Microsoft Purview Compliance Manager Improvement Actions for SOC 2
A company uses Microsoft Purview Compliance Manager to improve their compliance posture. They are preparing for a SOC 2 audit and need to score compliance with SOC 2 controls, track improvement actions, and assign tasks to responsible teams. Which component of Compliance Manager should they use to assign and track specific actions to improve their compliance score?
Quick Answer
The answer is the improvement action component in Microsoft Purview Compliance Manager. This is the correct choice because improvement actions are the granular, actionable tasks—such as configuring a specific security policy or enabling audit logging—that directly influence your compliance score for frameworks like SOC 2. By assigning these actions to responsible teams and tracking their completion status, you can systematically address control requirements and demonstrate measurable progress during a SOC 2 audit. On the SC-900 exam, this concept tests your understanding of how Compliance Manager operationalizes compliance, often appearing in scenario-based questions where you must distinguish improvement actions from assessments or templates. A common trap is confusing improvement actions with controls themselves, but remember: controls are the requirements, while improvement actions are the specific steps you take to meet them. For a quick memory tip, think “Actions improve your score”—if it’s a task you assign and track, it’s an improvement action.
⚠ Common exam trap
Watch out — candidates often confuse 'Control' (the requirement) with 'Improvement action' (the task to meet the requirement), leading them to select B, even though controls are not directly assignable or trackable as individual tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Improvement action
Improvement actions in Compliance Manager are the specific, actionable tasks that directly impact your compliance score. They represent the steps you need to take (e.g., configuring a policy, enabling logging) to satisfy a control. By assigning these actions to responsible teams and tracking their completion status, you can systematically improve your score and demonstrate progress during a SOC 2 audit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assessment
Why it's wrong here
An assessment groups controls for a specific regulation, but users do not assign tasks directly to assessments; tasks are assigned at the improvement action level.
- ✗
Control
Why it's wrong here
A control represents a compliance requirement. While controls have implementation status, the actionable tasks are found in improvement actions.
- ✓
Improvement action
Why this is correct
Improvement actions are detailed tasks that can be assigned to groups or individuals, tracked, and documented to demonstrate compliance progress.
- ✗
Template
Why it's wrong here
A template is a predefined set of controls for a regulation (e.g., SOC 2 template). It is not used to assign individual tasks.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company operates in multiple countries and must comply with GDPR (EU) and CCPA (California). The compliance officer needs a single tool to assess the company's compliance posture against both regulations, get a consolidated compliance score, and receive prioritized improvement actions that can be assigned to responsible teams. The tool should also track progress over time. Which Microsoft Purview solution should the compliance officer use?
hard- ✓ A.Microsoft Purview Compliance Manager
- B.Microsoft Purview Data Loss Prevention (DLP)
- C.Microsoft Purview eDiscovery (Standard)
- D.Microsoft Purview Insider Risk Management
Why A: Microsoft Purview Compliance Manager is the correct solution because it provides a unified dashboard to assess compliance posture against multiple regulations like GDPR and CCPA. It offers a consolidated compliance score, prioritized improvement actions that can be assigned to responsible teams, and tracks progress over time through continuous assessments and automated control mapping.
Variation 2. A company must comply with the General Data Protection Regulation (GDPR). They need a unified solution that provides a compliance score, actionable recommendations to improve their security posture, and the ability to track their progress over time. Additionally, they want to assign improvement actions to specific teams and automate the collection of evidence for controls. Which two Microsoft Purview solutions should the administrator use? (Select two.)
hard- ✓ A.Compliance Manager
- B.Data Lifecycle Management
- C.Insider Risk Management
- D.Audit (Premium)
Why A: Compliance Manager is correct because it provides a unified compliance score, actionable recommendations to improve security posture, and the ability to track progress over time. It also allows administrators to assign improvement actions to specific teams and automate evidence collection for controls, directly meeting all the stated GDPR compliance requirements.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.