Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company wants to monitor Microsoft Teams messages and corporate emails for policy violations related to potential harassment and inappropriate behavior. They need a solution that allows them to define policies with conditions (e.g., keywords, patterns), automatically flag suspicious conversations, and optionally send notifications to the sender or escalate to a reviewer. Additionally, they need the ability to train employees when a minor violation is detected. Which Microsoft Purview solution should they use?

⚠ Common exam trap

A common mix-up: candidates confuse Communication Compliance with Data Loss Prevention (DLP) because both involve policy-based scanning of communications, but DLP lacks the behavioral monitoring, notification, and training capabilities required for harassment and inappropriate behavior scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Communication Compliance

Communication Compliance is the correct solution because it is specifically designed to detect policy violations in Microsoft Teams messages and corporate emails by scanning for keywords, patterns, and other conditions. It can automatically flag suspicious conversations, send notifications to the sender, escalate to a reviewer, and even train employees on minor violations through its built-in remediation workflows.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    Microsoft 365 Data Loss Prevention (DLP) is engineered to identify, monitor, and protect sensitive information from being shared inappropriately or accidentally leaked outside the organization. It uses policies to detect specific sensitive information types (SITs) like credit card numbers, social security numbers, or health records across emails, documents, and messages. While DLP can detect sensitive content in communications, its primary focus is on preventing the loss or misuse of classified data, not on proactively monitoring for general behavioral policy violations or code-of-conduct breaches like harassment.

  • Communication Compliance

    Why this is correct

    Communication Compliance is the correct solution, specifically designed to help organizations detect, investigate, and act on inappropriate messages within Microsoft Teams, Exchange Online, Yammer, and other communication platforms. It leverages intelligent classifiers and customizable policies to identify potential regulatory compliance issues, code-of-conduct violations, or instances of harassment. This service provides a robust framework for reviewing flagged communications, taking remediation actions such as notifying users, and fostering a compliant and respectful workplace environment.

  • Information Protection

    Why it's wrong here

    Microsoft Information Protection (MIP) is a framework focused on classifying, labeling, and protecting an organization's sensitive data wherever it resides or travels. It utilizes sensitivity labels to apply encryption, visual markings, and access restrictions to documents and emails based on their content's sensitivity. While labels can be applied to emails, MIP's core function is data classification and protection at the item level, not the active, ongoing monitoring of communication content for behavioral policy violations or code-of-conduct breaches within messages.

    When this WOULD be correct

    A company needs to classify documents and emails containing credit card numbers and apply encryption automatically. Information Protection with sensitivity labels would be the correct solution.

  • Audit

    Why it's wrong here

    The Microsoft 365 Audit log provides a comprehensive, immutable record of user and administrator activities across various services, serving as a critical tool for forensic investigations, compliance reporting, and troubleshooting. It captures metadata about actions performed, such as who accessed a file or sent an email, and when. However, the Audit log does not proactively scan the content of messages for policy violations or offer automated remediation for inappropriate communications; its purpose is purely to provide a historical record of events.

    When this WOULD be correct

    A company needs to track user and admin activities across Microsoft 365 services for security investigations or compliance reporting, such as who accessed sensitive files or changed permissions.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.

Communication ComplianceCorrect answer

Why this is correct

Communication Compliance is the correct solution, specifically designed to help organizations detect, investigate, and act on inappropriate messages within Microsoft Teams, Exchange Online, Yammer, and other communication platforms. It leverages intelligent classifiers and customizable policies to identify potential regulatory compliance issues, code-of-conduct violations, or instances of harassment. This service provides a robust framework for reviewing flagged communications, taking remediation actions such as notifying users, and fostering a compliant and respectful workplace environment.

Information ProtectionWrong answer — click to see why

Why this is wrong here

Information Protection focuses on classifying and protecting sensitive data (e.g., labels, encryption) but does not include monitoring communications for policy violations like harassment or sending training notifications.

★ When this WOULD be the correct answer

A company needs to classify documents and emails containing credit card numbers and apply encryption automatically. Information Protection with sensitivity labels would be the correct solution.

Why candidates choose this

Candidates may confuse 'protecting information' broadly with monitoring communications, or think that policies for harassment involve protecting information from misuse.

AuditWrong answer — click to see why

Why this is wrong here

Audit logs user and admin activity but does not define policies to monitor content for harassment or policy violations, nor does it provide training or notification features.

★ When this WOULD be the correct answer

A company needs to track user and admin activities across Microsoft 365 services for security investigations or compliance reporting, such as who accessed sensitive files or changed permissions.

Why candidates choose this

Candidates may think Audit is used for monitoring communications because it tracks activities, but it lacks content analysis and policy enforcement capabilities.

Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.