SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your company uses Microsoft Purview Compliance Manager to track compliance with regulatory standards. You need to generate a report that shows the percentage of controls that are not yet implemented for the PCI DSS standard. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In Compliance Manager, open the PCI DSS assessment and view the control status.
The correct option is A: in Compliance Manager, open the PCI DSS assessment and view the control status, because Compliance Manager assessments include a controls view that shows each control's implementation status and progress percentages for the specific standard, which directly provides the percentage of controls not yet implemented. This is the built-in reporting surface for tracking regulatory compliance progress against PCI DSS. Option B is incorrect because Data Lifecycle Management policies govern retention and deletion of content, not compliance control reporting. Option C is incorrect because custom risk assessments are for assessing risks, not for reporting control implementation percentages for a regulatory standard. Option D is incorrect because Communication Compliance policies detect policy violations in communications, not PCI DSS control implementation status.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In Compliance Manager, open the PCI DSS assessment and view the control status.
Why this is correct
Compliance Manager ships with a pre-built PCI DSS v3.2.1 or v4.0 assessment template that maps each requirement to customer actions and Microsoft-managed controls. Opening that assessment shows per-control status (e.g., Completed, In progress, Not started), implementation and testing evidence, ownership, and corrective actions. This is the direct, supported UI for monitoring PCI DSS compliance posture, and the status reflected is exactly what an auditor would expect to see.
- ✗
Create a Data Lifecycle Management policy for PCI DSS.
Why it's wrong here
Data Lifecycle Management is a Microsoft Purview feature for governing the retention and deletion of content based on labels and policies, such as keeping audit evidence for a required retention period. Creating a policy labeled 'PCI DSS' would not evaluate or track any security control status; it only manages data aging and disposal. Compliance Manager, not Data Lifecycle Management, is the workspace where PCI DSS control assessments are actually recorded and scored.
- ✗
Create a custom risk assessment in Compliance Manager for PCI DSS.
Why it's wrong here
While Compliance Manager does allow you to create a custom risk assessment, doing so for PCI DSS is redundant and inefficient because Microsoft already provides a fully mapped, pre-built PCI DSS template. A custom assessment would require you to manually recreate the entire control framework, which risks missing mandatory requirements, and you would not receive Microsoft's periodically updated mappings and signals. Therefore, you should use the existing pre-built template rather than build a custom one for a widely adopted standard like PCI DSS.
- ✗
Configure a Communication Compliance policy to monitor PCI DSS compliance.
Why it's wrong here
Communication Compliance is designed to analyze Microsoft 365 messages and Teams chats to detect policy violations such as harassment, sensitive-data sharing, or insider-trading behavior. It does not evaluate PCI DSS technical controls, system security configurations, or audit evidence, and it has no concept of compliance assessments or control status. Since the question is about viewing PCI DSS compliance status in a central tool, this feature is outside the compliance-management workflow altogether and cannot answer the user's need.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.