Single Choice Moderate

Q

A company uses Microsoft 365 Copilot and a third-party agent.

The company has Microsoft SharePoint Online content that is protected by using Microsoft Purview sensitivity labels that restrict programmatic access.

Security testing shows that users can paste regulated content into Copilot prompts and ask the agent to summarize and share the content externally.

You need to recommend a solution that mitigates prompt misuse, enforces data access controls, and supports the investigation and retention of Copilot interactions.

What should you recommend?

ID: #26612 Practice Assessment for Exam AB-100: Agentic AI Business Solutions Architect 8 views
Question Info
#26612Q ID
ModerateDifficulty
Practice Assessment for Exam AB-100: Agentic AI Business Solutions ArchitectTopic

Choose the Best Option

Click any option to instantly check if you're correct.

  • A Rely on the privacy terms of the third-party agent and rewrite the prompt instructions. ✔ ✖
  • B Enable web search connected experiences and export Microsoft Teams chat logs for retention. ✔ ✖
  • C Disable connected experiences in Microsoft 365 Apps and rely on users to clear the Copilot history. ✔ ✖
  • D Rely on Copilot permission trimming and Microsoft Purview Information Protection usage rights and use Microsoft Purview to search and retain Copilot interaction records. ✔ ✖
Correct Answer

Explanation

Objective:

3.4 Design responsible AI, security, governance, risk management, and compliance

What This Item Tests:

Analyze solution and AI vulnerabilities and mitigations, including prompt manipulation

Additional Reading:

Additional information

Best practices for prompt instructions

Rationale:

Using Microsoft 365 Copilot permission trimming together with Information Protection usage rights enforces access boundaries that prevent protected content from being processed, while Microsoft Purview enables the investigation and retention of Copilot prompts and responses. User-managed deletion, chat log exports, and prompt wording changes do not reliably mitigate prompt manipulation or enforce data protection controls.

Share This Question

Challenge a friend or share with your study group.

Related MCQ Questions