Q: 2
You have a Microsoft 365 E5 subscription. You plan to use insider risk management to collect and investigate forensic evidence. You need to enable forensic evidence capturing. What should you do first?
Options
Discussion
Its B, you have to claim capacity before anything else happens in Purview for this feature. Nothing else is possible until that's done. Pretty sure that's required per docs, agree?
Option B
A is wrong, B. You can't set up forensic evidence capture unless you claim capacity first. It's a common trap to jump into config (like A or D) before this initial licensing step. Seen it trip up folks in similar questions.
I don't think it's A. You can't even configure any forensic settings until you've claimed capacity, so B should be first. That "first" word in these risk management setups is a classic trap for folks who just want to jump into config steps like A or D. Anyone else seen this sequence in practice exams?
B (A is tempting, but it’s useless before claiming capacity). Seen this on other practice sets too.
D isn't right, it's B. Without claiming capacity, the feature can't be activated at all.
I’d say B since you can't even see the option for forensic evidence before claiming capacity in Purview. The other steps only unlock after that, so pretty sure that's the right order unless I'm missing something.
B
Option B makes sense to me since you have to claim the forensic evidence capacity before any other config is possible in Purview. Without that, none of the settings for capture even become available. I think D comes later when scoping who gets monitored. Pretty sure but if someone actually tried this in a lab and got a different result, let me know!
D imo, since you usually define who the priority users are before configuring things like forensic capture. B looks tricky here but I'd go with D first. Anyone else see it that way?
Be respectful. No spam.