SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A healthcare organization must demonstrate compliance with HIPAA by assessing their current posture against regulatory controls, tracking improvement actions, and generating reports for auditors. Which Microsoft Purview solution should they use?
⚠ Common exam trap
A common mix-up: candidates confuse Compliance Manager (which assesses and tracks compliance posture) with Information Protection (which protects data) or Insider Risk Management (which detects risky behavior), because all three are Purview solutions but serve fundamentally different compliance lifecycle stages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager is the correct solution because it provides a built-in assessment template for HIPAA, enabling the organization to assess its current compliance posture against regulatory controls, track improvement actions, and generate auditor-ready reports. It offers a compliance score, automated control mapping, and evidence collection workflows specifically designed for regulatory frameworks like HIPAA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Information Protection
Why it's wrong here
Microsoft Purview Information Protection is fundamentally designed for classifying, labeling, and protecting sensitive data throughout its lifecycle, employing encryption and access controls to prevent unauthorized disclosure. While crucial for safeguarding data that falls under regulatory scrutiny, it does not provide the overarching framework for assessing an organization's adherence to specific regulatory standards or generating comprehensive compliance reports. Its focus is on data-centric security rather than holistic compliance posture management.
- ✗
Microsoft Purview Data Lifecycle Management
Why it's wrong here
Microsoft Purview Data Lifecycle Management is engineered to manage the retention and deletion of data, ensuring that information is kept for legally or operationally required periods and then defensibly disposed of. While essential for meeting the data retention requirements of various regulations, this solution does not offer pre-built regulatory templates, track the implementation status of controls, or provide a consolidated view of an organization's compliance against a specific standard like HIPAA. Its scope is limited to data retention policies, not comprehensive compliance assessments.
- ✓
Microsoft Purview Compliance Manager
Why this is correct
Microsoft Purview Compliance Manager is the dedicated solution for simplifying compliance and reducing risk by providing pre-built assessments for common industry regulations, such as HIPAA. It allows organizations to track progress on improvement actions, assign responsibilities, and generate detailed compliance reports, offering a measurable compliance score. This service directly addresses the need to demonstrate and manage an organization's adherence to regulatory requirements through a structured workflow.
- ✗
Microsoft Purview Insider Risk Management
Why it's wrong here
Microsoft Purview Insider Risk Management is specifically engineered to detect, investigate, and act on potentially risky activities by internal users, whether malicious or inadvertent, that could lead to data leakage or policy violations. While mitigating insider risks contributes to an organization's overall security posture, it does not provide the capabilities to map controls to regulatory frameworks, track assessment progress, or generate compliance scores against external standards. Its primary function is behavioral analytics and risk mitigation, not regulatory compliance assessment.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.