Q
A company uses Microsoft 365 Copilot and a third-party agent.
The company has Microsoft SharePoint Online content that is protected by using Microsoft Purview sensitivity labels that restrict programmatic access.
Security testing shows that users can paste regulated content into Copilot prompts and ask the agent to summarize and share the content externally.
You need to recommend a solution that mitigates prompt misuse, enforces data access controls, and supports the investigation and retention of Copilot interactions.
What should you recommend?
Question Info
Choose the Best Option
Click any option to instantly check if you're correct.
Explanation
Objective:
3.4 Design responsible AI, security, governance, risk management, and compliance
What This Item Tests:
Analyze solution and AI vulnerabilities and mitigations, including prompt manipulation
Additional Reading:
Best practices for prompt instructions
Rationale:
Using Microsoft 365 Copilot permission trimming together with Information Protection usage rights enforces access boundaries that prevent protected content from being processed, while Microsoft Purview enables the investigation and retention of Copilot prompts and responses. User-managed deletion, chat log exports, and prompt wording changes do not reliably mitigate prompt manipulation or enforce data protection controls.
Share This Question
Challenge a friend or share with your study group.