A security team has configured Microsoft Purview Insider Risk Management to detect when employees in the AI research division download unusually large volumes of AI model files and scripts near their resignation date. Which insider risk policy template is most appropriate for this scenario?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because the 'Data theft by departing users' insider risk management policy template specifically combines signals from HR systems (resignation data) with data exfiltration activity indicators (file downloads, copying to USB, uploading to cloud storage). When an employee submits a resignation and then downloads large volumes of files, this policy template surfaces the correlated risk.
Full explanation below image
Full Explanation
B is correct because the 'Data theft by departing users' insider risk management policy template specifically combines signals from HR systems (resignation data) with data exfiltration activity indicators (file downloads, copying to USB, uploading to cloud storage). When an employee submits a resignation and then downloads large volumes of files, this policy template surfaces the correlated risk. A is wrong because 'General data leaks' detects data exfiltration signals without the correlation to HR resignation events; it is designed for broader, non-HR-correlated exfiltration detection. C is wrong because 'Security policy violations' detects activities like disabling security software or accessing restricted systems, not data download behavior. D is wrong because 'Risky browser usage' detects accessing inappropriate or risky websites, not internal data download activity.