Detect Insider Data Exfiltration with Microsoft Purview Insider Risk Management
Your organization has a Microsoft 365 E5 subscription and wants to detect insider data exfiltration attempts. You need to design a solution that can identify users copying sensitive data to personal cloud storage services. Which Microsoft Purview capability should you use?
Quick Answer
The correct answer is Microsoft Purview Insider Risk Management because it is specifically designed to detect insider data exfiltration attempts by analyzing user activities, such as copying sensitive data to personal cloud storage services, through behavioral indicators and risk scoring. Unlike Data Loss Prevention, which enforces policies to block data sharing at the endpoint, Insider Risk Management focuses on identifying suspicious patterns—like unusual file uploads to personal cloud apps—that signal exfiltration intent. On the Microsoft Cybersecurity Architect exam, this question tests your ability to distinguish between prevention and detection capabilities within Purview, with a common trap being to select DLP because it deals with data protection. A useful memory tip is to think of Insider Risk Management as the “detective” that spots the leak, while DLP is the “guard” that tries to stop it at the door.
⚠ Common exam trap
SC-100 often tests the boundary between DLP (policy enforcement) and Insider Risk Management (behavioral detection), so candidates who see 'sensitive data' and pick DLP miss the insider threat detection requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Insider Risk Management
Microsoft Purview Insider Risk Management is designed to detect, investigate, and act on risky user activities such as data exfiltration to personal cloud storage. It uses machine learning and policy templates to correlate signals like unusual downloads, uploads to personal cloud services, and other indicators of insider risk. DLP policies enforce data handling rules but do not focus on detecting insider intent or anomalous behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
DLP policies evaluate sensitive information against conditions and locations, but they act on content flows within Microsoft 365 workloads and endpoint activities, not on detecting insider intent across personal cloud uploads. It would be correct for blocking or warning on sensitive data sharing through supported channels such as email or Teams.
- ✗
eDiscovery (Premium)
Why it's wrong here
eDiscovery (Premium) supports legal hold, custodial searches and case review for litigation, not real-time monitoring of user file transfers. It identifies content after the fact for legal purposes, so it cannot detect copying to personal cloud storage as it happens. It would be correct when preserving and reviewing evidence for a legal matter.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance inspects text-based communications such as email, Teams chats and Yammer for policy violations like harassment or regulatory breaches. It does not monitor file uploads to personal cloud storage, so it cannot identify that exfiltration vector. It would be correct for detecting inappropriate or risky language in messaging channels.
- ✓
Insider Risk Management
Why this is correct
Insider Risk Management correlates signals such as file copies to personal cloud storage, detecting exfiltration intent rather than only content matches. This satisfies the requirement to identify users moving sensitive data to unsanctioned services, which DLP alone cannot contextualise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Purview to govern sensitive data. You need to design a solution that automatically detects and protects credit card numbers in emails and documents stored in Microsoft 365. The solution should also provide data loss prevention (DLP) policy tips to users when they try to share such data externally. What should you configure?
medium- A.Sensitivity labels with auto-classification
- ✓ B.Microsoft Purview Data Loss Prevention policies
- C.Microsoft 365 compliance center
- D.Microsoft Information Protection unified labeling
Why B: Microsoft Purview Data Loss Prevention policies (option B) are the correct choice because DLP is the service that detects sensitive information types such as credit card numbers in Exchange Online email and SharePoint/OneDrive documents, and it can enforce protection by blocking or restricting external sharing while displaying policy tips to users in supported apps like Outlook and Office. DLP policies natively support the credit card number sensitive information type and the policy tip configuration for user notifications during external sharing attempts. Sensitivity labels with auto-classification (A) apply classification and protection to content but do not provide DLP policy tips or block external sharing in real time. The Microsoft 365 compliance center (C) is just the administrative portal, not a protection mechanism, and Microsoft Information Protection unified labeling (D) is the labeling infrastructure, not the DLP enforcement engine.
Variation 2. Your organization uses Microsoft Purview to protect sensitive data. You need to create a sensitivity label that automatically encrypts documents containing credit card numbers when they are shared externally. Which configuration should you use?
medium- A.Create a trainable classifier to detect credit cards
- ✓ B.Create an auto-labeling policy that applies a label with encryption for external sharing
- C.Create a default label policy for SharePoint
- D.Create a manual sensitivity label that users apply
Why B: Auto-labeling in Purview can be configured to apply a sensitivity label based on sensitive info types like credit card numbers. The label should have encryption enabled for external sharing. The other options describe different scenarios: manual labeling, default labeling, or classification without encryption.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.