SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A multinational corporation stores highly sensitive intellectual property in SharePoint Online. To meet regulatory requirements, they need an additional layer of encryption beyond Microsoft's baseline encryption. The company wants to manage their own encryption keys using Azure Key Vault, so that if they remove the key from the service, the data becomes unreadable. Which Microsoft Purview solution should they implement?
⚠ Common exam trap
It's easy for candidates to confuse Customer Key with Double Key Encryption, mistakenly thinking DKE is required for customer-managed keys in Azure Key Vault, when in fact Customer Key is the correct solution for managing encryption keys at rest across Microsoft 365 workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer Key
Customer Key (Option B) is the correct solution because it provides the ability to control and manage the encryption keys used to encrypt data at rest in Microsoft 365, including SharePoint Online. By using Azure Key Vault to store the keys, the organization can revoke access at any time, rendering the data unreadable—a key requirement for meeting regulatory obligations. This goes beyond Microsoft's baseline encryption by adding a customer-controlled layer of encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Double Key Encryption
Why it's wrong here
Double Key Encryption (DKE) is designed for content so highly sensitive that customers require absolute assurance Microsoft cannot access it, even for service operations, by utilising two keys for specific files. However, the scenario describes encrypting *all* highly sensitive intellectual property stored in SharePoint Online with customer-managed keys in Azure Key Vault, such that removing the key renders *all* data unreadable. This points to a service-level encryption solution. DKE would be the correct choice if the requirement was to encrypt *individual, extremely sensitive documents* where Microsoft should never hold a complete key, rather than the entire service data at rest.
When this WOULD be correct
A company needs to ensure that only they can decrypt sensitive data, even if Microsoft's systems are compromised, and they want to hold one of the two encryption keys themselves (not in Azure Key Vault). For example: 'A law firm stores highly confidential client documents in SharePoint Online and requires that no one, including Microsoft, can access the data without the firm's explicit key, which is stored on-premises.'
- ✓
Customer Key
Why this is correct
Correct. Microsoft Purview Customer Key allows customers to provide and manage their own encryption keys using Azure Key Vault, providing an additional layer of encryption on top of the baseline. Data is encrypted using these keys, and the customer can control key access.
- ✗
Information Rights Management
Why it's wrong here
Information Rights Management (IRM) in Microsoft 365 is a feature of Azure Information Protection (AIP) that applies persistent usage policies directly to documents and emails. It restricts actions like copying, printing, or forwarding content, ensuring data remains protected even when shared outside the organization. However, IRM does not provide a mechanism for customers to manage their own encryption keys for data at rest across an entire service like SharePoint Online; it focuses on content usage rights rather than service-level encryption key control.
- ✗
Customer Lockbox
Why it's wrong here
Microsoft Purview Customer Lockbox is a compliance feature designed to give customers explicit control over when Microsoft support engineers can access their data to perform service operations or troubleshoot issues. It establishes an approval workflow, requiring customer consent before any Microsoft personnel can gain temporary, audited access to content. This feature, however, is solely focused on managing access permissions for support staff and does not involve customer-provided or customer-managed encryption keys for data at rest.
When this WOULD be correct
A company needs to ensure that Microsoft support engineers cannot access their data without explicit approval, often for compliance or audit purposes. The question would specify a need for access control during support sessions, not encryption key management.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Customer KeyCorrect answer▾
Why this is correct
Correct. Microsoft Purview Customer Key allows customers to provide and manage their own encryption keys using Azure Key Vault, providing an additional layer of encryption on top of the baseline. Data is encrypted using these keys, and the customer can control key access.
✗Double Key EncryptionWrong answer — click to see why▾
Why this is wrong here
Double Key Encryption (DKE) requires two keys: one managed by Microsoft and one managed by the customer. The question specifies that the company wants to manage their own encryption keys using Azure Key Vault and that removing the key makes data unreadable, which aligns with Customer Key, not DKE. DKE is designed for scenarios where data must be encrypted with a key held outside Microsoft's control, but it does not use Azure Key Vault for the customer key.
★ When this WOULD be the correct answer
A company needs to ensure that only they can decrypt sensitive data, even if Microsoft's systems are compromised, and they want to hold one of the two encryption keys themselves (not in Azure Key Vault). For example: 'A law firm stores highly confidential client documents in SharePoint Online and requires that no one, including Microsoft, can access the data without the firm's explicit key, which is stored on-premises.'
Why candidates choose this
Candidates may confuse Double Key Encryption with Customer Key because both involve customer-managed keys. The term 'double' might suggest an extra layer of encryption, which matches the question's requirement for an additional layer beyond baseline encryption.
✗Customer LockboxWrong answer — click to see why▾
Why this is wrong here
Customer Lockbox provides controlled access for Microsoft engineers to your data during support requests, not an additional layer of encryption where you manage your own keys. It does not make data unreadable if you remove a key.
★ When this WOULD be the correct answer
A company needs to ensure that Microsoft support engineers cannot access their data without explicit approval, often for compliance or audit purposes. The question would specify a need for access control during support sessions, not encryption key management.
Why candidates choose this
Candidates may confuse 'Customer Lockbox' with a customer-managed encryption solution because both involve customer control, but Lockbox controls access, not encryption keys.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.