SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A compliance administrator needs to generate a report showing all user activities related to accessing highly sensitive documents in SharePoint. Which Microsoft Purview solution should they use?
⚠ Common exam trap
Watch out — candidates often confuse eDiscovery (which finds content) with Audit (which tracks activities), assuming both can generate activity reports, but only Audit captures the specific user actions needed for this scenario.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Audit (Standard or Premium)
Audit (Standard or Premium) logs and records all user activities, including access to highly sensitive documents in SharePoint. Audit (Premium) provides deeper visibility with events like 'FileAccessed' and 'SensitivityLabelApplied', enabling compliance administrators to generate detailed reports on who accessed sensitive content and when.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Audit (Standard or Premium)
Why this is correct
Microsoft Purview Audit (Standard or Premium) is the correct service for generating reports on user and administrator activities across Microsoft 365 services. It captures a comprehensive record of events, such as file access, mailbox activities, and system configuration changes, which are crucial for forensic investigations, regulatory compliance, and internal policy adherence. The unified audit log allows compliance administrators to search, filter, and export these activity records to demonstrate compliance with various regulations.
- ✗
eDiscovery
Why it's wrong here
Microsoft Purview eDiscovery (Standard or Premium) is designed to identify, preserve, collect, and export electronic content for legal or investigative purposes. While it can search for specific items within mailboxes, documents, or Teams chats, its primary function is content discovery, not generating reports on user activities or system events. It does not provide a comprehensive log of actions taken by users or administrators across the tenant.
- ✗
Data Loss Prevention
Why it's wrong here
Microsoft Purview Data Loss Prevention (DLP) policies are configured to identify, monitor, and protect sensitive information from being shared inappropriately. While DLP generates incident reports when a policy is matched and an action is taken (e.g., blocking sharing or notifying an administrator), these reports are specific to sensitive data policy violations. DLP does not provide a broad activity log of all user actions, such as general file access or system changes, which a compliance administrator would need for a comprehensive activity report.
- ✗
Communication Compliance
Why it's wrong here
Microsoft Purview Communication Compliance helps organizations detect, investigate, and act on inappropriate messages in their internal and external communications, such as harassment, threats, or regulatory violations. It focuses on analyzing content within communication channels like Microsoft Teams, Exchange, and Yammer. While it generates alerts and reports related to communication policy matches, it does not provide a comprehensive audit trail of general user activities or system events across the entire Microsoft 365 environment.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.