MS-900 Data lifecycle management Practice Question
Which TWO of the following are features of Microsoft Purview that help organizations meet compliance requirements for data lifecycle management? (Choose two.)
⚠ Common exam trap
MS-900 often tests the confusion between retention/lifecycle features (retention policies, records management) and adjacent Purview tools like DLP, eDiscovery, and Insider Risk Management, which solve different problems but are all branded under the same compliance umbrella.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retention policies
Retention policies (A) are a core Microsoft Purview capability that let organizations keep or delete content for a defined period, directly supporting data lifecycle management by governing how long data is retained and when it is disposed of. Records management (C) extends this by letting organizations declare content as records, apply retention and disposition rules (including event-based retention and regulatory records), and manage the full lifecycle of high-value or regulated data. Together, A and C are the Purview features specifically designed for lifecycle governance from creation through disposal. eDiscovery (Premium) (B) focuses on identifying, preserving, collecting, and reviewing content for legal investigations rather than lifecycle retention. Insider Risk Management (D) detects and mitigates risky user activity, and Data Loss Prevention policies (E) prevent sharing of sensitive data in motion — neither governs retention or disposition of data over its lifecycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Retention policies
Why this is correct
Retention policies in Microsoft Purview govern how long content is kept and when it is deleted, covering the full data lifecycle across Exchange, SharePoint, OneDrive, and Teams. This directly satisfies the compliance requirement for data lifecycle management.
- ✗
eDiscovery (Premium)
Why it's wrong here
eDiscovery (Premium) supports legal investigations, identifying and collecting content for litigation, not governing data retention or deletion across its lifecycle. It is tempting because it is a Purview compliance feature, but lifecycle management requires retention policies and labels, which is the correct scenario for eDiscovery's investigative tooling.
- ✓
Records management
Why this is correct
Records management in Microsoft Purview applies retention and disposal labels to declare items as records, enforcing immutability and audit trails across their lifecycle. This directly satisfies the stem's data lifecycle compliance requirement by governing how content is retained, amended and eventually disposed of.
- ✗
Insider Risk Management
Why it's wrong here
Insider Risk Management detects and investigates risky user behaviour such as data theft, not the retention, deletion or archival of content. It is tempting because it is a Purview compliance feature, but lifecycle management is served by retention policies and labels, which govern how long data is kept.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
DLP policies detect and block sensitive data sharing in motion, addressing protection rather than lifecycle management of retention and deletion. It is tempting because DLP is a core Purview compliance capability, but the lifecycle question requires retention policies and records management, not exfiltration prevention.
Go deeper
Related to this question
Learn chapter
Microsoft Teams Governance and Policy Management
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.