This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
An administrator needs to reconstruct the exact sequence of events for a data loss prevention (DLP) alert, including files accessed, labels applied, and timestamps. Which investigation surface provides this chronological record?
Activity explorer filtered by user and time range
The unified audit log, accessible through Data Security Posture Management (DSPM)
Reports with advanced filtering
DLP alerts spiked this week. Before investigating individual alerts, an administrator wants to determine whether the spike reflects genuine behavioral change or a recently deployed sensitivity information type. Which surface answers this most efficiently?
Activity explorer filtered to the past seven days
Reports comparing current and previous weeks
The audit log filtered for DLP-related operations
The risky user investigation Promptbook reports no anomalous behavior for a user. But the administrator knows this user recently resigned and has been downloading large quantities of files. What should they do next?
Accept the Promptbook result because Security Copilot found no risk.
Validate through activity explorer and the audit log, filtering for file downloads after the resignation notice.
Run the sensitive data protection Promptbook instead.
AI observability flags a customer support agent as high risk for 'oversharing.' The agent has access to customer records. What must the administrator determine before concluding this is a genuine risk?
Whether the sharing volume matches expected operational levels for a customer support agent.
Whether the agent has a DLP policy applied to it.
Whether the Insider Risk Management risk level is critical.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?