MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A security analyst receives an alert about a user who downloaded a large number of files from a SharePoint document library in a short period. The analyst needs to investigate the user's activities across Exchange, SharePoint, and Teams to determine if data exfiltration is occurring. Which Microsoft Purview solution should the analyst use to review detailed activity logs?
⚠ Common exam trap
A common mix-up: candidates confuse the investigative capability of Audit logs with the preventive or content-focused tools like DLP or eDiscovery, assuming that any security-related alert must be handled by DLP or eDiscovery, when in fact Audit (Premium) is the correct tool for reviewing historical activity logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Audit (Premium)
Microsoft Purview Audit (Premium) provides detailed, searchable activity logs for user actions across Exchange, SharePoint, and Teams, including file downloads, access events, and admin operations. The analyst can use the Audit log search to filter by user, date range, and activity type (e.g., 'FileDownloaded') to identify potential data exfiltration patterns. Audit (Premium) also offers longer retention (up to 1 year by default, extendable to 10 years) and higher-bandwidth APIs for large-scale investigations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Audit (Premium)
Why this is correct
Microsoft Purview Audit (Premium) provides a comprehensive, forensic-grade record of user and admin activities across Microsoft 365 services, including file downloads from SharePoint/OneDrive. It extends the standard audit log with features like longer retention (up to 10 years), access to high-value events such as MailItemsAccessed and unusual admin actions, and intelligent insights that surface anomalies. For a security analyst triaging an alert about a suspicious download, Audit (Premium) is the correct tool because it lets you query the unified audit log for the specific 'FileDownloaded' event and reconstruct a timeline of the user's actions.
- ✗
Microsoft Purview eDiscovery (Premium)
Why it's wrong here
Microsoft Purview eDiscovery (Premium) is designed for legal discovery and litigation, enabling you to search, collect, and export content such as emails, documents, and chats from mailboxes, SharePoint sites, and Teams. It does not capture or expose activity audit logs, so you cannot use it to identify that a user downloaded a file or to review a sequence of user actions. Its purpose is to find the content itself based on queries and place it on hold for legal review, not to analyze operational activities. Thus it is not suitable for this security investigation.
- ✗
Microsoft Purview Communication Compliance
Why it's wrong here
Microsoft Purview Communication Compliance is a supervision solution that monitors electronic communications like email, Microsoft Teams chats, and third-party sources for policy violations such as offensive language, harassment, or sharing sensitive information in messages. It applies machine-learning-based classifiers and policies to detect inappropriate or non-compliant content within communications, but it does not audit general user activities like file downloads outside of message attachments. While a downloaded file could be mentioned in a communication, this tool does not provide a comprehensive activity log of every file access or download event, making it irrelevant to the analyst's alert.
- ✗
Microsoft Purview Data Loss Prevention (DLP)
Why it's wrong here
Microsoft Purview Data Loss Prevention (DLP) protects sensitive data by enforcing policies that inspect content for predefined patterns (e.g., credit card numbers, PII) and automatically block or alert on actions such as copying or sending that data, often at the endpoint or in cloud apps. It is proactive and policy-driven, operating in real time to prevent leakage, but it does not maintain a historical audit log of all user downloads of files, especially non-sensitive files. The alert about a user who 'downloaded' something may not involve sensitive data, and DLP's actions would only trigger on matching content types, not on generic download events across the environment. Therefore, DLP cannot provide the retrospective evidence needed for this investigation.
Go deeper
Related to this question
Learn chapter
Teams Live Events and Webinars
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
Audit log
An audit log is a chronological record of security-relevant events and user activities within a system, used for monitoring, compliance, and forensic analysis.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.