SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A company's security team needs to detect and investigate potential data theft by employees who have legitimate access to sensitive data. They want a solution that uses heuristics and behavioral analytics to identify risky user actions such as data exfiltration to personal cloud storage. Which Microsoft Purview solution should they use?
⚠ Common exam trap
Many candidates confuse the reactive, policy-based enforcement of Data Loss Prevention (DLP) with the proactive, behavioral detection of Insider Risk Management, assuming DLP can detect risky user actions when it actually only blocks or alerts on content matching static rules.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Insider Risk Management
Microsoft Purview Insider Risk Management is the correct solution because it is specifically designed to detect, investigate, and act on risky user activities that may lead to data theft, using heuristics and behavioral analytics. It correlates signals from Microsoft 365 and Azure services to identify patterns like data exfiltration to personal cloud storage, which aligns directly with the scenario's requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Data Loss Prevention (DLP)
Why it's wrong here
Microsoft Purview Data Loss Prevention (DLP) is designed to prevent the unauthorized sharing or transfer of sensitive information based on content inspection and predefined policies. While it can block or warn users, it primarily acts as a rule-based prevention mechanism and does not employ behavioral analytics or machine learning to proactively detect evolving insider risks or suspicious user patterns indicative of data theft.
When this WOULD be correct
A company wants to automatically block employees from emailing credit card numbers to external recipients or uploading them to a public SharePoint site. DLP would be the correct solution to enforce policies that prevent data loss.
- ✓
Microsoft Purview Insider Risk Management
Why this is correct
Microsoft Purview Insider Risk Management is the correct solution as it specifically leverages built-in risk indicators, machine learning, and behavioral analytics to identify and investigate potential insider risks, including data theft. It correlates various user activities across Microsoft 365 services to detect unusual patterns, enabling security teams to proactively identify, analyze, and respond to incidents.
- ✗
Microsoft Purview Audit (Standard)
Why it's wrong here
Microsoft Purview Audit (Standard) provides a detailed log of user and administrator activities across Microsoft 365 services, which is essential for forensic investigations and compliance reporting. However, it is a reactive logging service that records events for later review and does not include automated detection capabilities, behavioral analytics, or machine learning to proactively identify risky patterns or potential data theft.
- ✗
Microsoft Purview Information Barriers
Why it's wrong here
Microsoft Purview Information Barriers are a compliance solution focused on preventing communication and collaboration between specific groups of users within Microsoft Teams, SharePoint, and Exchange. Its purpose is to enforce regulatory requirements by segmenting communication channels, not to detect data theft or analyze user behavior for security risks.
When this WOULD be correct
A company needs to restrict communication between two departments (e.g., traders and analysts) to prevent insider trading. Which Microsoft Purview solution should they use?
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Purview Insider Risk ManagementCorrect answer▾
Why this is correct
Microsoft Purview Insider Risk Management is the correct solution as it specifically leverages built-in risk indicators, machine learning, and behavioral analytics to identify and investigate potential insider risks, including data theft. It correlates various user activities across Microsoft 365 services to detect unusual patterns, enabling security teams to proactively identify, analyze, and respond to incidents.
✗Microsoft Purview Data Loss Prevention (DLP)Wrong answer — click to see why▾
Why this is wrong here
Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data by enforcing policies, but it does not use heuristics and behavioral analytics to detect risky user actions like data exfiltration by insiders.
★ When this WOULD be the correct answer
A company wants to automatically block employees from emailing credit card numbers to external recipients or uploading them to a public SharePoint site. DLP would be the correct solution to enforce policies that prevent data loss.
Why candidates choose this
Candidates may confuse DLP's data protection capabilities with insider risk detection, assuming that any solution involving sensitive data and prevention also covers behavioral analytics.
✗Microsoft Purview Information BarriersWrong answer — click to see why▾
Why this is wrong here
Information Barriers are designed to prevent communication and collaboration between specific groups to avoid conflicts of interest, not to detect or investigate data theft by employees with legitimate access.
★ When this WOULD be the correct answer
A company needs to restrict communication between two departments (e.g., traders and analysts) to prevent insider trading. Which Microsoft Purview solution should they use?
Why candidates choose this
Candidates may confuse 'barriers' with 'preventing data theft' and think Information Barriers can block data exfiltration, but they focus on communication restrictions, not behavioral analytics.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Insider Risk Management
Insider Risk Management is the practice of identifying, assessing, and mitigating threats that originate from within an organization, such as employees, contractors, or partners who have legitimate access to systems and data.
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.