Compliance Manager in Microsoft Purview: Assessing Compliance Posture
A compliance officer is tasked with continuously assessing the organization's compliance posture against GDPR and ISO 27001. The solution should generate a compliance score based on implemented controls, provide recommended improvement actions, and track remediation progress over time. Which Microsoft Purview solution should they use?
Quick Answer
Compliance Manager is the tool built for measuring compliance posture against a named external framework and turning that measurement into a running score — it maps an organization's current Microsoft 365 configuration against assessment templates for standards like GDPR and ISO 27001, evaluates which controls are actually satisfied, and rolls that up into a compliance score that moves as controls change over time. What makes it fit this scenario specifically, beyond just scoring, is that it also generates recommended improvement actions tied to each unmet control and tracks the organization's progress against them as remediation work gets done, so the compliance officer isn't just getting a static number but an ongoing view of where the gaps are and whether they're closing. This is a genuinely different job from DLP or sensitivity labels, which protect or restrict individual pieces of content — Compliance Manager operates one level up, assessing the overall posture of the environment against a regulatory or industry standard rather than acting on specific data. Any scenario asking for a measurable, trackable compliance score against a named standard like GDPR or ISO 27001, with guidance on what to fix next, is describing Compliance Manager.
⚠ Common exam trap
Test-takers frequently confuse Compliance Manager with Audit (Premium) because both involve compliance, but Audit is for log investigation, not for scoring or tracking control implementation against a framework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance Manager
Compliance Manager is the correct solution because it provides a continuous compliance score based on implemented controls, offers recommended improvement actions, and tracks remediation progress over time. It supports frameworks like GDPR and ISO 27001 by mapping controls to assessments and generating a dynamic score that reflects the organization's compliance posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit (Premium)
Why it's wrong here
Audit (Premium) provides forensic log retrieval for investigating events, but it does not offer compliance scoring or remediation recommendations.
When this WOULD be correct
An organization needs to enable long-term retention of audit logs, customize audit log retention policies, and gain high-bandwidth access to the Office 365 Management Activity API for security and compliance investigations.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance focuses on detecting policy violations in communications (e.g., harassment, threats), not on assessing overall compliance posture against regulatory frameworks.
When this WOULD be correct
An organization needs to detect and prevent policy violations in communications, such as offensive language or sharing confidential information, and enforce communication policies. The question would ask for a solution to monitor employee communications for regulatory compliance (e.g., SEC rules).
- ✓
Compliance Manager
Why this is correct
Compliance Manager provides built-in assessments, a compliance score, recommended actions, and supports ongoing tracking of improvement activities for standards like GDPR and ISO 27001.
- ✗
Data Lifecycle Management
Why it's wrong here
Data Lifecycle Management manages retention, deletion, and classification of data, but it does not assess compliance against specific regulations or provide scoring and recommendations.
When this WOULD be correct
A question asking for a solution to automatically retain or delete data based on regulatory requirements (e.g., GDPR right to erasure) or to manage data expiration and archiving would make Data Lifecycle Management the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Compliance ManagerCorrect answer▾
Why this is correct
Compliance Manager provides built-in assessments, a compliance score, recommended actions, and supports ongoing tracking of improvement activities for standards like GDPR and ISO 27001.
✗Audit (Premium)Wrong answer — click to see why▾
Why this is wrong here
Audit (Premium) provides advanced auditing capabilities for forensic and security investigations, but it does not generate compliance scores, recommend improvement actions, or track remediation progress against frameworks like GDPR or ISO 27001.
★ When this WOULD be the correct answer
An organization needs to enable long-term retention of audit logs, customize audit log retention policies, and gain high-bandwidth access to the Office 365 Management Activity API for security and compliance investigations.
Why candidates choose this
Candidates may confuse 'Audit' with 'Compliance Manager' because both are under Microsoft Purview and relate to compliance, but Audit focuses on logging and investigation, not continuous assessment and scoring.
✗Communication ComplianceWrong answer — click to see why▾
Why this is wrong here
Communication Compliance is designed to detect and remediate inappropriate communications (e.g., harassment, insider trading), not to assess compliance posture against regulations like GDPR or ISO 27001 or generate compliance scores.
★ When this WOULD be the correct answer
An organization needs to detect and prevent policy violations in communications, such as offensive language or sharing confidential information, and enforce communication policies. The question would ask for a solution to monitor employee communications for regulatory compliance (e.g., SEC rules).
Why candidates choose this
The term 'compliance' in the name leads candidates to assume it covers all compliance scenarios, but it specifically addresses communication risks, not overall compliance management.
✗Data Lifecycle ManagementWrong answer — click to see why▾
Why this is wrong here
Data Lifecycle Management focuses on governing data retention and deletion policies, not on assessing compliance posture, generating scores, or tracking remediation against frameworks like GDPR and ISO 27001.
★ When this WOULD be the correct answer
A question asking for a solution to automatically retain or delete data based on regulatory requirements (e.g., GDPR right to erasure) or to manage data expiration and archiving would make Data Lifecycle Management the correct answer.
Why candidates choose this
Candidates may confuse data lifecycle management with compliance management because both involve regulatory requirements, but Data Lifecycle Management does not provide compliance scoring or remediation tracking.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance Manager
A Compliance Manager is a tool or service that helps organizations assess, monitor, and improve their adherence to regulatory standards, industry frameworks, and internal policies.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A compliance officer wants a central dashboard to assess the organization's compliance posture against regulatory standards such as GDPR and ISO 27001. They need actionable recommendations to improve their compliance score and track progress over time. Which Microsoft Purview solution should they use?
medium- A.Microsoft Purview Information Protection
- B.Microsoft Purview Data Lifecycle Management
- ✓ C.Microsoft Purview Compliance Manager
- D.Microsoft Purview Audit
Why C: Microsoft Purview Compliance Manager is the correct solution because it provides a central dashboard that assesses an organization's compliance posture against regulatory standards like GDPR and ISO 27001, offers actionable recommendations to improve the compliance score, and tracks progress over time through continuous assessments and improvement actions.
Variation 2. A healthcare organization must demonstrate compliance with HIPAA by assessing their current posture against regulatory controls, tracking improvement actions, and generating reports for auditors. Which Microsoft Purview solution should they use?
medium- A.Microsoft Purview Information Protection
- B.Microsoft Purview Data Lifecycle Management
- ✓ C.Microsoft Purview Compliance Manager
- D.Microsoft Purview Insider Risk Management
Why C: Microsoft Purview Compliance Manager is the correct solution because it provides a built-in assessment template for HIPAA, enabling the organization to assess its current compliance posture against regulatory controls, track improvement actions, and generate auditor-ready reports. It offers a compliance score, automated control mapping, and evidence collection workflows specifically designed for regulatory frameworks like HIPAA.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.