SC-400 Insider Risk Management 4 — Questions and Answers
Question 1: Which Insider Risk Management feature allows an investigator to send a reminder or warning directly to a user whose behavior triggered an alert, without escalating to HR?
- Notice templates (Correct answer)
- Case notes
- User activity report
- Alert feedback
Correct answer: Notice templates
Notice templates allow investigators to send pre-written email notifications to users as a corrective action option directly from within a case.
Question 2: An Insider Risk Management policy is configured with the 'General data leaks' template. Which type of triggering event activates this policy for a user?
- A high-severity DLP policy match (Correct answer)
- An HR termination record
- A failed login attempt
- A privileged access request
Correct answer: A high-severity DLP policy match
The 'General data leaks' template uses a high-severity DLP policy match as its default triggering event to begin monitoring a user.
Question 3: What does the 'risk score boosting' feature do in Insider Risk Management?
- Temporarily increases the risk score for users with specific attributes like a privileged access level (Correct answer)
- Automatically escalates high-score users to HR
- Adds bonus points to analysts who resolve cases
- Raises alert scores based on endpoint DLP events only
Correct answer: Temporarily increases the risk score for users with specific attributes like a privileged access level
Risk score boosting allows administrators to configure certain user attributes or sequences of activities to contribute an elevated weight to a user's overall risk score.
Question 4: An organization needs to investigate an insider risk case that may involve legal proceedings. Which feature ensures that case evidence is preserved appropriately?
- Export case data to eDiscovery (Correct answer)
- Alert retention policy
- Legal hold via Records Management
- Case archiving
Correct answer: Export case data to eDiscovery
Insider Risk Management cases can be escalated to eDiscovery (Premium) to place evidence on legal hold and support formal legal investigations.
Question 5: Which signal source is NOT natively supported as a risk indicator in Microsoft Purview Insider Risk Management?
- Physical access badge data (Correct answer)
- Microsoft Teams messages
- SharePoint file downloads
- USB device usage detected by Microsoft Defender for Endpoint
Correct answer: Physical access badge data
Physical badge access data is not natively ingested by Insider Risk Management; only digital activity signals from Microsoft 365 and integrated connectors are supported.
Question 6: A user has been placed in scope for an Insider Risk Management policy. What happens if no triggering event occurs within the policy's defined window?
- The user exits the policy scope without any alert being generated (Correct answer)
- An informational alert is generated automatically
- The user is permanently excluded from future policies
- A case is opened for manual review
Correct answer: The user exits the policy scope without any alert being generated
If no triggering event occurs during the policy window, the user simply remains in scope until the window closes with no alert or case generated.
Question 7: Which Insider Risk Management analytics feature helps administrators understand policy coverage before deploying a live policy?
- Policy analytics insights (Correct answer)
- Alert simulation
- Risk score preview
- User activity baseline report
Correct answer: Policy analytics insights
Policy analytics provides insights into potential policy matches and estimated alert volumes based on existing activity, allowing admins to tune policies before activation.
Which Insider Risk Management feature allows an investigator to send a reminder or warning directly to a user whose behavior triggered an alert, without escalating to HR?