SC-400 Insider Risk Management 3 — Questions and Answers
Question 1: An administrator wants to ensure that only specific users can view the actual content of files in Insider Risk Management cases. Which role group should these users be assigned to?
- Insider Risk Management Investigators (Correct answer)
- Insider Risk Management Analysts
- Compliance Administrators
- Security Administrators
Correct answer: Insider Risk Management Investigators
The Insider Risk Management Investigators role group grants access to all case management features including viewing file and email content in the content explorer.
Question 2: What is the function of 'cumulative exfiltration detection' in Insider Risk Management?
- It identifies users who gradually move large volumes of data over time (Correct answer)
- It blocks data exfiltration in real time
- It detects a single large file upload
- It monitors cumulative DLP policy matches
Correct answer: It identifies users who gradually move large volumes of data over time
Cumulative exfiltration detection identifies users whose total data movement over time exceeds normal baselines, even if individual events seem small.
Question 3: Which connector type must be deployed to allow Insider Risk Management to trigger alerts based on employee performance review data?
- HR data connector (Correct answer)
- Microsoft 365 data connector
- Azure AD connector
- Audit log connector
Correct answer: HR data connector
The HR data connector is used to import signals such as performance improvement plans and resignation dates from external HR systems.
Question 4: A company wants to reduce false positive alerts for a known group of executives who regularly move large files. Which Insider Risk Management feature should be configured?
- Priority user groups
- Allowed domains list
- Indicator thresholds (Correct answer)
- Alert suppression rules
Correct answer: Indicator thresholds
Adjusting indicator thresholds allows administrators to raise the sensitivity level required to trigger an alert, reducing false positives for users with legitimately high activity.
Question 5: In the context of Insider Risk Management, what is a 'triggering event'?
- An activity that causes a user to enter the active monitoring window of a policy (Correct answer)
- An event that automatically creates a case
- A DLP alert that feeds into an insider risk policy
- A user login from an anonymous IP
Correct answer: An activity that causes a user to enter the active monitoring window of a policy
A triggering event (such as a resignation date or a DLP policy match) is what activates a policy for a specific user and begins monitoring their activity.
Question 6: Which Microsoft Purview feature can be integrated with Insider Risk Management to provide enhanced context for DLP-triggered insider risk alerts?
- Communication Compliance
- Data Loss Prevention policies (Correct answer)
- Microsoft Defender for Cloud Apps
- Records Management
Correct answer: Data Loss Prevention policies
DLP policy matches can serve as triggering events or risk indicators within Insider Risk Management policies, providing direct integration between the two features.
Question 7: What is the maximum number of users that can be included in a single Insider Risk Management priority user group?
- 10,000 (Correct answer)
- 1,000
- 500
- There is no documented limit
Correct answer: 10,000
Priority user groups in Insider Risk Management can contain up to 10,000 users to designate higher-risk individuals for enhanced monitoring.
An administrator wants to ensure that only specific users can view the actual content of files in Insider Risk Management cases.
Which role group should these users be assigned to?