SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A multinational corporation must comply with regulations that require them to keep financial records for 7 years and then permanently delete them. However, they are currently involved in litigation that requires preservation of all documents related to a specific project. They use Microsoft Purview. Which combination of features should they use to meet both requirements?
⚠ Common exam trap
Test-takers frequently confuse Sensitivity labels (which mark or protect data) with retention labels (which enforce lifecycle policies), or assume eDiscovery alone can handle both retention and hold, missing the need for DLM to define the deletion schedule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Lifecycle Management to retain for 7 years then delete, and eDiscovery (Premium) to place a legal hold on the project documents
Data Lifecycle Management (DLM) allows you to create retention labels that enforce a 7-year retention period followed by automatic deletion, satisfying the regulatory requirement. eDiscovery (Premium) provides the ability to place a legal hold on specific documents, which overrides the deletion policy to preserve data relevant to ongoing litigation. This combination ensures both compliance with the retention/deletion mandate and the preservation obligation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Lifecycle Management to retain for 7 years then delete, and eDiscovery (Premium) to place a legal hold on the project documents
Why this is correct
Data Lifecycle Management (DLM) effectively establishes a baseline retention policy to retain data for seven years and then automatically delete it, ensuring general compliance with record-keeping regulations. Concurrently, eDiscovery (Premium) allows for the precise application of a legal hold on specific project documents, which critically overrides any deletion policy, including the DLM policy, to preserve evidence for potential litigation. This combination ensures both routine data governance and specific, immutable preservation for legal requirements.
- ✗
Data Lifecycle Management to retain for 7 years then delete, and Sensitivity labels to mark documents
Why it's wrong here
While Data Lifecycle Management correctly implements the seven-year retention and deletion policy, the addition of Sensitivity labels primarily serves to classify and apply protective actions like encryption or access restrictions to documents. Sensitivity labels are not designed to provide a legal hold capability, nor do they possess the authority to override an existing deletion policy to preserve content for legal discovery, making them unsuitable for the preservation requirement.
- ✗
Audit (Premium) to log access and eDiscovery (Premium) to search
Why it's wrong here
Audit (Premium) is instrumental for logging user and admin activities, providing an immutable record of who accessed what and when, which is valuable for forensic analysis and compliance reporting. Similarly, eDiscovery (Premium) search capabilities are essential for efficiently locating relevant data across the organization. However, neither auditing nor searching inherently places a legal hold on content, meaning they do not prevent the deletion of documents that are subject to a retention policy or user action, failing the preservation requirement.
- ✗
Information Protection to classify data and Data Lifecycle Management to retain
Why it's wrong here
Information Protection, primarily through sensitivity labels, enables organizations to classify data based on its sensitivity and apply corresponding protective measures, such as visual markings or encryption. While Data Lifecycle Management can establish a retention period, Information Protection itself does not provide the legal hold functionality necessary to override a scheduled deletion or user-initiated deletion for specific documents required for litigation. Therefore, critical project documents could still be inadvertently deleted without a proper legal hold.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.