This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Answer the following questions to check your understanding of the concepts covered in this module.
An administrator turns on the default DLP policy for Microsoft 365 Copilot, expecting it to immediately block prompts containing sensitive information types. Users continue submitting sensitive prompts without any block. What's the most likely explanation?
DLP policies for Copilot only take effect after the tenant is restarted
The Microsoft 365 Copilot location doesn't support blocking sensitive information types in prompts under any configuration
The default policy ships configured to run in simulation mode, which only logs events until the policy mode is switched to enforce
A DLP policy is scoped to endpoint file-upload activity for the Finance group and detects credit card numbers. An AI agent in a different group messages a human reviewer with a customer's actual credit card number, and this policy doesn't generate an alert. Which statement best explains why?
DLP doesn't monitor AI agent activity at all, so no policy could have caught this
The policy is scoped to a different activity (endpoint file uploads) and a different group than the one where the agent-messaging event occurred, so it was never evaluated against that event
The policy is misconfigured and needs its detection condition corrected to include credit card numbers
A SharePoint document is subject to an org-wide retention policy that deletes items after ten years, a scoped retention policy that retains items for five years and then deletes them, and a retention label that retains the item for three years and then deletes it. How long is the document retained, and when is it permanently deleted?
Retained for five years (the longest period), then permanently deleted per the label's 3-year delete action, since a label's delete action always takes precedence over a policy's delete action
Retained for three years only, since the retention label always overrides both retention policies entirely
Retained for ten years (the longest period overall), then deleted according to the org-wide policy
An administrator wants to know whether an unfamiliar AI agent has recently appeared in Relecloud's environment and how risky its activity has been. Which DSPM capability answers this question?
Activity explorer, because it lists every AI app and agent used across the organization
AI observability, because it provides an inventory of AI apps and agents (including Agent 365) prioritized by recent risk activity
Data risk assessments, because they scan for AI apps introduced in the last 30 days
An administrator notices that Insider Risk Management includes a policy template called "Detect risky AI usage," and recalls this same policy name from earlier work in DSPM for AI. What's the most accurate way to describe this relationship?
The names are a coincidence—DSPM for AI and Insider Risk Management maintain entirely separate policy engines
Insider Risk Management copied the policy design from DSPM for AI after it was released
DSPM for AI's policies include IRM policy templates—enabling one from DSPM for AI activates the underlying IRM policy, rather than these being two separate, unrelated features
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?