Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A financial services firm has a strict compliance requirement to prevent insider trading. The firm must ensure that employees in the Investment Banking division cannot communicate or share documents via Microsoft Teams and SharePoint Online with employees in the Equity Research division. The solution must automatically block all communication and collaboration between the two groups, and any attempts to share must be denied. Which Microsoft Purview solution should they implement?

⚠ Common exam trap

A common mix-up: candidates confuse Information Barriers with Communication Compliance, mistakenly thinking that monitoring and reviewing communications (Option B) can prevent insider trading, but only Information Barriers provide the proactive, automatic blocking required by the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Information Barriers

Information Barriers (A) is the correct solution because it is specifically designed to prevent communication and collaboration between defined user groups within Microsoft Teams, SharePoint Online, and other Microsoft 365 services. It enforces policies that automatically block unauthorized communications and document sharing, which directly meets the firm's compliance requirement to segregate Investment Banking and Equity Research divisions to prevent insider trading.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Information Barriers

    Why this is correct

    Information Barriers in Microsoft 365 are specifically designed to prevent specific groups of users from communicating or collaborating with each other, fulfilling "ethical wall" requirements. Administrators define policies that segment users and restrict interactions in services like Microsoft Teams, SharePoint, and Exchange Online. This directly addresses the firm's need to proactively block communication to ensure compliance and prevent information leakage between sensitive departments.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance is a reactive tool designed to help organizations detect, capture, and review inappropriate messages or policy violations within communications. While it can identify instances where users shouldn't have communicated, it does not proactively prevent or block communication channels between specific user segments. Its primary function is auditing and investigation, not enforcing communication "ethical walls."

    When this WOULD be correct

    A company wants to monitor employee communications for potential insider trading or regulatory breaches, and requires a solution that captures, reviews, and escalates suspicious messages or documents. The goal is detection and investigation, not automatic blocking.

  • Insider Risk Management

    Why it's wrong here

    Insider Risk Management focuses on identifying, triaging, and acting on potential malicious or inadvertent insider activities that could pose a risk to an organization. It leverages behavioral analytics and data signals to detect suspicious patterns, such as data exfiltration or policy violations. However, this solution is designed for detection and investigation of risk, not for establishing preventative communication barriers between defined user groups.

    When this WOULD be correct

    An organization wants to detect and investigate suspicious user activities that could lead to insider trading, such as unusual data access or exfiltration, and apply automated remediation actions like triggering alerts or initiating investigations.

  • Sensitivity Labels

    Why it's wrong here

    Sensitivity Labels are used to classify and protect data by applying encryption, watermarks, or access restrictions to specific documents and emails. While they help control who can access specific content, they do not establish or enforce communication boundaries between distinct user groups or departments. Their function is content-centric protection, not group-centric communication blocking.

    When this WOULD be correct

    A company needs to automatically apply encryption and access restrictions to documents containing financial data shared externally. Sensitivity labels with auto-labeling policies would be the correct solution to protect sensitive data based on content.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Information BarriersCorrect answer

Why this is correct

Information Barriers in Microsoft 365 are specifically designed to prevent specific groups of users from communicating or collaborating with each other, fulfilling "ethical wall" requirements. Administrators define policies that segment users and restrict interactions in services like Microsoft Teams, SharePoint, and Exchange Online. This directly addresses the firm's need to proactively block communication to ensure compliance and prevent information leakage between sensitive departments.

Communication ComplianceWrong answer — click to see why

Why this is wrong here

Communication Compliance is designed to detect and review communications for policy violations (e.g., insider trading), not to automatically block all communication and collaboration between groups. It relies on post-hoc detection and review, not real-time blocking.

★ When this WOULD be the correct answer

A company wants to monitor employee communications for potential insider trading or regulatory breaches, and requires a solution that captures, reviews, and escalates suspicious messages or documents. The goal is detection and investigation, not automatic blocking.

Why candidates choose this

Candidates may confuse the goal of preventing insider trading with the tool that monitors for it, assuming that Communication Compliance can enforce restrictions rather than just detect violations.

Insider Risk ManagementWrong answer — click to see why

Why this is wrong here

Insider Risk Management is designed to detect, investigate, and act on potential insider threats after they occur, not to proactively block all communication and collaboration between groups as required by the compliance policy.

★ When this WOULD be the correct answer

An organization wants to detect and investigate suspicious user activities that could lead to insider trading, such as unusual data access or exfiltration, and apply automated remediation actions like triggering alerts or initiating investigations.

Why candidates choose this

Candidates may confuse the proactive blocking of communications (Information Barriers) with the detection and investigation of risky user behavior (Insider Risk Management), especially since both relate to insider trading scenarios.

Sensitivity LabelsWrong answer — click to see why

Why this is wrong here

Sensitivity labels classify and protect data based on sensitivity, but they do not automatically block all communication and collaboration between specific groups. They require manual application or automated labeling policies, and cannot enforce communication restrictions between divisions.

★ When this WOULD be the correct answer

A company needs to automatically apply encryption and access restrictions to documents containing financial data shared externally. Sensitivity labels with auto-labeling policies would be the correct solution to protect sensitive data based on content.

Why candidates choose this

Candidates may think sensitivity labels can restrict sharing between groups because labels can enforce encryption and permissions, but they lack the ability to block communications and are not designed for organizational segmentation.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.