SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A multinational corporation must comply with GDPR and requires that personal data of EU users be retained for a maximum of 90 days after account closure. After that, all personal data must be permanently deleted. Which combination of Microsoft Purview capabilities should be used?
⚠ Common exam trap
SC-900 often tests the confusion between retention labels and sensitivity labels, and candidates may incorrectly choose sensitivity labels for retention requirements, but retention labels are specifically for retention and deletion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a retention label with a retention period of 90 days and then delete the content automatically
A retention label with a retention period of 90 days and then automatic deletion is the correct combination. Retention labels in Microsoft Purview are designed to manage data lifecycle, including retention and deletion. You can configure a retention label to retain content for a specific period and then delete it automatically, which meets the GDPR requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an eDiscovery case to delete content after 90 days
Why it's wrong here
Configuring an eDiscovery case is designed for identifying, preserving, collecting, and producing electronically stored information (ESI) for legal or investigative purposes. While eDiscovery can place content on legal hold to prevent its deletion, it does not provide functionality to automatically delete content after a specified period. Its primary role is data preservation and investigation, not automated lifecycle management or scheduled content disposal.
- ✓
Create a retention label with a retention period of 90 days and then delete the content automatically
Why this is correct
Creating a retention label with a 90-day retention period is the correct approach for this compliance requirement. Retention labels allow organizations to define how long content should be kept, and critically, what action should occur afterward, including automatic deletion. This ensures that data is retained for the necessary compliance duration and then systematically disposed of, aligning with GDPR's data minimization principles.
- ✗
Apply a sensitivity label that expires after 90 days
Why it's wrong here
Applying a sensitivity label is primarily used for classifying data and applying protective actions like encryption, visual markings, or access restrictions. Sensitivity labels are focused on what the data is and who can access it, along with how it's protected. They do not possess capabilities to manage data lifecycle, such as setting an expiration date or triggering automatic deletion after a specific timeframe.
- ✗
Use a Data Loss Prevention policy to block retention after 90 days
Why it's wrong here
A Data Loss Prevention (DLP) policy is engineered to identify, monitor, and protect sensitive information from being shared inappropriately or leaving the organization's control. DLP policies are focused on preventing data exfiltration or misuse, not on managing the lifecycle of data within the organization's repositories. They do not have features to enforce retention periods or trigger the automatic deletion of content after a set duration.
Go deeper
Related to this question
Learn chapter
Records Management in Microsoft Purview
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Retention label
A retention label is a tag applied to emails, documents, or files in Microsoft 365 that tells the system how long to keep the item and what to do with it when the time is up.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.