Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A financial services company is required by the Payment Card Industry Data Security Standard (PCI-DSS) to retain all documents containing credit card numbers for at least seven years. The compliance team has created a custom sensitive information type (SIT) to detect credit card numbers in Microsoft 365. They want to automatically apply a retention label (e.g., "7-Year Retention") to any document in SharePoint or OneDrive that matches this SIT. Which Microsoft Purview solution should they configure to apply the label automatically based on content?

⚠ Common exam trap

Candidates often confuse Data Loss Prevention (DLP) with Data Lifecycle Management because both use sensitive information types, but DLP is for protection (blocking/sharing) while DLM is for governance (retention/deletion).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Lifecycle Management

Data Lifecycle Management (DLM) in Microsoft Purview is the solution specifically designed for automatically applying retention labels based on conditions like sensitive information types (SITs). By creating a retention label policy with auto-labeling rules that reference the custom SIT for credit card numbers, DLM can automatically assign the '7-Year Retention' label to documents in SharePoint and OneDrive that contain PCI-DSS data, ensuring compliance with retention requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    DLP policies are designed to prevent sensitive information from being shared externally or used inappropriately. They can detect credit card numbers but do not automatically apply retention labels. They may show a policy tip or block sharing.

  • Insider Risk Management

    Why it's wrong here

    Insider Risk Management is designed to identify, investigate, and act on potentially malicious or inadvertent risky activities by internal users, such as data exfiltration or intellectual property theft. It leverages behavioral analytics and signals across Microsoft 365 services to detect patterns indicative of insider risk. While it can detect sensitive data being mishandled, its function is focused on user behavior and risk mitigation, not on automatically applying data governance actions like retention labels to content based on its classification.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance policies are specifically engineered to help organizations detect and remediate inappropriate content within internal and external communications, such as email, Microsoft Teams, and Yammer. These policies monitor for regulatory compliance violations, offensive language, or harassment, enabling designated reviewers to investigate and take action on messages. Its scope is limited to communication content and its actions involve review and remediation of messages, not the application of retention labels to documents or files for data lifecycle management.

    When this WOULD be correct

    An organization wants to automatically detect and review emails containing confidential financial data (e.g., unreleased earnings reports) sent to external parties, and optionally escalate for legal investigation. Communication Compliance would be the correct solution to monitor communications and apply actions like notifying reviewers.

  • Data Lifecycle Management

    Why this is correct

    Data Lifecycle Management provides auto-apply retention label policies that can use sensitive information types (SITs) to classify and retain content automatically. This is the correct solution to apply a retention label based on content detection.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Data Lifecycle ManagementCorrect answer

Why this is correct

Data Lifecycle Management provides auto-apply retention label policies that can use sensitive information types (SITs) to classify and retain content automatically. This is the correct solution to apply a retention label based on content detection.

Communication ComplianceWrong answer — click to see why

Why this is wrong here

Communication Compliance is designed to detect and act on inappropriate or policy-violating communications (e.g., harassment, insider trading), not to apply retention labels based on sensitive content like credit card numbers.

★ When this WOULD be the correct answer

An organization wants to automatically detect and review emails containing confidential financial data (e.g., unreleased earnings reports) sent to external parties, and optionally escalate for legal investigation. Communication Compliance would be the correct solution to monitor communications and apply actions like notifying reviewers.

Why candidates choose this

Candidates may confuse the ability to detect sensitive information in communications with the broader content classification and labeling capabilities of Data Lifecycle Management, assuming any detection of sensitive data can trigger labeling.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.