SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A data analyst is planning to leave the company in two weeks and has access to a large volume of sensitive customer data. The compliance team wants to detect if the analyst starts downloading large amounts of files to a personal USB drive or sending sensitive content to an external email address. They need to set up a policy that alerts on such anomalous data exfiltration activities without blocking operations until a thorough investigation is completed. Which Microsoft Purview solution should they configure?
⚠ Common exam trap
Test-takers frequently confuse Insider Risk Management with Communication Compliance, but Communication Compliance focuses on communication content (e.g., offensive language) rather than behavioral data exfiltration patterns like USB downloads or bulk external emails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Insider Risk Management
Microsoft Purview Insider Risk Management is designed to detect, investigate, and act on risky user activities, including data exfiltration by departing employees. It uses predefined indicators such as downloading files to USB drives or sending emails to external addresses, and can generate alerts without automatically blocking operations, allowing for a thorough investigation first.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Insider Risk Management
Why this is correct
Microsoft Purview Insider Risk Management is the correct solution as it proactively identifies and mitigates potential data exfiltration risks from within the organization. It leverages machine learning to detect anomalous user behaviors, such as unusual download volumes, email forwarding, or cloud uploads, especially when correlated with HR signals like an employee's impending departure. The service provides configurable policies, alerts security teams to suspicious activities, and offers case management tools for investigation and remediation, directly addressing the scenario of a departing data analyst.
- ✗
Microsoft Purview Data Lifecycle Management
Why it's wrong here
Microsoft Purview Data Lifecycle Management focuses on automating the retention, deletion, and disposition of data across an organization based on predefined policies and regulatory requirements. Its primary function is to ensure data is kept for the necessary duration and then appropriately removed, thereby managing storage costs and compliance. This service does not monitor user actions, detect anomalous behaviors like large-scale data downloads, or provide real-time alerts for potential data exfiltration, making it unsuitable for the given scenario.
When this WOULD be correct
An organization needs to automatically retain customer data for 7 years to meet regulatory requirements and then securely delete it. They should configure Microsoft Purview Data Lifecycle Management to apply retention labels and deletion policies.
- ✗
Microsoft Purview Communication Compliance
Why it's wrong here
Microsoft Purview Communication Compliance is designed to help organizations detect, investigate, and remediate policy violations in internal and external communications, such as harassment, sensitive information sharing, or regulatory non-compliance. It analyzes messages and attachments within platforms like Microsoft Teams, Exchange, and Yammer for specific content patterns. However, its scope is limited to communication content and does not extend to monitoring or alerting on bulk data downloads from SharePoint, OneDrive, or other endpoints, which are common methods for data exfiltration.
When this WOULD be correct
An organization wants to detect and prevent employees from sharing confidential information via email or Microsoft Teams messages, such as sending customer data to external recipients. They need a policy that scans communications for sensitive content and can enforce actions like blocking the message.
- ✗
Microsoft Purview eDiscovery (Standard)
Why it's wrong here
Microsoft Purview eDiscovery (Standard) is primarily designed for legal and regulatory compliance, enabling organizations to search for, preserve, and export content from various Microsoft 365 locations in response to litigation or investigative requests. While it can identify where data resides, it is a reactive tool for content discovery and preservation, not a proactive system for detecting real-time user behaviors like bulk data downloads or other exfiltration attempts by a departing employee. It lacks the behavioral analytics and alerting capabilities required for this scenario.
When this WOULD be correct
A legal team needs to identify and preserve all emails and documents related to a specific litigation case from a departing employee's mailbox and OneDrive. They require a solution to search, hold, and export relevant data for eDiscovery purposes.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Microsoft Purview Insider Risk ManagementCorrect answer▾
Why this is correct
Microsoft Purview Insider Risk Management is the correct solution as it proactively identifies and mitigates potential data exfiltration risks from within the organization. It leverages machine learning to detect anomalous user behaviors, such as unusual download volumes, email forwarding, or cloud uploads, especially when correlated with HR signals like an employee's impending departure. The service provides configurable policies, alerts security teams to suspicious activities, and offers case management tools for investigation and remediation, directly addressing the scenario of a departing data analyst.
✗Microsoft Purview Data Lifecycle ManagementWrong answer — click to see why▾
Why this is wrong here
Microsoft Purview Data Lifecycle Management focuses on retaining and deleting data based on policies, not on detecting anomalous user behavior like data exfiltration to USB drives or external emails.
★ When this WOULD be the correct answer
An organization needs to automatically retain customer data for 7 years to meet regulatory requirements and then securely delete it. They should configure Microsoft Purview Data Lifecycle Management to apply retention labels and deletion policies.
Why candidates choose this
Candidates may confuse data lifecycle management with data security controls, thinking that managing data retention also covers monitoring data movement, but it does not include behavioral detection.
✗Microsoft Purview Communication ComplianceWrong answer — click to see why▾
Why this is wrong here
Microsoft Purview Communication Compliance monitors communications for policy violations like inappropriate language or sharing sensitive info, but it does not detect anomalous data exfiltration activities such as bulk file downloads to USB drives.
★ When this WOULD be the correct answer
An organization wants to detect and prevent employees from sharing confidential information via email or Microsoft Teams messages, such as sending customer data to external recipients. They need a policy that scans communications for sensitive content and can enforce actions like blocking the message.
Why candidates choose this
Candidates may confuse Communication Compliance with Insider Risk Management because both deal with insider threats and data leakage, but Communication Compliance focuses on communications rather than behavioral patterns like file downloads.
✗Microsoft Purview eDiscovery (Standard)Wrong answer — click to see why▾
Why this is wrong here
Microsoft Purview eDiscovery (Standard) is used for searching and exporting content for legal or investigative purposes, not for real-time detection and alerting on anomalous data exfiltration activities. It does not provide proactive alerts on user behavior like downloading files to USB drives or sending sensitive emails.
★ When this WOULD be the correct answer
A legal team needs to identify and preserve all emails and documents related to a specific litigation case from a departing employee's mailbox and OneDrive. They require a solution to search, hold, and export relevant data for eDiscovery purposes.
Why candidates choose this
Candidates may confuse eDiscovery's ability to search and export data with the detection of data exfiltration, assuming that monitoring for large downloads falls under the same umbrella of data investigation.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Insider Risk Management
Insider Risk Management is the practice of identifying, assessing, and mitigating threats that originate from within an organization, such as employees, contractors, or partners who have legitimate access to systems and data.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.