Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A user reports that a sensitive document labeled 'Highly Confidential' was accidentally shared with an external vendor. You need to investigate how the sharing occurred. Which two Microsoft Purview tools should you use together?

⚠ Common exam trap

Many candidates confuse 'investigating how sharing occurred' with 'preventing sharing' (DLP) or 'monitoring communications' (Communication Compliance), but the question specifically asks for forensic investigation tools, which require an audit trail and content visibility.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Audit (Standard) and Content Explorer

Audit (Standard) logs all user activities, including sharing events, while Content Explorer shows where sensitive documents with specific sensitivity labels (like 'Highly Confidential') are stored and who has accessed them. Together, they allow you to trace the exact sharing action and identify the document's location and exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Audit (Standard) and Content Explorer

    Why this is correct

    Audit (Standard) logs all user and admin activities across Microsoft 365 services, including file sharing events, access, and modifications, providing a historical record of who shared the document and when. Content Explorer, part of Microsoft Purview data classification, allows security administrators to visualize and locate sensitive information across SharePoint, OneDrive, and Exchange, showing the document's current location, sensitivity labels, and other metadata, which helps confirm its status and context post-sharing.

  • Insider Risk Management and Information Barriers

    Why it's wrong here

    Insider Risk Management proactively identifies and mitigates potential insider risks by analyzing user activities for unusual or suspicious patterns that might indicate data exfiltration or policy violations, but it's not designed for a direct, retrospective investigation of a single, known sharing incident. Information Barriers enforce policies to prevent specific groups of users from communicating or sharing data with other designated groups, acting as a preventative control rather than an investigative tool for a past event.

  • eDiscovery (Premium) and Communication Compliance

    Why it's wrong here

    eDiscovery (Premium) is primarily used for legal and regulatory investigations, allowing organizations to search, preserve, collect, review, and export content from Microsoft 365 mailboxes, sites, and documents, typically in response to litigation or regulatory requests, not for a direct security incident investigation of a specific sharing event. Communication Compliance monitors user communications within Microsoft Teams, Exchange, and Yammer for policy violations, such as harassment or sensitive data sharing within messages, but it does not directly track or provide details on document sharing events themselves.

  • Data Loss Prevention and Sensitivity labels

    Why it's wrong here

    Data Loss Prevention (DLP) policies are designed to prevent sensitive information from leaving the organization or being shared inappropriately by detecting and blocking such actions in real-time or near real-time, acting as a preventative measure. Sensitivity labels classify and protect data by applying encryption, visual markings, and access restrictions, but they are classification and protection mechanisms, not investigative tools that can retrospectively show who shared a specific document or when.

  • Records Management and Data Lifecycle Management

    Why it's wrong here

    Records Management focuses on managing the lifecycle of records, ensuring they are retained for specific periods to meet legal, regulatory, or business requirements, and then disposed of appropriately. Data Lifecycle Management (DLM) is a broader strategy encompassing data creation, storage, usage, archiving, and deletion, primarily concerned with data retention and disposition policies. Neither of these services provides the specific audit trails or content exploration capabilities needed to investigate a past incident of a sensitive document being shared.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.