Courseiva

MS-102 Manage compliance by using Microsoft Purview Practice Question

Your organization uses Microsoft Purview eDiscovery (Premium) for a legal investigation. You need to collect data from Microsoft Teams chat messages and channel conversations. The case manager wants to search for specific keywords and exclude irrelevant content. What should you do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a collection in eDiscovery (Premium) with a KQL query to search Teams data.

EDiscovery (Premium) collections allow searching Microsoft Teams chat messages and channel conversations using KQL queries with conditions to include specific keywords and exclude irrelevant content. Option A is incorrect because Content Search (Standard) is less powerful and lacks advanced filtering capabilities for Teams data. Option B is incorrect because DLP policies are designed for data loss prevention, not legal discovery. Option C is incorrect because Communication Compliance is for monitoring communications, not for eDiscovery searches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Content Search (Standard) with keyword queries.

    Why it's wrong here

    Content Search (Standard) executes basic keyword searches across Exchange, SharePoint, OneDrive, and Teams but lacks the advanced collection, legal hold, review-set, and analytics capabilities of eDiscovery Premium. Its limited filtering options cannot precisely scope Teams message metadata or conversations, and results cannot be added to a legal case for iterative refinement.

  • ✗

    Create a DLP policy to capture matching content.

    Why it's wrong here

    A DLP policy is a data-loss-prevention mechanism that monitors and protects sensitive information through rules applied to email, documents, and Teams messages; it is designed to prevent accidental or malicious exfiltration, not to discover evidence. DLP does not create collectable search results, cannot be queried with KQL, and provides no exportable review set or legal hold for litigation.

  • ✗

    Use Communication Compliance to review messages.

    Why it's wrong here

    Communication Compliance is a supervisory tool for detecting workplace policy violations such as harassment or inappropriate language, and it can generate alerts and remediation tasks, but it is not a discovery pipeline. It lacks KQL-based collections, review sets, legal holds, and indexing for evidence, and it cannot produce a legally defensible export for eDiscovery matters.

  • ✓

    Create a collection in eDiscovery (Premium) with a KQL query to search Teams data.

    Why this is correct

    Create a collection in eDiscovery (Premium) and use a KQL query to search Teams data; this is the correct approach because eDiscovery Premium natively indexes Teams chats, threads, meeting messages, and attachments, and supports advanced query filters for scoping. The collection ingests hits into a review set where you can analyze, tag, add to a hold, and export with metadata for litigation.

About these practice questions

Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.