security team suspects that some legacy SharePoint collaboration sites are overshared using “Anyone” and “People in your organization” links. They want a quick way to identify which sites are most at risk so they can prioritise remediation before Copilot can surface this content to users.
As the SharePoint administrator, what should you do first?
Which action best helps you quickly identify overshared SharePoint sites using out-of-the-box capabilities?
A data security engineer wants to explain the difference between Activity explorer and other Purview views.
Complete the sentence:
“Microsoft Purview Activity explorer primarily reports on ______.”
The HR team at Tailwind Traders has 200 specialists who use Copilot heavily every day across Outlook, Word, Teams, and SharePoint. The CFO wants Copilot costs for this team to be stable and easy to forecast for the next 12 months. Other small project teams will experiment with SharePoint agents, but their usage will be occasional and unpredictable.
Which licensing approach best fits the HR specialists?
A security architect summarises two Microsoft Purview solutions as follows:
“Data Loss Prevention mainly looks at content and actions in the moment, such as a user trying to send sensitive data out of the organisation. Insider Risk Management looks at user behaviour over time, correlating signals like file downloads, copying to personal cloud, or unusual activities to detect potential insider risks.”
Is this statement True or False?
Your organisation uses Microsoft 365 with Microsoft Entra ID. The security team wants to require MFA only when risk or context justifies it, not for every sign-in.
They propose this requirement:
If a user signs in from a trusted corporate device on the corporate network, allow access without extra prompts.
If a user signs in from a personal device on an untrusted network, require MFA before granting access.
Which approach best fits how conditional access works?