Bash, the Crucial Exams Chat Bot
AI Bot

Security, Compliance & Data Governance (AB-900) Flashcards

Microsoft 365 Certified: Copilot and Agent Administration Fundamentals AB-900 Flashcards

Study our Security, Compliance & Data Governance (AB-900) flashcards for the Microsoft 365 Certified: Copilot and Agent Administration Fundamentals AB-900 exam with 40+ flashcards. Review key concepts as flashcards, a searchable table, or an interactive matching game to reinforce exam concepts.
Microsoft 365 Certified: Copilot and Agent Administration Fundamentals AB-900 Course Header Image
FrontBack
Access reviewsRegularly review and certify user access rights
Access telemetry retention periodsDefine how long access logs and agent interactions are kept
Agent data handling in CopilotUnderstand what telemetry training and retention are used
Audit logging and monitoringCollect access and activity logs for investigation and compliance
Breach notification requirementsNotify authorities and impacted users within legal timeframes
Change control and configuration managementTrack approve and test changes to production systems
Compliance certificationsKnow relevant certifications like ISO27001 SOC2 and GDPR readiness
Compliance Manager and ScoreUse tools to assess risks track improvements and generate evidence
Conditional access policiesEnforce access rules based on signals like location device risk
Consent managementObtain and record user consent when required by law
Customer managed keysAllow customers to control encryption keys for added control
Data localization vs data residencyLocalization requires local processing residency may only require storage
Data Loss Prevention DLPPrevent sensitive data exfiltration via policy actions
Data minimizationCollect and retain only the data necessary for purpose
Data processing agreementsDPA define roles obligations and processing details with processors
Data residency requirementsStore data in specific geographic regions as required
Data subject requestsSupport access correction deletion and portability requests
Encryption at restEnsure stored data is encrypted using managed keys
Encryption in transitProtect data during transmission with TLS or equivalent
Incident response planningPrepare detection containment notification and remediation steps
Information classificationLabel data by sensitivity to drive protection policies
Just in time accessJIT grant temporary elevated privileges
Key management and rotationRotate keys periodically and audit key usage
Legal holdPreserve data to meet litigation and investigation requirements
Model governance for CopilotDocument model versions data provenance and deployment controls
Multi factor authentication MFARequire an additional verification factor for high risk access
Principle of least privilegeAssign only minimal permissions needed
Privacy by designIncorporate privacy principles early in system design
Privileged Identity Management PIMEnable just in time elevation and approval workflows
Provenance of training dataTrack origin consent and restrictions for data used in model training
Pseudonymization and anonymizationRemove or mask identifiers to reduce privacy risk
Retention labelsMark content lifecycle stages for automated retention actions
Retention policiesDefine how long data is retained and when it is disposed
Role based access control (RBAC)Group users by role and assign role permissions
Secure default settingsEnable secure defaults to reduce misconfiguration risk
Secure development lifecycleIntegrate security testing and reviews into the development process
Sensitivity labelsApply labels to files messages and contexts to enforce protection
Session controls for CopilotLimit session features and enforce timeouts for agent sessions
Telemetry and diagnostic loggingControl what telemetry is collected and for how long
Third party processorsAssess security and compliance of external vendors
Share on...
Follow us on...