Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A company wants to ensure that all Microsoft 365 admin actions are recorded and searchable for at least 180 days. They also need to create custom alert rules to notify the security team when critical events occur, such as a user being added to the Global Admin role. Which Microsoft Purview solution should they use?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Purview Audit with Microsoft Purview eDiscovery, mistakenly thinking eDiscovery is used for monitoring admin actions, when in fact eDiscovery is solely for legal content search and holds, not for real-time auditing or alerting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Audit

Microsoft Purview Audit (specifically Audit (Standard) or Audit (Premium)) is the correct solution because it records all admin actions from Microsoft 365 services into the unified audit log, retains those logs for at least 180 days (Audit Standard) or up to 10 years (Audit Premium), and allows you to create custom alert policies that trigger notifications when specific events like 'Added member to role' (e.g., Global Admin) occur. This directly meets the requirement for recording, searchability, and custom alerting on critical admin events.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Purview Audit

    Why this is correct

    Microsoft Purview Audit is the correct solution because it provides a unified audit log of user and admin activities across Microsoft 365. Audit (Premium) extends the default 90-day retention to one year (and up to 10 years with an add-on license), supports custom alert policies for critical events such as privileged role changes or eDiscovery searches, and can be queried via Search-AuditLog or the Purview compliance portal. For recording all admin actions with alerting on high-impact operations, this is the intended native capability.

  • ✗

    Microsoft Purview Data Loss Prevention (DLP)

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) is incorrect because it enforces policies to prevent sensitive data from being shared or leaked, such as blocking email transmission of credit card numbers or restricting file uploads to unapproved sites. While DLP rule matches are logged as events in the audit log, DLP itself does not provide an operational record of administrative actions (e.g., changing permissions, modifying tenant settings) nor does it offer long-term audit retention or alerting on admin activity. Its purpose is data protection, not activity logging.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection (also known as Microsoft Information Protection or MIP) is incorrect because it focuses on classifying and labeling sensitive content using sensitivity labels, applying encryption, and enforcing usage rights. Admin actions like labeling policy changes or label auto-labeling rules are not what this service is designed to record; it does not maintain a distinct audit trail of administrative operations or generate alerts for privileged actions. Instead, it consumes audit data to show label activity, but it is not the logging/alerting mechanism for all admin actions.

  • ✗

    Microsoft Purview eDiscovery

    Why it's wrong here

    Microsoft Purview eDiscovery is incorrect because it is built for legal investigations and compliance searches, enabling you to identify, hold, collect, and export content from Exchange, SharePoint, and Teams. It does not continuously log or record administrative actions across the tenant; rather, it can access the unified audit log to locate evidence after an incident. eDiscovery is a consumption/presentation layer for content, not an operational audit and alerting system, and it does not enforce long-term retention of admin action logs.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.