Question 1,283 of 1,411

Quick Answer

The answer is Microsoft Purview Insider Risk Management. This solution is correct because it uses heuristics and behavioral analytics to detect risky user actions, such as data exfiltration to personal cloud storage, by correlating signals from Microsoft 365 and Azure services to identify patterns indicative of insider data theft. On the SC-900 exam, this question tests your understanding of how Purview solutions map to specific security scenarios, often appearing as a scenario-based multiple-choice question where you must distinguish Insider Risk Management from other tools like Data Loss Prevention or Audit. A common trap is confusing it with Purview eDiscovery, which focuses on legal holds and searches rather than behavioral detection. Remember the memory tip: “Insider Risk = Behavioral Analytics + Heuristics” — if the scenario mentions unusual patterns or risk scoring, think of this solution first.

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

This SC-900 practice question tests your understanding of describe the capabilities of microsoft compliance solutions. Match the stated requirement to the specific cloud service, access model, or configuration option — many options are valid in isolation but not for this scenario. After answering, compare your reasoning against the explanation and wrong-answer breakdown below. Once you have made your selection, read the full explanation to reinforce the concept and understand why each distractor is designed to mislead on exam day.

A company's security team needs to detect and investigate potential data theft by employees who have legitimate access to sensitive data. They want a solution that uses heuristics and behavioral analytics to identify risky user actions such as data exfiltration to personal cloud storage. Which Microsoft Purview solution should they use?

Question 1hardmultiple choice
Full question →

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Insider Risk Management

Microsoft Purview Insider Risk Management is the correct solution because it is specifically designed to detect, investigate, and act on risky user activities that may lead to data theft, using heuristics and behavioral analytics. It correlates signals from Microsoft 365 and Azure services to identify patterns like data exfiltration to personal cloud storage, which aligns directly with the scenario's requirements.

Key principle: Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Data Loss Prevention (DLP)

    Why it's wrong here

    DLP policies can automatically block or warn users from sharing sensitive data, but they do not use behavioral analytics to proactively detect potential data theft; they are rule-based prevention mechanisms.

  • Microsoft Purview Insider Risk Management

    Why this is correct

    Correct. Insider Risk Management uses built-in risk indicators and machine learning to identify activities that may pose insider risks, enabling investigation and response to incidents like data theft.

    Related concept

    Read the scenario before looking for a memorised answer.

  • Microsoft Purview Audit (Standard)

    Why it's wrong here

    Audit (Standard) records user and admin activities for investigation and compliance purposes, but it does not include automated detection or behavioral analytics to identify risky patterns.

  • Microsoft Purview Information Barriers

    Why it's wrong here

    Information Barriers prevent communication and collaboration between specific groups via Teams, SharePoint, and email, but they do not detect data theft or use behavioral analytics.

Common exam traps

Common exam trap: answer the scenario, not the keyword

The trap here is that candidates often confuse the reactive, policy-based enforcement of Data Loss Prevention (DLP) with the proactive, behavioral detection of Insider Risk Management, assuming DLP can detect risky user actions when it actually only blocks or alerts on content matching static rules.

Detailed technical explanation

How to think about this question

Insider Risk Management uses machine learning models to baseline normal user behavior and then detects anomalies such as unusual file downloads, email forwarding to personal accounts, or access to sensitive data outside business hours. It integrates with Microsoft Defender for Cloud Apps to monitor shadow IT usage, including uploads to personal cloud storage services like Dropbox or Google Drive, and provides a built-in case management workflow for investigation. The solution leverages telemetry from Microsoft 365 audit logs, Azure Active Directory sign-in logs, and endpoint signals to create risk scores that trigger alerts for security teams.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.

TExam Day Tips

  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Key takeaway

Answer the scenario, not the keyword: identify the specific constraint before choosing the most familiar-sounding option.

Real-world example

How this comes up in practice

A media company stores terabytes of video archives that are accessed once a year for audit purposes. Moving these objects to a cold storage tier (Azure Archive, S3 Glacier, or Google Nearline) costs a fraction of hot storage. Questions like this test whether you understand storage tiers, access frequency tradeoffs, and retrieval latency requirements.

What to study next

Got this wrong? Here's your next step.

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

Related practice questions

Related SC-900 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

Practice this exam

Start a free SC-900 practice session

Short sessions build daily habit. Longer sessions build exam-day stamina. Try a timed session to simulate real conditions.

FAQ

Questions learners often ask

What does this SC-900 question test?

Describe the capabilities of Microsoft compliance solutions — This question tests Describe the capabilities of Microsoft compliance solutions — Read the scenario before looking for a memorised answer..

What is the correct answer to this question?

The correct answer is: Microsoft Purview Insider Risk Management — Microsoft Purview Insider Risk Management is the correct solution because it is specifically designed to detect, investigate, and act on risky user activities that may lead to data theft, using heuristics and behavioral analytics. It correlates signals from Microsoft 365 and Azure services to identify patterns like data exfiltration to personal cloud storage, which aligns directly with the scenario's requirements.

What should I do if I get this SC-900 question wrong?

Identify which exam domain this question belongs to, review the core concept, then practise similar questions from the same domain.

What is the key concept behind this question?

Read the scenario before looking for a memorised answer.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more ways this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to proactively detect and investigate potential insider security risks, such as a departing employee copying large amounts of data to a personal USB drive or sharing confidential files with unauthorized individuals. Which Microsoft Purview solution should they use?

hard
  • A.Data Lifecycle Management
  • B.Insider Risk Management
  • C.Communication Compliance
  • D.eDiscovery (Standard)

Why B: Insider Risk Management in Microsoft Purview is specifically designed to detect, investigate, and act on risky user activities that may lead to data security incidents, such as unauthorized data exfiltration by departing employees. It uses predefined and customizable policies to correlate signals from Microsoft 365 logs (e.g., copying files to USB, sharing with external users) and applies risk-scoring to prioritize alerts. This makes it the correct solution for proactively identifying potential insider threats like bulk data copying or unauthorized file sharing.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.