Your organization wants to audit all activities related to accessing sensitive files in Microsoft SharePoint. Which Microsoft Purview solution should you use?
Microsoft Purview Audit (Premium) provides advanced auditing capabilities, including extended retention of audit logs (up to 10 years), intelligent insights, and access to high-value audit events crucial for forensic investigations. It captures a comprehensive record of user and admin activities across Microsoft 365 services, enabling organizations to track who accessed what, when, and from where, which is essential for security and compliance audits.
Why this answer
Audit (Premium) in Microsoft Purview provides detailed logging of user and admin activities, including granular events like file access, modification, and permission changes in SharePoint. This solution enables organizations to investigate and audit all activities related to sensitive files by capturing and retaining audit records with high-volume event support and custom alerting.
Exam trap
The trap here is that candidates often confuse Data Loss Prevention (DLP) with auditing, because DLP also monitors sensitive files, but DLP focuses on preventing data exfiltration rather than providing a retrospective audit trail of all access activities.
How to eliminate wrong answers
Option B (Data lifecycle management) is wrong because it focuses on retaining, deleting, or archiving data based on policies, not on auditing access activities. Option C (Information barriers) is wrong because it restricts communication and collaboration between specific user groups to prevent conflicts of interest, not to audit file access. Option D (Data loss prevention) is wrong because it detects and prevents unauthorized sharing or leakage of sensitive data, but it does not provide a comprehensive audit trail of all access activities.