SC-500: Data Loss Prevention (DLP) & Insider Risk Flashcards
Microsoft Cloud and AI Security Engineer Associate SC-500 Flashcards

| Front | Back |
| Alert severity levels | Informational low medium high |
| Audit logging for DLP | Store detailed events for compliance and investigations |
| Auto case creation criteria | Threshold risk score sustained anomalous activity or multiple signals |
| Case management best practice | Document findings assign owner and track remediation |
| Common DLP policy actions | Block notify encrypt or audit |
| Data discovery strategy | Map sensitive data locations and owners first |
| Defender for Cloud Apps integration | Enhance DLP with cloud activity detection and app controls |
| DLP alert content | Contains matched rule information location and user |
| Endpoint DLP controls | Clipboard print device copy and external storage restrictions |
| Endpoint DLP purpose | Extend DLP protections to Windows and macOS devices |
| Escalation path design | Define when to notify HR legal or security |
| Exact Data Match EDM | Matches sensitive items by exact database or file fingerprint |
| False positive handling workflow | Collect feedback tune rules and add exceptions |
| False positive reduction for insider risk | Correlate multiple signals and review context |
| File fingerprinting advantage | Detects known files even after renaming |
| Incident vs alert distinction | Incident is grouped alerts requiring investigation |
| Insider risk management goal | Detect mitigate and investigate risky insider behavior |
| Integration with eDiscovery | Export case artifacts for legal review |
| Integration with Exchange and Teams | Inspect messages attachments and chat content |
| Integration with SharePoint and OneDrive | Apply policies to files stored or shared in cloud storage |
| Investigation step one | Review alert details and evidence |
| Key components of a DLP policy | Rules conditions actions and exceptions |
| Override retention best practice | Log justification and set automatic expiry |
| Override risk mitigation | Limit override availability to specific users |
| Overriding a DLP block | Allow user override with required business justification |
| Policy mode testing only | Use to evaluate rules without enforcing actions |
| Policy tip design best practice | Keep concise mention what to do next |
| Policy tip purpose | Educate users at time of action to prevent accidental violations |
| Privacy by design for investigations | Minimize scope and use role based access |
| Proximity detection in DLP | Detects sensitive data when defined items appear near each other |
| Purpose of DLP | Prevent data loss by detecting and protecting sensitive information |
| Regular policy review cadence | Monthly or quarterly depending on risk level |
| Reporting and dashboards for DLP | Monitor trends policy hits and incident timelines |
| Risk score meaning | A numeric indicator of likelihood of risky behavior |
| Scope best practice | Apply policies to high risk locations first |
| Sensitive information type definition | Pattern or identifier used to detect specific data such as credit cards |
| Signals used in insider risk | File activity email activity user behavior anomalies |
| Tip for tuning thresholds | Start high then lower to reduce false positives |
| Trainable classifier function | Machine learning model that identifies content by example |
| Use of DLP sensitive info templates | Quickly deploy rules for common data types |
| Use of policy exceptions | Exclude trusted users locations or file types |
| User notification options | Notify user with policy tip or block message |
About the Flashcards
Flashcards for the Microsoft Cloud and AI Security Engineer Associate exam help students review data loss prevention terminology, policy components, sensitive information detection, Exact Data Match, trainable classifiers, file fingerprinting, and proximity detection. The deck also covers policy actions, testing modes, exceptions, thresholds, and scope best practices.
Students can reinforce key ideas involving endpoint and cloud DLP controls, alerts, incidents, investigations, user notifications, policy overrides, auditing, and false-positive reduction. Additional cards address insider risk signals, risk scores, case management, escalation, privacy, eDiscovery integration, reporting dashboards, and strategies for discovering and protecting sensitive data.
Topics covered in this flashcard deck:
- DLP policies and rules
- Sensitive data detection
- Endpoint and cloud DLP
- Alerts and investigations
- Policy tuning and auditing
- Insider risk management