Question 1
A pharmaceutical research company, BioGen Innovations, has implemented Microsoft Purview Insider Risk Management. They are concerned about potential data theft of clinical trial results. An analyst needs to capture video clips of on-screen activity on endpoints when approved high-risk users perform specific risky activities, such as copying files to USB devices. Which setting must be enabled to achieve this?
Answer and explanation
Correct answer: B
Forensic evidence is the opt-in Insider Risk Management feature that captures video clips of user on-screen activity on devices. Captures happen either for specific activities (when a triggering event brings an approved user into scope and a policy indicator is detected) or for all activities. Users must be requested and approved (dual authorization), and devices must be onboarded to Microsoft Purview with the Microsoft Purview Client installed. Microsoft Defender for Endpoint integration is not required. Policy indicators and device indicators only define what's scored; they don't capture clips. Source: Microsoft Learn 'Learn about Insider Risk Management forensic evidence'.