Courseiva

Detecting Insider Threats Using Microsoft Purview Insider Risk Management

A large enterprise is concerned about insider threats. The compliance team needs to detect and investigate potential data theft scenarios, such as when employees nearing their resignation date suddenly copy large amounts of sensitive data to USB drives or email confidential files to personal accounts. They require a solution that uses machine learning to identify risky activities and create alerts for investigation. Which Microsoft Purview solution should they deploy?

Quick Answer

The answer is Insider Risk Management. This Microsoft Purview solution is correct because it uses machine learning to correlate user activities—such as copying large amounts of data to USB drives or emailing confidential files to personal accounts—with contextual indicators like an employee’s approaching resignation date, enabling it to detect potential data theft scenarios and generate alerts for investigation. On the SC-900 exam, this question tests your understanding of how Purview’s specialized risk and compliance solutions map to specific threat scenarios; a common trap is confusing Insider Risk Management with Audit or Data Lifecycle Management, which handle logging and retention rather than behavioral detection. To remember, think of the phrase “Insider Risk = Behavior + Context,” highlighting that this solution uniquely combines activity signals with situational cues like resignation dates to spot risky patterns.

⚠ Common exam trap

Candidates often confuse Audit (Premium) with a detection solution, but Audit is purely a logging and search tool, not a proactive ML-based risk detection system like Insider Risk Management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Insider Risk Management

Insider Risk Management is the correct solution because it uses machine learning to correlate signals from user activities (e.g., copying files to USB, emailing to personal accounts) with contextual indicators like resignation dates, enabling detection of potential data theft scenarios. It provides built-in alerting and investigation workflows specifically designed for insider threat use cases, unlike the other options which focus on retention, auditing, or compliance posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Lifecycle Management

    Why it's wrong here

    Data Lifecycle Management handles retention and deletion of content, not detection of risky user behaviors.

    When this WOULD be correct

    A question asking which solution to automatically retain or delete data based on regulatory requirements, such as implementing a policy to delete customer records after 7 years, would make Data Lifecycle Management the correct answer.

  • Audit (Premium)

    Why it's wrong here

    Audit (Premium) provides detailed logging and search capabilities but does not proactively model or detect insider risk patterns.

  • Insider Risk Management

    Why this is correct

    Insider Risk Management uses machine learning to detect, investigate, and act on insider threats based on behavioral patterns.

  • Compliance Manager

    Why it's wrong here

    Compliance Manager helps assess and manage compliance posture but does not detect or investigate user activities.

    When this WOULD be correct

    An organization needs to assess and improve its compliance posture against industry standards like GDPR or ISO 27001, and requires a dashboard to track remediation actions and control effectiveness.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Insider Risk ManagementCorrect answer

Why this is correct

Insider Risk Management uses machine learning to detect, investigate, and act on insider threats based on behavioral patterns.

Data Lifecycle ManagementWrong answer — click to see why

Why this is wrong here

Data Lifecycle Management focuses on governing data retention and deletion policies, not on detecting insider threats or risky user behavior using machine learning.

★ When this WOULD be the correct answer

A question asking which solution to automatically retain or delete data based on regulatory requirements, such as implementing a policy to delete customer records after 7 years, would make Data Lifecycle Management the correct answer.

Why candidates choose this

Candidates may confuse data governance with security monitoring, assuming that managing data lifecycles includes preventing data theft, but the two are distinct functions.

Compliance ManagerWrong answer — click to see why

Why this is wrong here

Compliance Manager is a risk assessment tool that helps organizations evaluate their compliance posture against regulations, not a solution for detecting insider threats via machine learning on user activities.

★ When this WOULD be the correct answer

An organization needs to assess and improve its compliance posture against industry standards like GDPR or ISO 27001, and requires a dashboard to track remediation actions and control effectiveness.

Why candidates choose this

Candidates may confuse 'compliance' in the name with the compliance team's need, or think Compliance Manager covers all compliance-related detection scenarios.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A data analyst is planning to leave the company in two weeks and has access to a large volume of sensitive customer data. The compliance team wants to detect if the analyst starts downloading large amounts of files to a personal USB drive or sending sensitive content to an external email address. They need to set up a policy that alerts on such anomalous data exfiltration activities without blocking operations until a thorough investigation is completed. Which Microsoft Purview solution should they configure?

hard
  • A.Microsoft Purview Insider Risk Management
  • B.Microsoft Purview Data Lifecycle Management
  • C.Microsoft Purview Communication Compliance
  • D.Microsoft Purview eDiscovery (Standard)

Why A: Microsoft Purview Insider Risk Management is designed to detect, investigate, and act on risky user activities, including data exfiltration by departing employees. It uses predefined indicators such as downloading files to USB drives or sending emails to external addresses, and can generate alerts without automatically blocking operations, allowing for a thorough investigation first.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.