Your organization uses Microsoft Purview Audit (Standard) and needs to investigate a data breach that occurred 120 days ago. You discover that the required audit logs are not available. What is the most likely reason?
Microsoft Purview Audit (Standard) is specifically designed with a fixed retention period of 90 days for all audit logs. This means that any audit records generated will be automatically retained for exactly 90 days from their creation date. After this 90-day window expires, these logs are automatically and permanently purged from the system, making them irretrievable. This inherent limitation is a primary reason why older audit logs might appear to be missing.
Why this answer
Microsoft Purview Audit (Standard) retains audit logs for only 90 days by default. Since the data breach occurred 120 days ago, the logs would have been automatically purged after the retention period expired, making them unavailable for investigation.
Exam trap
The trap here is that candidates may assume licensing or storage issues cause log unavailability, but the SC-900 specifically tests the 90-day retention limit for Audit (Standard) as a key differentiator from Audit (Premium).
How to eliminate wrong answers
Option A is wrong because licensing affects the ability to generate or access audit logs, but the user already has access to Audit (Standard); the issue is retention duration, not licensing. Option C is wrong because insufficient storage does not cause log unavailability in Purview Audit; logs are stored in a managed, scalable backend and are not constrained by organizational storage limits. Option D is wrong because while manual deletion is possible, the most likely reason given the 120-day timeframe is the default 90-day retention policy, not deliberate administrative action.