SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A user accidentally shared a confidential document with an external vendor. You need to revoke access immediately for all copies, even if the file has been downloaded. Which Microsoft Purview feature should you use?
⚠ Common exam trap
Many exam-takers confuse Data Loss Prevention (DLP) policies with Information Protection, assuming DLP can retroactively block access to already-exposed data, when in fact DLP only prevents future sharing and does not revoke access to files already in the wild.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Information Protection
Microsoft Purview Information Protection (formerly Azure Information Protection) allows you to classify, label, and protect documents and emails. When a confidential document is shared accidentally, you can use the 'Revoke Access' action on the protected file via the Microsoft Purview compliance portal or PowerShell. This revokes access for all copies, even if the file has been downloaded, because the protection travels with the file through persistent rights management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Information Protection
Why this is correct
Microsoft Purview Information Protection (MPIP) provides persistent data protection by allowing organizations to classify, label, and encrypt sensitive documents. Crucially, even after a document protected with MPIP is shared, the data owner or administrator retains the ability to revoke access at any time, regardless of the document's location. This capability directly addresses the scenario of accidental oversharing by enabling immediate remediation.
- ✗
Retention policy
Why it's wrong here
A retention policy in Microsoft Purview is designed to manage the lifecycle of data, ensuring it is either preserved for compliance or deleted after a specified period. Its primary function is data governance related to storage and disposal, not real-time access control. Therefore, a retention policy cannot be used to revoke access to a document that has already been inadvertently shared with an external party.
- ✗
Data loss prevention (DLP) policy
Why it's wrong here
Data Loss Prevention (DLP) policies are configured to identify, monitor, and prevent sensitive information from being shared inappropriately *before* it leaves the organizational boundary. While a DLP policy could have potentially blocked the initial accidental sharing event, it does not possess the functionality to retroactively revoke access to a document that has already been successfully transmitted or shared with an unauthorized external recipient.
- ✗
Audit log search
Why it's wrong here
An audit log search in Microsoft Purview is a diagnostic tool used to track and report on user and administrator activities across various Microsoft 365 services. While it can provide valuable information about *who* shared a document and *when*, it is purely a logging and investigative mechanism. It does not offer any direct capability to enforce security actions, such as revoking access to an already shared confidential document.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.