Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A healthcare organization must comply with HIPAA regulations. They store patient health information (PHI) in SharePoint Online documents. The compliance team needs to automatically detect PHI (e.g., medical record numbers) in documents, apply a sensitivity label that encrypts the document, and prevent users from removing that label. Which Microsoft Purview solution should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse Microsoft Purview Information Protection (which handles labeling and encryption) with Microsoft Purview Data Lifecycle Management (which handles retention and deletion), because both involve document policies, but only Information Protection can detect PHI and enforce encryption labels.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Information Protection

Microsoft Purview Information Protection (option B) is correct because it provides the ability to automatically detect sensitive data types (such as PHI) using trainable classifiers or sensitive information types, apply a sensitivity label that enforces encryption, and configure label protection settings to prevent users from removing the label. This directly meets the HIPAA compliance requirement for automated detection, encryption, and label persistence on SharePoint Online documents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Data Lifecycle Management

    Why it's wrong here

    Microsoft Purview Data Lifecycle Management focuses on managing the retention and deletion of data to meet regulatory, legal, and business requirements over its lifespan. While crucial for ensuring data is kept for the appropriate duration and then securely disposed of, it does not provide mechanisms for identifying sensitive data types like PHI, applying protective labels, or encrypting content to prevent unauthorized access. Its primary function is data governance related to storage duration, not proactive content protection.

    When this WOULD be correct

    An organization needs to automatically retain SharePoint documents containing PHI for 6 years and then delete them to comply with HIPAA data retention policies.

  • Microsoft Purview Information Protection

    Why this is correct

    Microsoft Purview Information Protection is the correct choice because it directly addresses the need to classify, label, and protect sensitive data like Protected Health Information (PHI) required by HIPAA. It enables the creation and automatic application of sensitivity labels based on identified sensitive information types, such as medical record numbers or health insurance information. These labels can enforce encryption, visual markings, and access restrictions, ensuring PHI remains secure and preventing unauthorized disclosure or removal, thereby meeting HIPAA's confidentiality and integrity requirements.

  • Microsoft Purview Communication Compliance

    Why it's wrong here

    Microsoft Purview Communication Compliance is designed to help organizations detect, investigate, and remediate policy violations in internal and external communications, such as identifying harassment, insider trading, or sharing of sensitive information via chat or email. While it can identify sensitive information *within* communications, its purpose is not to classify, label, or encrypt *stored documents* or files to prevent unauthorized access. It focuses on monitoring user interactions rather than securing data at rest.

    When this WOULD be correct

    A question where an organization needs to monitor employee communications for inappropriate sharing of sensitive information (e.g., PHI sent via email) and enforce compliance policies on those communications would make Communication Compliance the correct answer.

  • Microsoft Purview Audit

    Why it's wrong here

    Microsoft Purview Audit provides a unified logging solution that records user and administrator activities across various Microsoft 365 services. While essential for forensic investigations, compliance reporting, and detecting potential policy violations after they occur, it does not offer capabilities for automatic data classification, applying sensitivity labels, or encrypting data at rest or in transit. Therefore, it cannot proactively protect Protected Health Information (PHI) to meet HIPAA's core data protection mandates.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Microsoft Purview Information ProtectionCorrect answer

Why this is correct

Microsoft Purview Information Protection is the correct choice because it directly addresses the need to classify, label, and protect sensitive data like Protected Health Information (PHI) required by HIPAA. It enables the creation and automatic application of sensitivity labels based on identified sensitive information types, such as medical record numbers or health insurance information. These labels can enforce encryption, visual markings, and access restrictions, ensuring PHI remains secure and preventing unauthorized disclosure or removal, thereby meeting HIPAA's confidentiality and integrity requirements.

Microsoft Purview Data Lifecycle ManagementWrong answer — click to see why

Why this is wrong here

Data Lifecycle Management manages retention and deletion of data, not automatic detection of PHI or application of encryption labels.

★ When this WOULD be the correct answer

An organization needs to automatically retain SharePoint documents containing PHI for 6 years and then delete them to comply with HIPAA data retention policies.

Why candidates choose this

Candidates may confuse lifecycle management with the broader set of compliance controls needed for HIPAA, assuming it covers all data governance tasks.

Microsoft Purview Communication ComplianceWrong answer — click to see why

Why this is wrong here

Microsoft Purview Communication Compliance is designed to detect policy violations in communications like email and Teams, not to automatically detect PHI in documents and apply sensitivity labels. It lacks the ability to classify and protect content in SharePoint Online documents.

★ When this WOULD be the correct answer

A question where an organization needs to monitor employee communications for inappropriate sharing of sensitive information (e.g., PHI sent via email) and enforce compliance policies on those communications would make Communication Compliance the correct answer.

Why candidates choose this

Candidates may confuse 'compliance' with data protection and think Communication Compliance can handle document classification, or they may mistakenly believe it includes automated labeling capabilities for content in SharePoint.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.