Courseiva

SC-900 Communication Compliance Practice Question

AdventureWorks, a multinational manufacturing company, uses Microsoft Purview and Microsoft Communication Compliance to monitor and manage internal communications. They need to: (1) detect and review emails containing offensive language or harassment; (2) allow employees to report inappropriate messages; (3) retain reviewed messages for 5 years; (4) ensure that only designated reviewers can access the communication compliance data; (5) integrate with Microsoft Teams and Exchange Online. The company has 10,000 users and Microsoft 365 E5 licenses. The compliance team wants a solution that automates detection and provides secure review. What should they configure?

⚠ Common exam trap

SC-900 often tests the confusion between DLP (data protection for sensitive information types) and Communication Compliance (behavioral/offensive content monitoring) — candidates who see 'policy' and 'review' may incorrectly reach for DLP or eDiscovery instead of the purpose-built Communication Compliance workload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Communication Compliance policy with conditions for offensive language, enable user reporting, and configure a retention policy for 5 years on the original content locations (e.g., Exchange Online mailboxes, Teams chats, SharePoint sites).

Microsoft Purview Communication Compliance is purpose-built to detect offensive language, harassment, and inappropriate content across Exchange Online, Teams, and other channels, and it natively supports user-reported messages and role-scoped reviewer access. Pairing it with a retention policy applied to the original content locations (Exchange mailboxes, Teams chats, SharePoint) satisfies the 5-year retention requirement while preserving the source data for legal hold and audit. This combination meets all five requirements — detection, user reporting, retention, restricted reviewer access, and Teams/Exchange integration — within the M365 E5 licensing already in place.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a Communication Compliance policy with conditions for offensive language, enable user reporting, and configure a retention policy for 5 years on the original content locations (e.g., Exchange Online mailboxes, Teams chats, SharePoint sites).

    Why this is correct

    A Communication Compliance policy with offensive-language conditions automates detection across Exchange Online and Teams, while user reporting and a five-year retention policy on source locations meet the review, reporting and retention requirements. Role-based access restricts data to designated reviewers, satisfying all five constraints.

  • ✗

    Enable mailbox auditing and create a custom script to search for offensive language.

    Why it's wrong here

    Mailbox auditing plus a custom script provides no automated classifier, no reviewer workflow, no employee reporting and no Teams coverage. It is tempting because auditing is the correct choice for investigating a known incident retrospectively, not for proactive detection across Exchange Online and Teams.

  • ✗

    Create a Data Loss Prevention (DLP) policy to block offensive language and enable eDiscovery for review.

    Why it's wrong here

    A DLP policy blocks or warns on sensitive data flows; it does not classify harassment, route items to reviewers, or accept employee reports. It is tempting because DLP is the correct choice when the requirement is preventing sensitive information such as card numbers leaving the organisation.

  • ✗

    Configure information barriers between departments and use audit logs for review.

    Why it's wrong here

    Information barriers restrict communication between groups; they neither detect offensive language nor give reviewers a case workflow. It is tempting because information barriers are the correct choice when the requirement is preventing specific departments from communicating, rather than monitoring content.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.