SC-401 Practice Question 3644

Exam: SC-401
Domain: Manage risks, alerts, and activities
Difficulty: hard
You are configuring an Insider Risk Management policy to detect general data leaks. What must occur before the policy begins generating alerts for a specific user?

Answer Options

A
A triggering event to initiate the policy evaluation window
B
Manual approval from the tenant Global Admin
C
A complete re-installation of Windows OS on client devices
D
Power cycling the local corporate network routers

Correct Answer

A: A triggering event to initiate the policy evaluation window

Explanation

A triggering event (such as an exfiltration threshold violation or high-volume download) must be detected to initiate the policy evaluation window for that user.