Courseiva

Microsoft Purview Solutions for Compliance Requirements

You are the compliance administrator for Contoso, a multinational corporation with headquarters in the US and subsidiaries in Europe and Asia. Contoso uses Microsoft 365 E5 and Microsoft Purview. The company handles personal data subject to GDPR and CCPA. You need to design a compliance solution that meets the following requirements: - Automatically classify and protect documents containing personal data in SharePoint Online and OneDrive for Business. - Ensure that data subject requests (DSRs) for access and deletion can be fulfilled within the regulatory timeframes. - Prevent accidental sharing of sensitive data via email and Teams. - Maintain an audit trail of all activities related to personal data for at least one year. - Manage data retention to comply with local laws that require different retention periods for different types of data. Which combination of Microsoft Purview solutions should you use?

⚠ Common exam trap

The question tests the distinction between Purview solutions: understand that DSR fulfillment requires eDiscovery, not Communication Compliance or Insider Risk Management. Also note that Audit (Premium) is needed for 1-year retention, not Audit (Standard).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sensitivity labels with auto-labeling, DLP, eDiscovery, Data Lifecycle Management, and Audit (Premium)

It includes all the necessary Purview solutions: Sensitivity labels with auto-labeling classify and protect documents containing personal data; DLP prevents accidental sharing via email and Teams; eDiscovery enables fulfilling data subject requests (DSRs) for access and deletion; Data Lifecycle Management allows configuring different retention periods for different data types; Audit (Premium) provides one-year audit trail retention. Options B, C, and D each miss one or more critical components needed to meet all requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sensitivity labels with auto-labeling, DLP, eDiscovery, Data Lifecycle Management, and Audit (Premium)

    Why this is correct

    Sensitivity labels with auto-labelling classify and protect personal data across SharePoint Online and OneDrive for Business, while DLP blocks accidental sharing through email and Teams. eDiscovery handles DSR access and deletion, Data Lifecycle Management applies differing retention periods, and Audit (Premium) retains the one-year activity trail.

  • ✗

    Insider Risk Management, DLP, eDiscovery, and Data Lifecycle Management

    Why it's wrong here

    Insider Risk Management detects risky user behaviour rather than auto-classifying personal data in SharePoint and OneDrive, leaving that requirement unmet. It is tempting because Insider Risk Management is the right choice when the objective is identifying data exfiltration or IP theft by internal users.

  • ✗

    Data Lifecycle Management, Information Barriers, DLP, and Audit (Premium)

    Why it's wrong here

    Information Barriers restrict communication between groups; they neither classify personal data nor fulfil data subject access and deletion requests. It is tempting because Information Barriers is the correct control when segregating teams, such as preventing traders and advisers from communicating.

  • ✗

    Sensitivity labels, Communication Compliance, eDiscovery, and Audit (Standard)

    Why it's wrong here

    Audit (Standard) retains events for only 90 days, short of the one-year audit trail, and Communication Compliance does not classify documents. It is tempting because Communication Compliance is correct when the goal is reviewing Teams and email messages for policy violations.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.