SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A company must retain all customer contracts for 10 years to comply with industry regulations. After 10 years, the contracts must be permanently deleted. Which Microsoft Purview solution should be used to automate this process?
⚠ Common exam trap
Test-takers frequently confuse Data Lifecycle Management with Data Loss Prevention, mistakenly thinking DLP can delete data after a period, when DLP only blocks or alerts on data exfiltration, not manage retention schedules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Lifecycle Management
Data Lifecycle Management (DLM) in Microsoft Purview is the correct solution because it allows you to define retention labels and policies that automatically retain contracts for a specified period (10 years) and then trigger a permanent deletion disposition review or direct deletion. This aligns directly with the regulatory requirement to retain data for a fixed duration and then dispose of it securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Loss Prevention (DLP)
Why it's wrong here
Data Loss Prevention (DLP) policies in Microsoft Purview are specifically engineered to identify, monitor, and protect sensitive information from being inappropriately shared, transferred, or used. DLP focuses on preventing data exfiltration or unauthorized access by detecting sensitive content and enforcing protective actions. It does not, however, provide functionality for defining or managing the long-term retention periods or automated deletion schedules required for data lifecycle compliance.
When this WOULD be correct
A company wants to automatically detect and block emails containing credit card numbers from being sent to external recipients. DLP policies would be the correct solution to enforce this rule.
- ✓
Data Lifecycle Management
Why this is correct
Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels and policies to govern the entire lifecycle of data, from creation to deletion. It enables organizations to define specific retention periods, such as 10 years for customer contracts, ensuring compliance with legal or regulatory obligations. After the retention period expires, DLM policies can automatically dispose of the data, streamlining information governance and reducing risk.
- ✗
eDiscovery
Why it's wrong here
eDiscovery tools, such as Microsoft Purview eDiscovery (Standard and Premium), are designed for identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI) for legal cases or investigations. While eDiscovery can place content on legal hold to prevent deletion, its primary function is not to define or enforce automated, scheduled retention and subsequent deletion policies for routine compliance requirements like a 10-year contract retention.
- ✗
Information Protection
Why it's wrong here
Microsoft Purview Information Protection (MPIP) primarily focuses on classifying and protecting sensitive data using sensitivity labels. These labels can encrypt content, apply visual markings, and restrict access based on user permissions. While sensitivity labels can be *combined* with retention labels, Information Protection itself is not the mechanism for defining or enforcing the automated retention periods and subsequent deletion policies necessary for managing data throughout its lifecycle. Its core purpose is data classification and protection.
When this WOULD be correct
A company needs to automatically apply encryption and access restrictions to all customer contracts containing personally identifiable information (PII) to prevent unauthorized sharing. Information Protection with sensitivity labels would be the correct solution.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Data Lifecycle ManagementCorrect answer▾
Why this is correct
Data Lifecycle Management (DLM) in Microsoft 365 utilizes retention labels and policies to govern the entire lifecycle of data, from creation to deletion. It enables organizations to define specific retention periods, such as 10 years for customer contracts, ensuring compliance with legal or regulatory obligations. After the retention period expires, DLM policies can automatically dispose of the data, streamlining information governance and reducing risk.
✗Data Loss Prevention (DLP)Wrong answer — click to see why▾
Why this is wrong here
Data Loss Prevention (DLP) is designed to prevent accidental sharing or leakage of sensitive data, not to automate retention and deletion of records based on a fixed time period.
★ When this WOULD be the correct answer
A company wants to automatically detect and block emails containing credit card numbers from being sent to external recipients. DLP policies would be the correct solution to enforce this rule.
Why candidates choose this
Candidates may confuse DLP with retention policies because both involve data governance, but DLP focuses on preventing data loss, not lifecycle management.
✗Information ProtectionWrong answer — click to see why▾
Why this is wrong here
Information Protection focuses on classifying, labeling, and protecting sensitive data (e.g., encryption, rights management), not on automated retention and deletion schedules. The requirement to retain and then delete contracts after 10 years is a lifecycle management task, not a protection task.
★ When this WOULD be the correct answer
A company needs to automatically apply encryption and access restrictions to all customer contracts containing personally identifiable information (PII) to prevent unauthorized sharing. Information Protection with sensitivity labels would be the correct solution.
Why candidates choose this
Candidates may confuse 'protecting' data with 'managing its lifecycle,' assuming that retention and deletion are part of protection. The term 'Information Protection' sounds broad enough to include retention policies, but in Microsoft Purview it specifically covers classification and protection controls.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
Regulatory requirement
A regulatory requirement is a rule issued by a government or industry authority that organizations must follow, often to protect data, ensure safety, or maintain fair practices.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.