Communication Compliance, IRM and Priva Flashcards
With which systems is Communication Compliance compatible?
Teams, Exchange, Viva and third-party sources
What is the purpose of Communication Compliance?
To ensure users communicate appropriately according to corporate policies, risk management and/or regulatory compliance such as FINRA
What are the 6 policy templates when creating a communication compliance policy?
Detect inappropriate text/image/content
Detect SIT
Detect financial regulatory compliance
Detect conflict of interest
Detect Copilot interactions
Custom
What are the steps when creating a Communication Compliance policy?
1) Template
2) Users/groups and reviewers
3) Locations
4) Communication direction
5) Conditions
6) OCR ON/OFF
7) Review percentage
8) Filter email blast ON/OFF
In which Purview solutions can cases can be escalated to an eDiscovery cases?
Communication Compliance
Insider Risk Management
Which Purview solution can only be created in the portal and not in PowerShell?
Communication Compliance
Insider Risk Management
Privacy Risk Management
Data Subject Request
Trainable Classifiers
Which portal should you use to disable the “Report inappropriate” option (which is enabled by default)?
Teams Admin Centre
What are the two possible role groups that reviewers of Communication Compliance need to be assigned to?
Communication Compliance Analysts
Communication Compliance Investigators
If you select a distribution list when creating a Communication Compliance policy, are the individual mailboxes of the members being scanned?
Yes
Which Purview solutions require auditing to be turned on?
Sensitivity labels
Communication Compliance
Insider Risk Management
Information Barrier
What are two functionalities that you can use to reduce the amount of alerts?
Filter
Duplicate analysis
What are the possible remediation actions for a communication compliance alert?
Resolve
False Positive
Notify
Escalate to ediscovery case
What are some uses cases for Insider Risk Management?
Insider trading
Regulatory compliance violation
Data leakage
IP theft
What is the workflow for Insider Risk Management?
- Define policies
- Review and triage alerts
- Assign alerts to a case
- Investigate from case dashboard
- Escalate the case into a eDiscovery Premium case or with a SIEM service via the API
What are the steps when creating an IRM policy?
Select template
Select Users/Groups
Content to prioritize (optional) based o location/classification
Triggering Event (e.g., DLP policy)
Indicators
Threshold before alert is triggered
Which technologies does the Insider Risk Management reply on?
Microsoft Graph (API to access data from different systems)
Security services
Connector to HR services
What are the two policy templates available in IRM?
1) Data theft by departing users
2) Data leaks + by risk/priority users
3) Security policy violations + by departing/risky/priority users
4) Health record misuse
5) Risk browser usage
What should you do if you want to anonymize users in the alerts generated by IRM policies?
This is configured in the IRM general settings, that apply to all IRM policies, similar as policies timeframe and file type exclusions
How long does it take for audit to be effective after being turned on?
60 minutes
Which role group is able to create, read, update, delete IRM policies, settings and role group assignments?
IRM Admin
Which role group is able to access IRM alerts, cases and notice templates but not content search?
IRM Analyst
Which role group is able to access IRM alerts, cases and notice templates and content search?
IRM Investigator
What is the difference between the IRM Analyst and IRM Investigator role groups?
They can both access alerts, cases and notice templates, but only the Investigator can access content search
What is one requirements before creating a IRM policy?
Turn on indicators