SC-900 Communication Compliance Practice Question
AdventureWorks, a multinational manufacturing company, uses Microsoft Purview and Microsoft Communication Compliance to monitor and manage internal communications. They need to: (1) detect and review emails containing offensive language or harassment; (2) allow employees to report inappropriate messages; (3) retain reviewed messages for 5 years; (4) ensure that only designated reviewers can access the communication compliance data; (5) integrate with Microsoft Teams and Exchange Online. The company has 10,000 users and Microsoft 365 E5 licenses. The compliance team wants a solution that automates detection and provides secure review. What should they configure?
⚠ Common exam trap
SC-900 often tests the confusion between DLP (data protection for sensitive information types) and Communication Compliance (behavioral/offensive content monitoring) — candidates who see 'policy' and 'review' may incorrectly reach for DLP or eDiscovery instead of the purpose-built Communication Compliance workload.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Communication Compliance policy with conditions for offensive language, enable user reporting, and configure a retention policy for 5 years on the original content locations (e.g., Exchange Online mailboxes, Teams chats, SharePoint sites).
Microsoft Purview Communication Compliance is purpose-built to detect offensive language, harassment, and inappropriate content across Exchange Online, Teams, and other channels, and it natively supports user-reported messages and role-scoped reviewer access. Pairing it with a retention policy applied to the original content locations (Exchange mailboxes, Teams chats, SharePoint) satisfies the 5-year retention requirement while preserving the source data for legal hold and audit. This combination meets all five requirements — detection, user reporting, retention, restricted reviewer access, and Teams/Exchange integration — within the M365 E5 licensing already in place.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Communication Compliance policy with conditions for offensive language, enable user reporting, and configure a retention policy for 5 years on the original content locations (e.g., Exchange Online mailboxes, Teams chats, SharePoint sites).
Why this is correct
A Communication Compliance policy with offensive-language conditions automates detection across Exchange Online and Teams, while user reporting and a five-year retention policy on source locations meet the review, reporting and retention requirements. Role-based access restricts data to designated reviewers, satisfying all five constraints.
- ✗
Enable mailbox auditing and create a custom script to search for offensive language.
Why it's wrong here
Mailbox auditing plus a custom script provides no automated classifier, no reviewer workflow, no employee reporting and no Teams coverage. It is tempting because auditing is the correct choice for investigating a known incident retrospectively, not for proactive detection across Exchange Online and Teams.
- ✗
Create a Data Loss Prevention (DLP) policy to block offensive language and enable eDiscovery for review.
Why it's wrong here
A DLP policy blocks or warns on sensitive data flows; it does not classify harassment, route items to reviewers, or accept employee reports. It is tempting because DLP is the correct choice when the requirement is preventing sensitive information such as card numbers leaving the organisation.
- ✗
Configure information barriers between departments and use audit logs for review.
Why it's wrong here
Information barriers restrict communication between groups; they neither detect offensive language nor give reviewers a case workflow. It is tempting because information barriers are the correct choice when the requirement is preventing specific departments from communicating, rather than monitoring content.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Microsoft Secure Score
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Role
A role is a named set of permissions that can be assigned to users or groups to control access to resources in an IT environment.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.