Southridge Video has deployed Microsoft 365 Copilot organization-wide. The CISO wants visibility into what sensitive data Copilot is accessing and summarizing on behalf of users, including which sensitive information types appear in Copilot interactions. The administrator needs to set up a monitoring solution. What should they configure?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Purview DSPM for AI is basically the control tower for all your AI activity — it gives you a dedicated dashboard (the AI hub) that shows exactly what sensitive data Copilot is touching, without having to dig through raw audit logs or build custom dashboards. It's the purpose-built tool for exactly this job.
Full explanation below image
Full Explanation
The correct answer is B. Microsoft Purview Data Security Posture Management (DSPM) for AI is specifically designed to address AI-related data security concerns in Microsoft 365. When enabled, it provides the 'AI hub' — a centralized dashboard in the Microsoft Purview compliance portal that surfaces: aggregate reports on Copilot interactions, sensitive information types detected in prompts and responses (such as financial data, health records, or PII), oversharing risks (content shared broadly that Copilot can access), and recommendations for data protection policies. This is the purpose-built solution for CISO-level visibility into Copilot data access patterns.
Option A is incorrect. Microsoft Defender for Cloud Apps (MDCA) is designed to monitor third-party SaaS applications connected via API or reverse proxy. Microsoft 365 Copilot is a native Microsoft service, not a third-party cloud app — it is not managed through MDCA app connector policies. While MDCA does monitor some Microsoft 365 activities, it is not the right tool for comprehensive Copilot prompt-level sensitive data visibility.
Option C is incorrect. Microsoft Purview Unified Audit Logs do capture Copilot interaction events, and you can search them filtering for Copilot activities. However, this is a reactive, manual process that requires the compliance team to construct searches and parse raw log data. It does not provide an aggregated dashboard, sensitive data type summaries, or proactive policy recommendations. Audit logs are useful for investigation but not for ongoing posture monitoring at the CISO level.
Option D is incorrect. Integrating Microsoft Sentinel with a Copilot data connector is a valid security operations approach but is significantly more complex, requires a Sentinel workspace, involves custom KQL queries and workbook development, and is not a turnkey solution. DSPM for AI achieves the same visibility goal natively within the Purview portal without requiring a SIEM deployment. This answer describes a technically possible but unnecessarily complex solution when a built-in tool already exists.
Exam tip: DSPM for AI is one of the newer features in Microsoft Purview and is prominently tested on the AB-650 exam. Know that it lives in the Microsoft Purview compliance portal and provides the 'AI hub' — a dashboard that is the first place a compliance administrator should go for Copilot data visibility. The key differentiator is that it provides proactive posture insights, not just reactive log searches.