Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A financial organization needs to automatically detect emails containing the phrase 'Non-Public Material Information' and apply a retention policy that retains those emails for 7 years. They also need to train senders with a policy tip before sending, and if they still send the email, it should be encrypted and blocked from being forwarded outside the organization. Which Microsoft Purview solution should they use?

⚠ Common exam trap

Many exam-takers confuse Data Lifecycle Management (retention only) with DLP (detection + action), or assume Communication Compliance handles all email content monitoring, but DLP is the only solution that combines real-time content detection, user training via policy tips, and automated enforcement actions like encryption and forwarding blocks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it can automatically detect sensitive content (e.g., 'Non-Public Material Information') in emails, apply policy tips to train senders before sending, enforce encryption, and block forwarding outside the organization. DLP policies also integrate with retention labels to retain emails for a specified period, such as 7 years, by applying a retention label automatically when the sensitive content is detected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Data Lifecycle Management

    Why it's wrong here

    Microsoft Purview Data Lifecycle Management is primarily designed for governing the retention and deletion of data across Microsoft 365 services, ensuring compliance with regulatory requirements and organizational policies. It applies retention labels and policies to manage how long data is kept or when it is permanently deleted. However, this service does not possess the capability to actively scan email content for sensitive information in real-time or automatically enforce protective actions such as encryption or blocking based on detected content.

  • Microsoft Purview Data Loss Prevention (DLP)

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) is specifically engineered to identify, monitor, and protect sensitive information across Microsoft 365, including email communications. It leverages sensitive information types, keywords, and trainable classifiers to detect specific content patterns. Upon detection, DLP policies can automatically enforce a range of protective actions, such as blocking email delivery, encrypting messages, applying specific retention labels, or providing policy tips to users, directly addressing the need for automatic detection and enforcement.

  • Microsoft Purview Communication Compliance

    Why it's wrong here

    Microsoft Purview Communication Compliance focuses on helping organizations detect, investigate, and act on inappropriate messages within their internal and external communications to mitigate risks like harassment, insider trading, or regulatory non-compliance. It uses intelligent detection and review workflows to flag potential policy violations for human review and remediation. While it monitors communications, Communication Compliance does not automatically enforce real-time protective actions like encrypting or blocking emails containing sensitive data; its primary role is monitoring and investigation.

  • Microsoft Purview Audit

    Why it's wrong here

    Microsoft Purview Audit provides comprehensive logging of user and administrator activities across Microsoft 365 services, enabling organizations to conduct forensic investigations and compliance reviews. It records events such as file access, email sends, and policy changes, which are crucial for understanding past actions and identifying potential security breaches or policy violations after they occur. However, Audit is a reactive tool for logging and reporting, not a proactive solution for automatically detecting sensitive content in emails or enforcing real-time protective measures like encryption or blocking.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.