Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A financial services firm is required by regulatory bodies to monitor employee communications (email, Teams chats) for potential insider trading or market manipulation. They need a solution that allows them to define policies to detect messages containing specific keywords or phrases (e.g., 'confidential', 'insider info'), and then assign flagged messages to designated reviewers for investigation. Which Microsoft Purview solution should they use?

⚠ Common exam trap

Many exam-takers confuse Insider Risk Management (which focuses on behavioral analytics and user risk scores) with Communication Compliance (which directly scans communication content for specific text patterns), leading candidates to choose the wrong solution for keyword-based message monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Communication Compliance

Microsoft Purview Communication Compliance is the correct solution because it is specifically designed to detect policy violations in employee communications, such as email and Teams chats, by scanning for sensitive keywords or phrases like 'confidential' or 'insider info'. It then automatically flags and routes these messages to designated reviewers for investigation, directly meeting the regulatory requirement for monitoring potential insider trading or market manipulation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Communication Compliance

    Why this is correct

    Microsoft Purview Communication Compliance is specifically designed to help organizations detect and remediate regulatory compliance violations, such as insider trading, harassment, or sensitive data sharing, within their internal and external communications. It uses intelligent templates and customizable policies to proactively scan messages across Microsoft 365 services for specific keywords, sensitive information types, or patterns indicative of policy breaches. Compliance officers can then review, investigate, and take action on identified risky communications through a dedicated workflow.

  • Microsoft Purview Insider Risk Management

    Why it's wrong here

    Microsoft Purview Insider Risk Management focuses on identifying and mitigating risks from within an organization, such as data theft or intellectual property leakage, by analyzing user *behavior* and *data activities*. It correlates signals from various sources like file access, email patterns, and device usage to detect risky sequences of actions, rather than directly scanning the content of individual communications for specific keywords or phrases. Its primary goal is to identify potential malicious or inadvertent insider threats based on user actions, not content.

    When this WOULD be correct

    A scenario where an organization needs to identify and investigate users who are exfiltrating sensitive data (e.g., copying files to USB drives, emailing to personal accounts) or violating security policies based on user behavior patterns, rather than monitoring communications for specific keywords.

  • Microsoft Purview eDiscovery (Standard or Premium)

    Why it's wrong here

    Microsoft Purview eDiscovery (Standard or Premium) is a reactive tool primarily used for legal and investigative purposes, enabling organizations to search, preserve, collect, and export electronic content in response to litigation or regulatory requests. While it can access communication data, its function is to identify and gather existing information for review, not to proactively monitor live communications for policy violations or to enforce communication compliance policies in real-time. It does not provide automated detection or a workflow for ongoing communication content review.

    When this WOULD be correct

    A law firm needs to search and export all emails and chats related to a specific client matter for a court case. They require advanced search capabilities, hold management, and review sets. In this scenario, Microsoft Purview eDiscovery (Standard or Premium) would be the correct solution.

  • Microsoft Purview Audit (Standard or Premium)

    Why it's wrong here

    Microsoft Purview Audit (Standard or Premium) records user and administrator activities across Microsoft 365 services, providing a forensic trail of events for security, compliance, and investigative purposes. It logs *who* did *what*, *when*, and *where*, such as file access, mailbox operations, or policy changes. However, Audit logs do not perform content inspection of communications for specific keywords or policy violations, nor do they offer proactive detection or a review workflow for inappropriate messages.

    When this WOULD be correct

    An organization needs to investigate a specific security incident and must search through historical audit logs to identify which users accessed sensitive files or performed specific actions. They require detailed logging of user and admin activities for forensic analysis and compliance reporting. In this scenario, Microsoft Purview Audit (Standard or Premium) would be the correct solution.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Purview Communication ComplianceCorrect answer

Why this is correct

Microsoft Purview Communication Compliance is specifically designed to help organizations detect and remediate regulatory compliance violations, such as insider trading, harassment, or sensitive data sharing, within their internal and external communications. It uses intelligent templates and customizable policies to proactively scan messages across Microsoft 365 services for specific keywords, sensitive information types, or patterns indicative of policy breaches. Compliance officers can then review, investigate, and take action on identified risky communications through a dedicated workflow.

Microsoft Purview Insider Risk ManagementWrong answer — click to see why

Why this is wrong here

Insider Risk Management focuses on detecting and investigating risky user activities (e.g., data exfiltration, policy violations) based on behavioral analytics, not on monitoring communications for specific keywords or phrases. The question explicitly requires keyword-based policy detection in messages, which is a core feature of Communication Compliance.

★ When this WOULD be the correct answer

A scenario where an organization needs to identify and investigate users who are exfiltrating sensitive data (e.g., copying files to USB drives, emailing to personal accounts) or violating security policies based on user behavior patterns, rather than monitoring communications for specific keywords.

Why candidates choose this

Candidates may confuse 'insider risk' with 'communication compliance' because both deal with insider threats, but they overlook that the question specifically mentions keyword-based policy detection in communications, which is unique to Communication Compliance.

Microsoft Purview eDiscovery (Standard or Premium)Wrong answer — click to see why

Why this is wrong here

eDiscovery is designed for legal discovery and investigation of existing data, not for real-time policy-based detection and automated assignment of flagged messages to reviewers. The question requires proactive monitoring and policy enforcement, which is the domain of Communication Compliance.

★ When this WOULD be the correct answer

A law firm needs to search and export all emails and chats related to a specific client matter for a court case. They require advanced search capabilities, hold management, and review sets. In this scenario, Microsoft Purview eDiscovery (Standard or Premium) would be the correct solution.

Why candidates choose this

Candidates may confuse the investigative and review capabilities of eDiscovery with the policy-based detection and review workflow of Communication Compliance, as both involve reviewing communications.

Microsoft Purview Audit (Standard or Premium)Wrong answer — click to see why

Why this is wrong here

Microsoft Purview Audit (Standard or Premium) provides logging and investigation of user and admin activity, but it does not include policy-based detection of keywords/phrases in communications or assignment to reviewers for investigation. The question specifically requires monitoring communications for keywords and assigning flagged messages to reviewers, which is not an Audit capability.

★ When this WOULD be the correct answer

An organization needs to investigate a specific security incident and must search through historical audit logs to identify which users accessed sensitive files or performed specific actions. They require detailed logging of user and admin activities for forensic analysis and compliance reporting. In this scenario, Microsoft Purview Audit (Standard or Premium) would be the correct solution.

Why candidates choose this

Candidates may confuse Audit with Communication Compliance because both involve monitoring and compliance. They might think that auditing communications is part of Audit, but Audit focuses on activity logs (e.g., who accessed what), not on scanning message content for keywords and routing to reviewers.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.