SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A company must retain all customer service emails in Exchange Online for 7 years for regulatory purposes. After 7 years, the emails must be automatically deleted. Additionally, employees must not be able to permanently delete these emails before the retention period ends. Which Microsoft Purview solution should they configure?
⚠ Common exam trap
Watch out — candidates often confuse retention policies (which enforce deletion after a period) with eDiscovery holds (which preserve content indefinitely for legal cases), leading them to select eDiscovery (Premium) instead of Data Lifecycle Management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Lifecycle Management (retention policies and labels)
Data Lifecycle Management (DLM) via retention policies and labels in Microsoft Purview is the correct solution because it allows you to define a retention period of 7 years for Exchange Online emails and then automatically delete them. Additionally, DLM retention policies prevent users from permanently deleting emails before the retention period ends by locking the items in a 'preservation hold' state, ensuring regulatory compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Lifecycle Management (retention policies and labels)
Why this is correct
Data Lifecycle Management, specifically through Microsoft 365 retention policies and retention labels, is the precise solution for enforcing long-term data retention requirements. Retention policies can be applied broadly to Exchange mailboxes to ensure all customer service emails are preserved for a specified duration, such as seven years, preventing both accidental and malicious deletion by users. These policies also manage the automatic deletion of content after its retention period expires, ensuring compliance with regulatory and organizational data lifecycle mandates.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance in Microsoft 365 is primarily designed to help organizations detect, investigate, and act on inappropriate or non-compliant communications within their environment. It focuses on identifying sensitive information, harassment, or regulatory violations through policies that scan messages for specific content or patterns. While it monitors communications, it does not provide the mechanisms for enforcing long-term data retention periods or managing the lifecycle of data through automated deletion, making it unsuitable for the stated requirement.
- ✗
eDiscovery (Premium)
Why it's wrong here
eDiscovery (Premium) in Microsoft 365 is a specialized toolset used for identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI) for legal or investigative purposes. It enables placing legal holds on content to prevent its deletion and facilitates comprehensive searches across various data sources. However, eDiscovery is a reactive tool for specific cases, not a proactive system for establishing and enforcing an organization-wide, automated data retention and deletion schedule. It does not manage the routine lifecycle of data.
- ✗
Data Loss Prevention (DLP)
Why it's wrong here
Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information from being inadvertently or maliciously shared outside the organization or with unauthorized individuals internally. DLP focuses on preventing data exfiltration or inappropriate access by detecting sensitive data types and enforcing actions like blocking, auditing, or encrypting. While crucial for data security, DLP policies do not offer any functionality for defining, enforcing, or managing the long-term retention periods or automated deletion of data within an organization's systems.
Go deeper
Related to this question
Learn chapter
Microsoft Compliance Manager Score
Key term
Data lifecycle management
Data lifecycle management is the process of managing data from its creation to its deletion, ensuring it is stored, used, and disposed of in a way that meets security, compliance, and business needs.
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.