Domain 3: Microsoft Purview for AI Compliance
Microsoft SC-500 Security Copilot · 47 questions
- An organization is using Microsoft Purview AI Hub to monitor Microsoft Copilot for Microsoft 365 interactions. The security team wants to identify instances where users are submitting prompts that contain credit card numbers. Which Purview capability within AI Hub provides this detection?
- A healthcare organization needs to prevent Microsoft 365 Copilot from generating responses that include patient health information (PHI) when users ask Copilot to summarize documents. Which Microsoft Purview feature should be configured?
- A compliance officer needs to assess the organization's readiness against the NIST AI Risk Management Framework using Microsoft tools. Which Microsoft Purview feature provides pre-built assessments mapped to AI-specific regulatory frameworks?
- An organization wants to apply mandatory sensitivity labels to all content generated by Microsoft 365 Copilot. The policy should inherit the highest sensitivity label of any documents referenced during a Copilot session. Which Purview feature enables label inheritance for Copilot-generated content?
- A financial services company uses Microsoft 365 Copilot and must prevent the AI from surfacing salary data stored in SharePoint to users outside the Human Resources department. Users in HR have a specific Microsoft Entra ID group. Which combination of controls enforces this restriction?
- A company needs to configure Microsoft Purview Information Barriers to prevent Microsoft 365 Copilot from surfacing information between two business units that must remain informationally separated due to regulatory requirements. Which Purview feature implements this separation for Copilot?
- An organization needs to implement eDiscovery on Copilot for Microsoft 365 interactions for a legal hold related to a regulatory investigation. An in-scope employee used Copilot extensively. Where are Copilot interaction logs stored for eDiscovery purposes?
- A security engineer is configuring a Microsoft Purview Communication Compliance policy to detect when employees use Microsoft Copilot for Microsoft 365 to generate content that contains discriminatory language. Which configuration is required?
- A data governance team needs to catalog all datasets used for training AI models in Azure Machine Learning to track data lineage, ownership, and sensitivity classification. Which Microsoft service provides data catalog capabilities that integrate with Azure Machine Learning for lineage tracking?
- An organization must retain all Microsoft 365 Copilot interaction logs for 7 years to satisfy financial industry regulatory requirements. Which Microsoft Purview feature enforces this retention period?
- A healthcare organization needs to automatically detect medical record numbers (MRN) in content processed by Azure OpenAI Service via the Azure OpenAI REST API. The organization has a proprietary MRN format that does not match any built-in Microsoft sensitive information types. Which Purview feature enables this custom detection?
- A security team has configured Microsoft Purview Insider Risk Management to detect when employees in the AI research division download unusually large volumes of AI model files and scripts near their resignation date. Which insider risk policy template is most appropriate for this scenario?
- An organization wants to apply sensitivity labels directly to Azure Machine Learning models (model artifacts) stored in Azure Blob Storage. What is the correct approach using Microsoft Purview?
- A financial services organization has configured Microsoft Purview Data Loss Prevention to prevent Azure OpenAI from returning responses that contain credit card numbers. The DLP policy is in test mode and the security team wants to verify it is detecting credit card numbers correctly before switching to enforcement mode. Where can the team view DLP policy match reports?
- An organization needs to implement Microsoft Purview Customer Key for Microsoft 365 to encrypt Copilot interaction data with organization-managed keys. What is a prerequisite for configuring Customer Key?
- A compliance team needs to review all Microsoft 365 Copilot prompts containing the word 'acquisition' to ensure no material non-public information (MNPI) is being shared with AI. Which Purview tool provides this capability?
- An organization uses Microsoft Purview Audit (Premium) and needs to retain Copilot interaction audit logs for 3 years to comply with internal AI governance policies. The default retention period for Purview Audit (Standard) logs is 90 days. What must the organization configure to achieve 3-year retention?
- An organization wants to use Microsoft Purview Exact Data Match (EDM) to prevent Azure OpenAI from generating responses that contain specific patient identifiers from their patient database (patient IDs, SSNs, and date-of-birth combinations). How does EDM differ from a standard sensitive information type for this use case?
- A security team has configured Microsoft Purview Adaptive Protection to dynamically adjust DLP policy enforcement based on a user's current insider risk level. When a user's insider risk score increases to 'Elevated,' their Copilot interactions should be restricted to prevent sensitive data from being included in prompts. How does Adaptive Protection achieve this?
- A compliance team needs to retrieve all Microsoft 365 Copilot interaction records for a specific user ([email protected]) for the period January 1–January 31, 2025, as part of an HR investigation. Which Microsoft Purview tool and configuration correctly scopes this search?
- An organization's security team has configured sensitivity labels and wants to ensure that documents stored on-premises (Windows file servers and SharePoint Server 2019) that contain AI model weights and research data are automatically classified before the data is migrated to Azure. Which Purview tool scans and classifies on-premises repositories?
- An organization wants to prevent employees from using unauthorized consumer AI tools (like public ChatGPT) on corporate devices. They want to block uploads of sensitive files to these services while allowing approved enterprise AI tools. Which Microsoft solution enforces this endpoint-level control?
- A compliance officer needs to create a custom compliance assessment in Microsoft Purview Compliance Manager to track the organization's implementation of internal AI governance controls that are not part of any standard regulatory framework. Which Compliance Manager feature enables this?
- A healthcare organization is using Microsoft Purview Communication Compliance to detect when employees share patient information through Microsoft Teams. The policy should also cover Microsoft 365 Copilot interactions for the same employees. Which communication compliance policy configuration scope includes both Teams messages and Copilot interactions?
- An organization wants to automatically apply sensitivity labels to new files uploaded to a SharePoint Online document library that is used to store AI training datasets. The labels should be applied based on sensitive information type detection (SSN, financial account numbers). Without requiring users to manually label files. Which Purview feature achieves this?
- An organization uses Microsoft Purview to classify data processed by Azure OpenAI. A security engineer must configure a DLP policy that prevents Azure OpenAI API responses containing credit card numbers from being returned to the calling application. Which Microsoft Purview capability supports this scenario?
- A compliance officer needs to demonstrate to auditors that the organization's use of Microsoft 365 Copilot complies with GDPR data residency requirements. Which Microsoft Purview capability provides the evidence needed?
- A data engineer builds a pipeline that feeds customer data to an Azure Machine Learning model for churn prediction. The security team needs to ensure that training data containing personal information is identified and tracked for data lineage purposes. Which Microsoft Purview feature should be used?
- A security engineer is configuring Microsoft Purview sensitivity labels for documents that will be used as grounding data for an Azure OpenAI RAG solution. The requirement is that documents labeled 'Highly Confidential' cannot be retrieved and used as grounding context by the AI. How should this be enforced?
- A compliance team needs to create a retention policy in Microsoft Purview that ensures AI-generated content from Microsoft Copilot for Microsoft 365 is retained for 7 years for regulatory compliance. Where in Microsoft Purview should this policy be configured?
- A security engineer configures the Microsoft Purview AI Hub and notices that some AI interactions are categorized as 'Sensitive information detected' but no policy action was taken. What is the most likely reason?
- An organization requires that AI-generated content used in regulatory filings must be immutably preserved as a record. A compliance engineer needs to configure Microsoft Purview so that these documents cannot be modified or deleted during the retention period. Which Microsoft Purview feature should be used?
- A security engineer needs to configure Microsoft Purview Information Protection to automatically classify and label documents generated by an Azure OpenAI GPT-4 model when they contain financial projections, without user interaction. Which Microsoft Purview feature enables automatic labeling of AI-generated content stored in SharePoint?
- An organization processes financial data using Azure Machine Learning. Microsoft Purview must be configured to automatically classify files uploaded to Azure Data Lake Storage Gen2 that contain International Bank Account Numbers (IBANs). The classification must happen within 24 hours of file upload. How should this be configured?
- A compliance team needs to implement Microsoft Purview Information Barriers to prevent the AI research team from communicating with the trading floor team to avoid insider trading risks. After configuring information barrier policies, users report that Microsoft Teams channel creation is failing. What is the most likely cause?
- An organization uses Azure Machine Learning to build AI models that process employee performance data. The legal team requires that any model trained on this data must have a documented data processing impact assessment. Which Microsoft Purview feature helps create and track this documentation?
- A security engineer needs to configure a Microsoft Purview DLP policy to prevent employees from pasting content from documents labeled 'Confidential' into Microsoft 365 Copilot prompts. Which DLP policy scope achieves this?
- A compliance team needs to search across all Microsoft 365 Copilot interaction data for a specific employee's prompts and responses as part of an HR investigation. The investigation requires content from the past 60 days. Which Microsoft tool should be used?
- A security engineer is configuring Microsoft Purview to track the consent and purpose limitation for personal data used in AI model training. The GDPR requires that data is only used for purposes consented to by data subjects. Which Microsoft Purview feature helps manage and demonstrate consent-based data processing compliance?
- A security team needs to implement Microsoft Purview Insider Risk Management to detect when data scientists are exfiltrating AI model training data before departing the company. Which insider risk policy template is most appropriate, and what triggering event should be configured?
- A compliance team is configuring Microsoft Purview to generate reports demonstrating that the organization's Azure OpenAI usage complies with the EU AI Act. The reports must show that high-risk AI systems have human oversight enabled. Which Microsoft Purview capability should be used to create this compliance report?
- An organization's AI system processes employee performance reviews. The HR team and legal counsel require that this data be classified as 'Highly Confidential - HR' in Microsoft Purview and that any access to this data must be logged. Which combination of Microsoft Purview capabilities achieves both requirements?
- A security engineer is configuring Microsoft Purview to automatically apply sensitivity labels to Azure OpenAI-generated reports stored in SharePoint Online. The reports contain financial forecasts. The engineer creates an auto-labeling policy with a trainable classifier for financial reports. The policy has been active for 14 days but no labels have been applied. What is the most likely reason?
- A compliance officer needs to demonstrate to regulators that the organization's AI training data for a credit scoring model does not contain prohibited personal attributes (race, gender, religion) that could lead to discriminatory model outcomes. Which Microsoft Purview capability can identify these attributes in the training data?
- A compliance engineer is configuring Microsoft Purview for a banking organization that uses AI for loan underwriting decisions. The EU AI Act requires that high-risk AI systems maintain logs sufficient for post-hoc auditability of individual decisions. Which combination of Azure services provides the required audit trail for each AI-driven loan decision?
- A security engineer is auditing an organization's Microsoft Purview DLP policies for AI coverage. The engineer discovers that employees are using a third-party AI chatbot (not Microsoft 365 Copilot) accessed through a web browser to submit sensitive work documents. Which Microsoft Purview and Defender feature combination should be configured to detect and block this behavior?
- A security engineer is implementing Microsoft Purview for an organization using Azure Machine Learning. The team needs to scan Azure ML datasets and automatically classify them as 'Confidential' if they contain more than 100 records with Social Security Numbers. Which Microsoft Purview component provides this threshold-based classification?