Q: 5
Northwind Bank has deployed Microsoft Purview DLP policies that now include coverage
for Microsoft 365 Copilot interactions. After rollout, the security operations center (SOC)
notices a steady stream of alerts where Copilot content includes or references sensitive
information such as payment card numbers or customer IDs. They want to ensure that
these alerts are handled consistently and that serious incidents can be correlated with
other signals like endpoint activity and sign-in anomalies.
What is the most appropriate way for the SOC to operationalize DLP alerts that involve
Copilot?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.