SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A compliance officer needs to identify and monitor potentially risky user activities, such as users copying large amounts of data to external devices or sharing sensitive files with unauthorized recipients. They want to create a policy that detects these activities and automatically escalates them for investigation. Which Microsoft Purview solution should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Insider Risk Management
Microsoft Purview Insider Risk Management is specifically designed to detect and investigate malicious or inadvertent insider risks based on activities like data exfiltration, unusual file sharing, or violations of corporate policies. It uses indicators and adaptive policies to assign risk scores and trigger alerts for review. Audit (option B) only provides logging and does not have built-in risk analysis. Communication Compliance (option C) focuses on inappropriate communications, not data-related risks. Compliance Manager (option D) assesses compliance posture but does not detect risky user activities. Therefore, Insider Risk Management is the correct solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Insider Risk Management
Why this is correct
Microsoft Purview Insider Risk Management is the correct solution as it proactively identifies, analyzes, and acts on risky activities within an organization. It leverages machine learning and adaptive analytics to detect potential data exfiltration, intellectual property theft, and policy violations by employees, assigning risk scores and automatically generating cases for investigation by security teams. This capability directly addresses the need to identify and monitor potentially risky insider activities.
- ✗
Microsoft Purview Audit
Why it's wrong here
Microsoft Purview Audit provides detailed logs of user and administrator activities across Microsoft 365 services, serving as a crucial forensic tool for investigations and compliance reviews. However, it does not automatically detect or escalate risky patterns of behavior in real-time; it requires manual analysis of activity logs to identify potential threats. Therefore, it cannot proactively identify and monitor potentially risky activities without significant manual effort.
- ✗
Microsoft Purview Communication Compliance
Why it's wrong here
Microsoft Purview Communication Compliance is designed to detect and remediate inappropriate or policy-violating communications within an organization, such as harassment, discriminatory language, or the sharing of sensitive information via chat and email. Its focus is on the content and context of messages, not on broader patterns of data movement, copying, or exfiltration that characterize insider risk. Thus, it is not suited for monitoring general data handling activities for risk.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Microsoft Purview Compliance Manager assists organizations in assessing, managing, and improving their compliance posture against various regulatory standards and industry frameworks. It provides actionable recommendations, tracks progress, and generates reports on compliance scores. While vital for overall compliance management, it is a governance and reporting tool and does not possess the real-time monitoring or threat detection capabilities required to identify and investigate risky user activities.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.