For the complete documentation index, see llms.txt. This page is also available as Markdown.

INSIGHT Training Knowledge Check

A post-training multiple-choice questionnaire for INSIGHT participants.

INSIGHT training knowledge check

Use this questionnaire after an INSIGHT training session. Choose one answer for each question.

Questions

1. What is the primary role of the INSIGHT Agent?

A. It creates scheduled reports. B. It monitors local endpoint activity and data movement. C. It manages Microsoft 365 permissions. D. It replaces the Management Console.

2. Which INSIGHT component provides Exchange Online and SharePoint Online visibility?

A. INSIGHT Agent B. Management Console C. Cloud Monitor D. Risk Summary

3. What must you confirm after installing the agent on an endpoint?

A. The device appears online in INSIGHT. B. A report has been sent. C. A risk definition has been created. D. A user policy has expired.

4. Which organisation setting adds context for trusted communications?

A. Working days B. Trusted emails and email domains C. Device Maintenance D. Risk Summary

5. What does a User Policy define?

A. Dashboard layout and report frequency B. Monitored activities, data types, control actions, and assigned users C. Microsoft 365 licence allocation D. Endpoint hardware requirements

6. Which action is appropriate for a selected file transfer policy rule?

A. Block the transfer. B. Archive the device. C. Remove the user. D. Disable Cloud Monitor.

7. Why do you configure Risk Definitions?

A. To install the endpoint agent. B. To assign severity and prioritise monitored activities. C. To connect Microsoft 365. D. To schedule agent updates.

8. Which area controls communication, upload behaviour, and monitoring scope?

A. Advanced Settings B. Cyber Awareness C. Organisation Settings D. Risk Summary

9. What can Advanced Settings be assigned to?

A. A dashboard widget B. A device C. A report recipient D. A Microsoft 365 tenant

10. What is the first check when expected endpoint data is missing?

A. Delete the policy. B. Review the INSIGHT Status Monitor. C. Reconnect Microsoft 365. D. Export the Risk Summary.

11. Which report helps educate end users and support behaviour change?

A. Cyber Awareness B. Risk Summary C. Device Maintenance D. Status Monitor

12. Which report supports operational oversight for administrators?

A. Cyber Awareness B. Risk Summary C. User Policy D. Cloud Monitor

13. What should you do first when reviewing activity in the dashboard?

A. Start with high-level risk views. B. Uninstall the agent. C. Create a new device. D. Delete existing incidents.

14. Which filters help narrow dashboard results?

A. User, device, and time B. Licence, browser, and printer C. Password, region, and theme D. Agent version only

15. Which checks help troubleshoot missing activity?

A. Microsoft 365 connection, agent connectivity, and setting assignment B. Dashboard colours, report templates, and browser cache C. Licence expiry, printer status, and user profile photo D. Device name, keyboard layout, and screen resolution

16. When does an assigned device command run?

A. Immediately after the administrator selects it B. During the agent's next server communication C. Only during the next Microsoft 365 sync D. After the device is restarted

17. What is the purpose of the Application Scan command?

A. Update the installed agent version B. Report the current installed applications C. Test Microsoft 365 connectivity D. Reset the device identifier

18. What should you verify before assigning a command?

A. The device checked in recently B. The user has exported a report C. The dashboard uses the default filters D. The Microsoft 365 tenant has no MFA

19. Which command helps resolve duplicate device reporting after device imaging?

A. Hardware Scan B. Force Reload Settings C. Refresh SSL Certificate D. Enable Test Communication Settings

20. Which command should you use to retrieve a current hardware snapshot?

A. Application Scan B. Hardware Scan C. Uninstall Client D. Clear SSL Cache

21. What does the Uninstall Client command do?

A. Removes the agent from selected devices B. Disables a user policy C. Disconnects Microsoft 365 D. Deletes the device record

22. What is the impact of an Immediate agent uninstall?

A. It waits for the next device restart B. It runs in the background without user interruption C. It interrupts the user session and restarts explorer.exe D. It only removes the agent after a scheduled sync

23. Which account is required to connect Microsoft 365?

A. Exchange recipient account B. Azure Global Administrator account C. SharePoint site owner account D. Standard Microsoft 365 user account

24. What must the administrator select on the Microsoft permissions screen?

A. Export device inventory B. Consent on behalf of your organisation C. Enable test communication settings D. Assign all users

25. What does the Sync button in Cloud Monitoring do?

A. It updates the endpoint agent B. It synchronises configuration and user information from Microsoft 365 C. It uninstalls inactive agents D. It rebuilds dashboard reports

26. Where do you deploy an uploaded agent update?

A. DEVICES > INSIGHT > Maintenance Mode > Update B. INSIGHT > Cloud Monitoring > Sync C. ORGANISATION > Integrations D. REPORTING > Risk Summary

Trainer answer key
  1. B — The agent monitors endpoint activity and data movement.

  2. C — Cloud Monitor provides Microsoft 365 visibility.

  3. A — Confirm the device is online and reporting.

  4. B — Trusted emails and domains improve communication context.

  5. B — Policies define monitoring, controls, and user assignments.

  6. A — Policy rules can block selected file transfers.

  7. B — Risk Definitions assign severity and improve prioritisation.

  8. A — Advanced Settings control communications and monitoring scope.

  9. B — Assign Advanced Settings to devices.

  10. B — Status Monitor checks endpoint health and applied settings.

  11. A — Cyber Awareness supports end-user guidance.

  12. B — Risk Summary supports administrative oversight.

  13. A — Review higher-level risks before incident detail.

  14. A — Filter by user, device, and time.

  15. A — Validate connections, agent status, and assignments.

  16. B — Commands run during the agent's next server communication.

  17. B — Application Scan returns current installed application data.

  18. A — Confirm the device has checked in recently.

  19. B — Force Reload Settings resolves identifier conflicts after imaging.

  20. B — Hardware Scan reports device specifications and peripherals.

  21. A — Uninstall Client removes the agent from selected devices.

  22. C — Immediate uninstall interrupts the session and restarts explorer.exe.

  23. B — Microsoft 365 connection requires an Azure Global Administrator.

  24. B — Consent is granted on behalf of the organisation.

  25. B — Sync refreshes Microsoft 365 configuration and user information.

  26. A — Upload the MSI first, then deploy it from Maintenance Mode.

Last updated