SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A company uses Microsoft 365. The compliance team needs to create a policy that automatically blocks outgoing emails that contain personally identifiable information (PII) such as social security numbers. However, they want to allow users to override the block with a business justification if necessary. Which Microsoft Purview solution should they configure?
⚠ Common exam trap
Many exam-takers confuse Communication Compliance with DLP because both involve monitoring communications, but Communication Compliance is for policy violations and insider risk, not for automated blocking of sensitive data with user overrides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) in Microsoft Purview is designed to detect and protect sensitive information, such as social security numbers, by automatically blocking outgoing emails that contain PII. DLP policies support user override with a business justification through policy tips and allow overrides, enabling compliance teams to balance security with business needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP)
Why this is correct
Data Loss Prevention (DLP) in Microsoft 365 is specifically designed to identify, monitor, and protect sensitive information across various locations, including email, SharePoint, and OneDrive. It uses sensitive information types (SITs) to detect data like credit card numbers or PII, allowing organizations to define policies that block sharing, encrypt content, or notify users and administrators. This capability directly addresses the need to prevent accidental or malicious sharing of sensitive data, often providing user override options for legitimate business cases.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance in Microsoft 365 is engineered to help organizations detect and remediate inappropriate communications, such as harassment, offensive language, or insider trading risks, within internal and external messages. It leverages machine learning and policy templates to identify specific types of policy violations, facilitating review workflows for designated compliance officers. Unlike DLP, its primary focus is on behavioral and content-based risks in communications, rather than the real-time blocking of specific sensitive data types like PII from being shared.
When this WOULD be correct
A company needs to monitor employee communications for policy violations (e.g., offensive language or sharing confidential information) and allow managers to review and take action. The question would specify detecting and remediating communication risks rather than blocking data exfiltration.
- ✗
Records Management
Why it's wrong here
Records Management within Microsoft 365 focuses on the lifecycle governance of information, ensuring that organizational data is retained for specific periods and then disposed of according to regulatory and internal policies. Its primary function is to manage retention labels, disposition reviews, and legal holds, thereby supporting compliance with data longevity requirements. However, it does not provide real-time detection or blocking capabilities for sensitive data in transit, making it unsuitable for preventing immediate data exfiltration.
When this WOULD be correct
A company needs to automatically apply retention labels to emails containing specific keywords and ensure they are retained for a regulatory period. Records Management would be the correct solution for defining retention policies and labels.
- ✗
Audit
Why it's wrong here
Microsoft 365 Audit provides a comprehensive log of user and administrator activities across various services, enabling organizations to investigate security incidents, comply with regulatory requirements, and monitor for suspicious behavior. While crucial for forensic analysis and accountability, the Audit service is purely a logging mechanism. It does not possess any proactive capabilities to block content, prevent data sharing, or offer user override options, as its role is to record events rather than enforce real-time content policies.
When this WOULD be correct
An organization needs to investigate a specific data breach by reviewing detailed logs of who accessed sensitive files and when. Audit would be the correct solution to enable and search the audit log for relevant events.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Data Loss Prevention (DLP)Correct answer▾
Why this is correct
Data Loss Prevention (DLP) in Microsoft 365 is specifically designed to identify, monitor, and protect sensitive information across various locations, including email, SharePoint, and OneDrive. It uses sensitive information types (SITs) to detect data like credit card numbers or PII, allowing organizations to define policies that block sharing, encrypt content, or notify users and administrators. This capability directly addresses the need to prevent accidental or malicious sharing of sensitive data, often providing user override options for legitimate business cases.
✗Communication ComplianceWrong answer — click to see why▾
Why this is wrong here
Communication Compliance is designed to detect and manage inappropriate communications (e.g., harassment, insider trading), not to automatically block outgoing emails containing PII with user override capabilities.
★ When this WOULD be the correct answer
A company needs to monitor employee communications for policy violations (e.g., offensive language or sharing confidential information) and allow managers to review and take action. The question would specify detecting and remediating communication risks rather than blocking data exfiltration.
Why candidates choose this
Candidates may confuse Communication Compliance with DLP because both deal with email content and compliance, but Communication Compliance focuses on human behavior monitoring rather than automated data protection.
✗Records ManagementWrong answer — click to see why▾
Why this is wrong here
Records Management focuses on managing retention, disposition, and classification of records, not on preventing data leakage via email. It does not provide the ability to block outgoing emails containing PII or allow user overrides.
★ When this WOULD be the correct answer
A company needs to automatically apply retention labels to emails containing specific keywords and ensure they are retained for a regulatory period. Records Management would be the correct solution for defining retention policies and labels.
Why candidates choose this
Candidates may confuse Records Management with data governance or mistakenly think it includes data loss prevention capabilities, especially since both involve policies and sensitive data classification.
✗AuditWrong answer — click to see why▾
Why this is wrong here
Audit in Microsoft Purview is used for logging and reviewing user and admin activities, not for creating policies that block or allow emails based on content like PII.
★ When this WOULD be the correct answer
An organization needs to investigate a specific data breach by reviewing detailed logs of who accessed sensitive files and when. Audit would be the correct solution to enable and search the audit log for relevant events.
Why candidates choose this
Candidates may confuse Audit with monitoring or compliance solutions, thinking that auditing can enforce policies, but it only provides visibility after the fact, not real-time control.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.