Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company's security team needs to detect and investigate potential data theft by employees who have legitimate access to sensitive data. They want a solution that uses heuristics and behavioral analytics to identify risky user actions such as data exfiltration to personal cloud storage. Which Microsoft Purview solution should they use?

⚠ Common exam trap

Many candidates confuse the reactive, policy-based enforcement of Data Loss Prevention (DLP) with the proactive, behavioral detection of Insider Risk Management, assuming DLP can detect risky user actions when it actually only blocks or alerts on content matching static rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Insider Risk Management

Microsoft Purview Insider Risk Management is the correct solution because it is specifically designed to detect, investigate, and act on risky user activities that may lead to data theft, using heuristics and behavioral analytics. It correlates signals from Microsoft 365 and Azure services to identify patterns like data exfiltration to personal cloud storage, which aligns directly with the scenario's requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Data Loss Prevention (DLP)

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) is designed to prevent the unauthorized sharing or transfer of sensitive information based on content inspection and predefined policies. While it can block or warn users, it primarily acts as a rule-based prevention mechanism and does not employ behavioral analytics or machine learning to proactively detect evolving insider risks or suspicious user patterns indicative of data theft.

    When this WOULD be correct

    A company wants to automatically block employees from emailing credit card numbers to external recipients or uploading them to a public SharePoint site. DLP would be the correct solution to enforce policies that prevent data loss.

  • Microsoft Purview Insider Risk Management

    Why this is correct

    Microsoft Purview Insider Risk Management is the correct solution as it specifically leverages built-in risk indicators, machine learning, and behavioral analytics to identify and investigate potential insider risks, including data theft. It correlates various user activities across Microsoft 365 services to detect unusual patterns, enabling security teams to proactively identify, analyze, and respond to incidents.

  • Microsoft Purview Audit (Standard)

    Why it's wrong here

    Microsoft Purview Audit (Standard) provides a detailed log of user and administrator activities across Microsoft 365 services, which is essential for forensic investigations and compliance reporting. However, it is a reactive logging service that records events for later review and does not include automated detection capabilities, behavioral analytics, or machine learning to proactively identify risky patterns or potential data theft.

  • Microsoft Purview Information Barriers

    Why it's wrong here

    Microsoft Purview Information Barriers are a compliance solution focused on preventing communication and collaboration between specific groups of users within Microsoft Teams, SharePoint, and Exchange. Its purpose is to enforce regulatory requirements by segmenting communication channels, not to detect data theft or analyze user behavior for security risks.

    When this WOULD be correct

    A company needs to restrict communication between two departments (e.g., traders and analysts) to prevent insider trading. Which Microsoft Purview solution should they use?

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Purview Insider Risk ManagementCorrect answer

Why this is correct

Microsoft Purview Insider Risk Management is the correct solution as it specifically leverages built-in risk indicators, machine learning, and behavioral analytics to identify and investigate potential insider risks, including data theft. It correlates various user activities across Microsoft 365 services to detect unusual patterns, enabling security teams to proactively identify, analyze, and respond to incidents.

Microsoft Purview Data Loss Prevention (DLP)Wrong answer — click to see why

Why this is wrong here

Microsoft Purview Data Loss Prevention (DLP) is designed to prevent accidental or unauthorized sharing of sensitive data by enforcing policies, but it does not use heuristics and behavioral analytics to detect risky user actions like data exfiltration by insiders.

★ When this WOULD be the correct answer

A company wants to automatically block employees from emailing credit card numbers to external recipients or uploading them to a public SharePoint site. DLP would be the correct solution to enforce policies that prevent data loss.

Why candidates choose this

Candidates may confuse DLP's data protection capabilities with insider risk detection, assuming that any solution involving sensitive data and prevention also covers behavioral analytics.

Microsoft Purview Information BarriersWrong answer — click to see why

Why this is wrong here

Information Barriers are designed to prevent communication and collaboration between specific groups to avoid conflicts of interest, not to detect or investigate data theft by employees with legitimate access.

★ When this WOULD be the correct answer

A company needs to restrict communication between two departments (e.g., traders and analysts) to prevent insider trading. Which Microsoft Purview solution should they use?

Why candidates choose this

Candidates may confuse 'barriers' with 'preventing data theft' and think Information Barriers can block data exfiltration, but they focus on communication restrictions, not behavioral analytics.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.