Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company wants to monitor internal communications for inappropriate content such as harassment or threats, and also prevent employees from accidentally sharing credit card numbers via email. Which combination of Microsoft Purview solutions should they use?

⚠ Common exam trap

Many candidates confuse the overlapping capabilities of Communication Compliance and DLP, assuming one tool can handle both behavioral monitoring and data protection, when in fact each is specialized for a distinct compliance domain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Communication Compliance for harassment detection and DLP for preventing sharing of credit card numbers

Communication Compliance is designed to detect and investigate inappropriate internal communications (e.g., harassment, threats) by analyzing messages against customizable policies. Data Loss Prevention (DLP) is purpose-built to identify and prevent the accidental sharing of sensitive data, such as credit card numbers, by scanning content for predefined patterns (e.g., regex for credit card formats) and enforcing policy actions like blocking the email. Together, they address the two distinct requirements: Communication Compliance for behavioral monitoring and DLP for data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Communication Compliance for both detecting harassment and preventing credit card sharing

    Why it's wrong here

    Communication Compliance can detect certain sensitive information types, but its primary purpose is policy-violating communications. DLP is more effective for preventing accidental sharing of regulated data like credit card numbers, as it provides actions like blocking.

  • ✗

    Use Data Loss Prevention (DLP) for both detecting harassment and preventing credit card sharing

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information types, such as credit card numbers, from unauthorized sharing or exfiltration. However, DLP lacks the advanced contextual analysis, machine learning, and human review workflows required to effectively detect nuanced policy violations like harassment, threats, or discriminatory language within communications. Its core function is data protection, not the behavioral or content-based compliance analysis needed for inappropriate conduct.

  • ✓

    Use Communication Compliance for harassment detection and DLP for preventing sharing of credit card numbers

    Why this is correct

    This option correctly assigns the distinct capabilities of each solution. Microsoft Purview Communication Compliance leverages machine learning and predefined or custom policies to proactively detect inappropriate content, including harassment, threats, and discriminatory language, across various communication channels. Concurrently, Microsoft Purview Data Loss Prevention (DLP) is precisely designed to identify and prevent the unauthorized sharing or leakage of sensitive information, such as credit card numbers, by applying policies that can block, warn, or encrypt data based on its content and context.

  • ✗

    Use eDiscovery for both harassment detection and data leak prevention

    Why it's wrong here

    Microsoft Purview eDiscovery tools are primarily designed for identifying, preserving, collecting, and reviewing electronic data for legal or investigative purposes *after* an event has occurred. They function as reactive tools for content search and retrieval, not as proactive real-time monitoring, detection, or prevention mechanisms. Therefore, eDiscovery cannot actively detect harassment as it happens or prevent data leaks in real-time, which are functions requiring continuous policy enforcement and automated actions.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.