Communication Compliance, IRM and Priva Flashcards
With which systems is Communication Compliance compatible?
Teams, Exchange, Viva and third-party sources
What is the purpose of Communication Compliance?
To ensure users communicate appropriately according to corporate policies, risk management and/or regulatory compliance such as FINRA
What are the 6 policy templates when creating a communication compliance policy?
Detect inappropriate text/image/content
Detect SIT
Detect financial regulatory compliance
Detect conflict of interest
Detect Copilot interactions
Custom
What are the steps when creating a Communication Compliance policy?
1) Template
2) Users/groups and reviewers
3) Locations
4) Communication direction
5) Conditions
6) OCR ON/OFF
7) Review percentage
8) Filter email blast ON/OFF
In which Purview solutions can cases can be escalated to an eDiscovery cases?
Communication Compliance
Insider Risk Management
Which Purview solution can only be created in the portal and not in PowerShell?
Communication Compliance
Insider Risk Management
Privacy Risk Management
Data Subject Request
Trainable Classifiers
Which portal should you use to disable the “Report inappropriate” option (which is enabled by default)?
Teams Admin Centre
What are the two possible role groups that reviewers of Communication Compliance need to be assigned to?
Communication Compliance Analysts
Communication Compliance Investigators
If you select a distribution list when creating a Communication Compliance policy, are the individual mailboxes of the members being scanned?
Yes
Which Purview solutions require auditing to be turned on?
Sensitivity labels
Communication Compliance
Insider Risk Management
Information Barrier
What are two functionalities that you can use to reduce the amount of alerts?
Filter
Duplicate analysis
What are the possible remediation actions for a communication compliance alert?
Resolve
False Positive
Notify
Escalate to ediscovery case
What are some uses cases for Insider Risk Management?
Insider trading
Regulatory compliance violation
Data leakage
IP theft
What is the workflow for Insider Risk Management?
- Define policies
- Review and triage alerts
- Assign alerts to a case
- Investigate from case dashboard
- Escalate the case into a eDiscovery Premium case or with a SIEM service via the API
What are the steps when creating an IRM policy?
Select template
Select Users/Groups
Content to prioritize (optional) based o location/classification
Triggering Event (e.g., DLP policy)
Indicators
Threshold before alert is triggered
Which technologies does the Insider Risk Management reply on?
Microsoft Graph (API to access data from different systems)
Security services
Connector to HR services
What are the two policy templates available in IRM?
1) Data theft by departing users
2) Data leaks + by risk/priority users
3) Security policy violations + by departing/risky/priority users
4) Health record misuse
5) Risk browser usage
What should you do if you want to anonymize users in the alerts generated by IRM policies?
This is configured in the IRM general settings, that apply to all IRM policies, similar as policies timeframe and file type exclusions
How long does it take for audit to be effective after being turned on?
60 minutes
Which role group is able to create, read, update, delete IRM policies, settings and role group assignments?
IRM Admin
Which role group is able to access IRM alerts, cases and notice templates but not content search?
IRM Analyst
Which role group is able to access IRM alerts, cases and notice templates and content search?
IRM Investigator
What is the difference between the IRM Analyst and IRM Investigator role groups?
They can both access alerts, cases and notice templates, but only the Investigator can access content search
What is one requirements before creating a IRM policy?
Turn on indicators
What are the possible status for an IRM alert?
Confirmed
Dismissed
Needs Review
Resolved
Is it possible to customize alert risk scores?
No
Which role groups are assigned as permanent contributors by default to IRM cases?
IRM Analyst
IRM Investigator
What are the two types of contributors to an IRM case?
Permanent
Temporary (can be added by the Permanent ones)
What are the two roles that can access Content Explorer inside IRM and how are they different
Content Explorer List View (can only see the list of items and location)
Content Explorer Content View (can also access the actual content)
What are the possible resolution status a IRM case can take?
Benign
Confirmed policy violation
What is Forensic Evidence functionality?
It enables visual activity capturing across devices
What is the volume limitation of captured clips using Forensic evidence?
20GB
Which Purview functionality requires dual authorization?
Forensic capture as part of IRM
Which role group approves requests to use Forensic capture?
IRM Approver
What are the steps to take before being able to enable Forensic evidence content capturing? (6)
1) Confirm subscription (special subscription on top of E5)
2) Add compliancedrive.microsoft.com
to allow list of firewall
3) Configure devices (onboard devices and have Purview client installed)
4) Define settings eg. bandwidth
5) Create a policy i.e., scope of capture
6) Dual authorization
Which roles submit a request for Forensic evidence content capture?
IRM and IRM Admin