Microsoft Purview Compliance Manager for GDPR and ISO 27001
A multinational organization uses Microsoft 365 and must demonstrate compliance with both GDPR and ISO 27001. The compliance team needs a centralized tool to assess their current compliance posture against these frameworks, receive prioritized improvement actions, and track the implementation of those actions over time. Which Microsoft Purview solution should they use?
Quick Answer
The answer is Compliance Manager. This is the correct choice because it serves as a centralized tool within Microsoft Purview that assesses an organization’s compliance posture against frameworks like GDPR and ISO 27001, providing a built-in assessment with prioritized improvement actions and tracking their implementation over time. On the SC-900 exam, this question tests your understanding of how Compliance Manager differs from other Purview solutions such as Data Loss Prevention or eDiscovery, which focus on data protection or legal holds rather than framework-based compliance scoring. A common trap is confusing Compliance Manager with the Compliance Center or Service Trust Portal, but remember that only Compliance Manager offers the full lifecycle of assessment, action, and tracking. A useful memory tip is to think of the three A’s: Assess, Act, and Audit—Compliance Manager handles all three for GDPR and ISO 27001.
⚠ Common exam trap
It's easy for candidates to confuse Audit or Data Lifecycle Management as compliance tools, but they lack the centralized assessment and action tracking capabilities that Compliance Manager uniquely provides for framework-specific compliance management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance Manager
Compliance Manager is the correct solution because it provides a centralized dashboard that assesses an organization's compliance posture against frameworks like GDPR and ISO 27001. It offers prioritized improvement actions based on built-in assessments and tracks the implementation of those actions over time, directly meeting the requirements for a unified compliance management tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compliance Manager
Why this is correct
Compliance Manager provides a central dashboard to assess compliance posture, manage improvement actions, and track progress against multiple regulations like GDPR and ISO 27001.
- ✗
Data Lifecycle Management
Why it's wrong here
Data Lifecycle Management focuses on retaining and deleting content based on policies, not on assessing compliance posture or tracking improvement actions against regulations.
When this WOULD be correct
A question asking which Microsoft Purview solution to use for automatically retaining or deleting data based on regulatory requirements (e.g., GDPR data retention) would make Data Lifecycle Management the correct answer.
- ✗
Audit
Why it's wrong here
Microsoft Purview Audit logs user and admin activities but does not assess compliance posture or provide improvement actions for regulatory frameworks.
When this WOULD be correct
A question asking which Microsoft Purview solution allows an organization to search and export user and admin activity logs to investigate a security incident or perform forensic analysis would have Audit as the correct answer.
- ✗
eDiscovery
Why it's wrong here
eDiscovery is used to search, hold, and export content for legal investigations, not for continuous compliance assessment against regulations.
When this WOULD be correct
A legal team needs to identify and preserve all emails and documents related to a pending lawsuit across Microsoft 365. They require a tool to search, hold, and export relevant data for litigation purposes.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓Compliance ManagerCorrect answer▾
Why this is correct
Compliance Manager provides a central dashboard to assess compliance posture, manage improvement actions, and track progress against multiple regulations like GDPR and ISO 27001.
✗Data Lifecycle ManagementWrong answer — click to see why▾
Why this is wrong here
Data Lifecycle Management focuses on governing data retention and deletion policies, not on assessing compliance posture against frameworks like GDPR and ISO 27001 or tracking improvement actions.
★ When this WOULD be the correct answer
A question asking which Microsoft Purview solution to use for automatically retaining or deleting data based on regulatory requirements (e.g., GDPR data retention) would make Data Lifecycle Management the correct answer.
Why candidates choose this
Candidates may confuse managing data lifecycle with managing compliance, as both involve regulatory requirements, but Data Lifecycle Management does not provide assessment or action tracking.
✗AuditWrong answer — click to see why▾
Why this is wrong here
Audit is used for investigating specific security or compliance events by searching the unified audit log, not for assessing compliance posture against frameworks like GDPR and ISO 27001 or tracking improvement actions.
★ When this WOULD be the correct answer
A question asking which Microsoft Purview solution allows an organization to search and export user and admin activity logs to investigate a security incident or perform forensic analysis would have Audit as the correct answer.
Why candidates choose this
Candidates may confuse Audit with Compliance Manager because both are compliance-related, and they might think auditing is sufficient for compliance assessment without understanding the distinct capabilities of each solution.
✗eDiscoveryWrong answer — click to see why▾
Why this is wrong here
eDiscovery is used for identifying and preserving electronic content for legal cases, not for assessing compliance posture against frameworks like GDPR and ISO 27001 or tracking improvement actions.
★ When this WOULD be the correct answer
A legal team needs to identify and preserve all emails and documents related to a pending lawsuit across Microsoft 365. They require a tool to search, hold, and export relevant data for litigation purposes.
Why candidates choose this
Candidates may confuse eDiscovery with compliance because both involve data management and regulatory requirements, but eDiscovery focuses on litigation, not continuous compliance assessment.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Compliance Manager
A Compliance Manager is a tool or service that helps organizations assess, monitor, and improve their adherence to regulatory standards, industry frameworks, and internal policies.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are features of Microsoft Purview Compliance Manager? (Select THREE.)
hard- A.Record declaration and disposition reviews
- ✓ B.Compliance score and templates for custom assessments
- ✓ C.Pre-built assessments for common regulations like GDPR
- D.Trainable classifiers to identify sensitive content
- ✓ E.Microsoft-managed improvement actions for regulations
Why B: Microsoft Purview Compliance Manager provides a **compliance score** that quantifies an organization's compliance posture and includes **templates for custom assessments** tailored to specific regulatory or organizational requirements (Option B). It also offers a library of **pre-built assessments** for common regulations like GDPR (Option C). Additionally, it details **improvement actions**, including those that are **Microsoft-managed**, to help organizations meet regulatory requirements (Option E).
Variation 2. Which THREE of the following are features of Microsoft Purview Compliance Manager?
hard- A.Data Loss Prevention policies
- ✓ B.Improvement actions with assigned owners
- C.Audit log search
- ✓ D.Compliance score
- ✓ E.Pre-built assessments for regulations like GDPR
Why B: Microsoft Purview Compliance Manager is a workflow-based solution that helps you manage your organization's compliance posture. Key features include: * **Compliance Score**: Provides a measurable score of your compliance posture, helping you understand your progress and prioritize actions. * **Pre-built assessments**: Offers templates for various regulations and industry standards (e.g., GDPR, ISO 27001, NIST) to help you assess your compliance against specific requirements. * **Improvement actions**: Provides step-by-step guidance for implementing controls that enhance your compliance posture. Each improvement action can be assigned to a specific owner within your organization, enabling accountability and tracking of remediation tasks.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.