Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company must retain all customer contracts for 10 years to comply with industry regulations. After 10 years, the contracts must be permanently deleted. Which Microsoft Purview solution should be used to automate this process?

⚠ Common exam trap

Test-takers frequently confuse Data Lifecycle Management with Data Loss Prevention, mistakenly thinking DLP can delete data after a period, when DLP only blocks or alerts on data exfiltration, not manage retention schedules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Lifecycle Management

Data Lifecycle Management (DLM) in Microsoft Purview is the correct solution because it allows you to define retention labels and policies that automatically retain contracts for a specified period (10 years) and then trigger a permanent deletion disposition review or direct deletion. This aligns directly with the regulatory requirement to retain data for a fixed duration and then dispose of it securely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention (DLP) policies in Microsoft Purview are specifically engineered to identify, monitor, and protect sensitive information from being inappropriately shared, transferred, or used. DLP focuses on preventing data exfiltration or unauthorized access by detecting sensitive content and enforcing protective actions. It does not, however, provide functionality for defining or managing the long-term retention periods or automated deletion schedules required for data lifecycle compliance.

    When this WOULD be correct

    A company wants to automatically detect and block emails containing credit card numbers from being sent to external recipients. DLP policies would be the correct solution to enforce this rule.

  • Data Lifecycle Management

    Why this is correct

    Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels and policies to govern the entire lifecycle of data, from creation to deletion. It enables organizations to define specific retention periods, such as 10 years for customer contracts, ensuring compliance with legal or regulatory obligations. After the retention period expires, DLM policies can automatically dispose of the data, streamlining information governance and reducing risk.

  • eDiscovery

    Why it's wrong here

    eDiscovery tools, such as Microsoft Purview eDiscovery (Standard and Premium), are designed for identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI) for legal cases or investigations. While eDiscovery can place content on legal hold to prevent deletion, its primary function is not to define or enforce automated, scheduled retention and subsequent deletion policies for routine compliance requirements like a 10-year contract retention.

  • Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection (MPIP) primarily focuses on classifying and protecting sensitive data using sensitivity labels. These labels can encrypt content, apply visual markings, and restrict access based on user permissions. While sensitivity labels can be *combined* with retention labels, Information Protection itself is not the mechanism for defining or enforcing the automated retention periods and subsequent deletion policies necessary for managing data throughout its lifecycle. Its core purpose is data classification and protection.

    When this WOULD be correct

    A company needs to automatically apply encryption and access restrictions to all customer contracts containing personally identifiable information (PII) to prevent unauthorized sharing. Information Protection with sensitivity labels would be the correct solution.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Data Lifecycle ManagementCorrect answer

Why this is correct

Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels and policies to govern the entire lifecycle of data, from creation to deletion. It enables organizations to define specific retention periods, such as 10 years for customer contracts, ensuring compliance with legal or regulatory obligations. After the retention period expires, DLM policies can automatically dispose of the data, streamlining information governance and reducing risk.

Data Loss Prevention (DLP)Wrong answer — click to see why

Why this is wrong here

Data Loss Prevention (DLP) is designed to prevent accidental sharing or leakage of sensitive data, not to automate retention and deletion of records based on a fixed time period.

★ When this WOULD be the correct answer

A company wants to automatically detect and block emails containing credit card numbers from being sent to external recipients. DLP policies would be the correct solution to enforce this rule.

Why candidates choose this

Candidates may confuse DLP with retention policies because both involve data governance, but DLP focuses on preventing data loss, not lifecycle management.

Information ProtectionWrong answer — click to see why

Why this is wrong here

Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not on automated retention and deletion schedules. The requirement to retain and then delete contracts after 10 years is a lifecycle management task, not a protection task.

★ When this WOULD be the correct answer

A company needs to automatically apply encryption and access restrictions to all customer contracts containing personally identifiable information (PII) to prevent unauthorized sharing. Information Protection with sensitivity labels would be the correct solution.

Why candidates choose this

Candidates may confuse 'protecting' data with 'managing its lifecycle,' assuming that retention and deletion are part of protection. The term 'Information Protection' sounds broad enough to include retention policies, but in Microsoft Purview it specifically covers classification and protection controls.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.