Courseiva
mediumMatching

SC-200 Practice Question: Match each Microsoft Purview compliance feature…

Match each Microsoft Purview compliance feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Prevents accidental sharing of sensitive data

Searches and exports data for legal cases

Logs user and admin activities

Classifies and protects sensitive data with labels

Manages retention and disposal of records

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Lifecycle Management: Governs data retention and deletion to meet compliance and legal obligations.

The correct matches are: Data Lifecycle Management with retention/deletion, MIP with classification/protection, Insider Risk Management with internal risk detection, and Communication Compliance with monitoring communications. Common confusions arise from overlapping scopes, such as communication monitoring being mistaken for data lifecycle or classification being misattributed to insider risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data Lifecycle Management: Governs data retention and deletion to meet compliance and legal obligations.

    Why this is correct

    Data Lifecycle Management in Microsoft Purview governs how data is retained and ultimately deleted across workloads such as Exchange, SharePoint, OneDrive, and Microsoft 365 Groups. It uses retention policies and retention labels to automatically keep data for a defined period and then dispose of it, addressing legal, regulatory, and organizational obligations. This is distinct from data classification or monitoring.

  • ✓

    Microsoft Information Protection: Discovers, classifies, and protects sensitive data across all environments.

    Why this is correct

    Microsoft Information Protection (MIP) is the Purview capability that discovers sensitive data through built-in and custom sensitive information types, classifies it with sensitivity labels, and applies protection such as encryption and access restrictions. It works across Microsoft 365 workloads and extends to endpoints, on-premises file shares, and third-party cloud apps via connectors. This covers labeling and protection, not retention/deletion or monitoring.

  • ✓

    Insider Risk Management: Identifies and helps mitigate internal risks to prevent data leaks and noncompliance.

    Why this is correct

    Insider Risk Management uses signals from user activities, HR indicators, and security alerts to score and detect risky insider behaviors such as exfiltration, data theft, or malicious sharing that violate policy. It applies adaptive analytics and provides detection, investigation, and response workflows so organizations can mitigate risk while preserving user privacy through role-based access and audit trails. Its focus is on user behavior, not data labeling or retention.

  • ✓

    Communication Compliance: Monitors communications to detect policy violations and ensure regulatory compliance.

    Why this is correct

    Communication Compliance monitors corporate communications including email, Microsoft Teams, and third-party chat and collaboration channels for policy violations such as harassment, threatening language, confidential information sharing, and compliance infractions. It uses trainable classifiers and condition policies to flag review-worthy messages and route them to designated reviewers for investigation and remediation. This is specifically about message content, not data retention or lifecycle policies.

  • ✗

    Data Lifecycle Management: Monitors communications to detect policy violations and ensure regulatory compliance.

    Why it's wrong here

    This statement incorrectly assigns the monitoring of communications for policy violations to Data Lifecycle Management. Detecting and remediating inappropriate or noncompliant messages, such as harassment or regulatory breaches, is the function of Communication Compliance, not Data Lifecycle Management. Data Lifecycle Management is only concerned with retention schedules and deletion of data once it reaches end of life.

  • ✗

    Insider Risk Management: Classifies sensitive data and applies protection policies.

    Why it's wrong here

    This statement wrongly equates Insider Risk Management with classifying and protecting sensitive data. Discovering and labeling data with sensitivity labels, as well as applying encryption or permissions, falls under Microsoft Information Protection. Insider Risk Management instead analyzes behavioral signals to detect internal users who might leak or misuse data.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.