MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A compliance officer needs to ensure that all user activities related to sensitive data in Microsoft 365 are recorded and available for forensic investigation. They require detailed logs of who accessed specific files in SharePoint Online, including attempts to access files that were blocked by DLP policies. Which solution should they enable?
⚠ Common exam trap
Many candidates confuse the real-time monitoring capabilities of Activity Explorer or Defender for Cloud Apps with the historical, searchable audit trail required for forensic investigation, mistakenly thinking those tools replace the Unified Audit Log.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Audit Log
Microsoft 365 Audit Log (Unified Audit Log) is the correct solution because it captures detailed records of user activities, including file access in SharePoint Online and blocked DLP policy actions. These logs are retained for forensic investigation and can be searched via the Microsoft 365 Purview compliance portal or accessed programmatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft 365 Audit Log
Why this is correct
The Microsoft 365 Audit Log is the authoritative, organization-wide record of every user and admin action across Exchange Online, SharePoint, OneDrive, Microsoft Entra ID, and other workloads. It captures critical forensics details, including actor, action, timestamp, client IP, and affected item, so it fully satisfies a compliance officer's requirement for a comprehensive audit trail. Unified audit logging is available in the Purview compliance portal and can be queried with Search-UnifiedAuditLog, making it the correct foundational solution.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that provides visibility, conditional access, and session controls for sanctioned and unsanctioned cloud apps, but it is not an audit-logging repository. Its activity logs are derived from and secondary to the unified audit log, and it does not maintain granular, file-level access history for SharePoint on its own. Therefore, while useful for app governance and threat detection, it lacks the comprehensive historical detail the compliance officer requires.
- ✗
Microsoft Purview Activity Explorer
Why it's wrong here
Microsoft Purview Activity Explorer is a dedicated investigation interface for data-loss-prevention (DLP) events, showing only actions that matched sensitive information types or DLP policies. It cannot be used as a complete activity log because it filters out non-DLP activities such as routine document uploads, permission changes, or mailbox admin actions. Thus, it answers 'why did the DLP rule fire?' rather than 'what did every user do in the tenant?'
- ✗
Microsoft 365 Defender
Why it's wrong here
Microsoft 365 Defender is an integrated threat-protection suite that correlates signals from endpoint, email, identity, and cloud apps to detect and respond to security incidents. It is an analytics engine, not a compliance audit trail; it retains detection- and incident-focused data with different retention logic and does not provide the exhaustive, searchable list of user activities needed for compliance forensics. Any underlying activity data it references actually originates from the unified audit log, reinforcing that the audit log is the correct choice.
Go deeper
Related to this question
Learn chapter
Microsoft Teams Governance and Policy Management
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
Key term
Audit log
An audit log is a chronological record of security-relevant events and user activities within a system, used for monitoring, compliance, and forensic analysis.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.