A security team needs to implement Microsoft Purview Insider Risk Management to detect when data scientists are exfiltrating AI model training data before departing the company. Which insider risk policy template is most appropriate, and what triggering event should be configured?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — a is correct because the 'Data theft by departing users' policy template in Microsoft Purview Insider Risk Management is specifically designed for the scenario of employees planning to leave who may exfiltrate data. The HR connector integration enables using resignation or termination events from the HR system as triggering events, which activates risk monitoring for the specific employee during their notice period.
Full explanation below image
Full Explanation
A is correct because the 'Data theft by departing users' policy template in Microsoft Purview Insider Risk Management is specifically designed for the scenario of employees planning to leave who may exfiltrate data. The HR connector integration enables using resignation or termination events from the HR system as triggering events, which activates risk monitoring for the specific employee during their notice period. A is incorrect in that it is the best choice; the triggering event in context does align. B is incorrect because the 'General data leaks' policy template monitors for broad data leak patterns without a departure-specific triggering event, making it less targeted for the departing employee scenario. C is incorrect because the security policy violations template focuses on security control bypasses, not data exfiltration patterns. D is incorrect because the risky browser usage template focuses on web browsing behaviors, not file download and exfiltration activity related to AI model data.