SC-400 Insider Risk Management 5 — Questions and Answers
Question 1: Which setting in Insider Risk Management enables the system to detect risky browsing behavior such as visiting job search or competitor websites?
- Risky browsing indicators (Correct answer)
- Communication compliance indicators
- DLP policy indicators
- Endpoint activity indicators
Correct answer: Risky browsing indicators
Risky browsing indicators, enabled via Microsoft Defender for Endpoint integration, detect visits to websites associated with job searching or other departure-related activities.
Question 2: An investigator needs to collaborate on an Insider Risk Management case with a colleague who does not have access to the compliance portal. What is the best approach?
- Add the colleague to the appropriate Insider Risk Management role group (Correct answer)
- Export the case data and share via email
- Grant temporary Global Administrator access
- Share a read-only link to the case dashboard
Correct answer: Add the colleague to the appropriate Insider Risk Management role group
Granting access through the appropriate IRM role group (Analyst or Investigator) is the correct and secure method to enable portal collaboration.
Question 3: What is the purpose of configuring 'intelligent detections' in Insider Risk Management settings?
- To exclude trusted domains and file types from triggering risk indicators (Correct answer)
- To enable machine learning-based anomaly detection
- To automatically create cases from high-severity alerts
- To integrate with Azure Sentinel for SIEM analysis
Correct answer: To exclude trusted domains and file types from triggering risk indicators
Intelligent detections settings allow administrators to define allowed domains and unallowed file type exclusions to reduce noise from legitimate business activities.
Question 4: A Compliance Administrator notices that the Insider Risk Management analytics page shows no data after being enabled. What is the most likely reason?
- Audit logging has not been enabled for the tenant (Correct answer)
- No HR connector has been configured
- No DLP policies exist in the tenant
- Microsoft Defender for Endpoint is not licensed
Correct answer: Audit logging has not been enabled for the tenant
Insider Risk Management analytics relies on the Microsoft 365 unified audit log; if audit logging is disabled, no activity data is available for analysis.
Question 5: When configuring an Insider Risk Management policy, what does the 'past activity detection' window control?
- How far back historical activity is reviewed when a user first enters a policy's scope (Correct answer)
- How long alerts are stored after being dismissed
- The lookback period for audit log retention
- The time window for generating weekly risk reports
Correct answer: How far back historical activity is reviewed when a user first enters a policy's scope
The past activity detection window determines how many days of historical user activity are evaluated once a triggering event places a user in active monitoring.
Question 6: Which of the following actions can an Insider Risk Management Analyst perform that an Insider Risk Management Viewer cannot?
- Triage alerts and add case notes (Correct answer)
- View the user activity dashboard
- Access the policy analytics page
- View alert details
Correct answer: Triage alerts and add case notes
Analysts can triage alerts, add notes, and take actions on cases, while Viewers have read-only access to dashboards and reports.
Question 7: An organization wants to create an Insider Risk Management policy that specifically monitors contractors who have access to source code repositories. Which policy configuration best supports this?
- Use priority user groups to scope the policy to contractor accounts with sensitive site access (Correct answer)
- Create a general data leaks policy with no scoping
- Use the security policy violations template for all users
- Enable the departing employee template for all contractor accounts
Correct answer: Use priority user groups to scope the policy to contractor accounts with sensitive site access
Priority user groups allow precise scoping of a policy to a defined set of high-risk users such as contractors with access to sensitive resources.
Which setting in Insider Risk Management enables the system to detect risky browsing behavior such as visiting job search or competitor websites?