Single Choice Moderate

Q

A company has a Microsoft Copilot Studio agent in Microsoft Teams that answers HR policy questions by grounding responses in Microsoft SharePoint Online documents.

Some documents are labeled as Highly Confidential and only certain HR users are authorized to access the documents.

Testing shows that the agent can process and summarize Highly Confidential files. The company's security team requires that the agent NOT process content labeled Highly Confidential, even when a user has access.

You need to recommend a security solution to ensure that the agent enforces this restriction.

What should you recommend?

ID: #26614 Practice Assessment for Exam AB-100: Agentic AI Business Solutions Architect 8 views
Question Info
#26614Q ID
ModerateDifficulty
Practice Assessment for Exam AB-100: Agentic AI Business Solutions ArchitectTopic

Choose the Best Option

Click any option to instantly check if you're correct.

  • A Enable Copilot Studio transcript logging in Microsoft Dataverse. ✔ ✖
  • B Create a Microsoft Purview retention policy scoped to Copilot experiences. ✔ ✖
  • C Rely on user context so that SharePoint permissions and sensitivity labels are honored. ✔ ✖
  • D Create a Microsoft Purview data loss prevention (DLP) policy scoped to Microsoft 365 Copilot that blocks the processing of SharePoint content labeled Highly Confidential. ✔ ✖
Correct Answer

Explanation

Objective:

3.4 Design responsible AI, security, governance, risk management, and compliance

What This Item Tests:

Design security for agents

Additional Reading:

Secure AI agents built in Copilot Studio

Data governance and compliance

Data privacy and security

Secure your Copilot Studio projects

Rationale:

A Microsoft Purview DLP policy scoped to Microsoft 365 Copilot can prevent Copilot from processing SharePoint content that has specific sensitivity labels, enforcing agent-level security controls regardless of user permissions. Retention policies and transcript logging do not restrict content processing, and relying on user context alone does not meet the requirement to block Highly Confidential data from being handled by the agent.

Share This Question

Challenge a friend or share with your study group.

Related MCQ Questions