Courseiva
Implement generative AI solutionsmediumMultiple ChoiceObjective-mapped

AI-102 Implement generative AI solutions Practice Question

Your company uses Microsoft Copilot for Microsoft 365. You need to ensure that Copilot only accesses data from approved SharePoint sites and does not use any other organizational data. What should you configure?

⚠ Common exam trap

Watch out — candidates often confuse data access control with authentication or data lifecycle management, leading them to select Conditional Access or retention policies instead of recognizing that sensitivity labels provide the specific Copilot data source restriction capability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply sensitivity labels to the approved SharePoint sites.

Sensitivity labels can be configured to restrict Microsoft Copilot for Microsoft 365 to only access content from approved SharePoint sites. By applying a sensitivity label that includes the 'mark content' or 'encrypt content' setting with a specific scope, you can use the 'Microsoft Copilot for Microsoft 365' condition under 'Access control' to block Copilot from processing data from unlabeled or non-approved sites. This ensures Copilot respects the label's policy and excludes all other organizational data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure Conditional Access policies in Microsoft Entra ID.

    Why it's wrong here

    Conditional Access controls access to apps, not specific data sources.

  • Use Microsoft Purview Data Map to catalog the approved sites.

    Why it's wrong here

    Data Map catalogs data, but does not restrict Copilot access.

  • Apply sensitivity labels to the approved SharePoint sites.

    Why this is correct

    Sensitivity labels can be used to restrict Copilot's data sources.

  • Set up data retention policies in Microsoft Purview.

    Why it's wrong here

    Retention policies manage data retention, not access.

About these practice questions

This AI-102 question is part of Courseiva's 945-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AI-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AI-102 exam.