How to Track Compliance Progress and Assign Improvement Actions in Compliance Manager
An organization uses Microsoft Purview Compliance Manager. They need to track their progress against a specific regulatory standard and assign improvement actions to different teams. Which component should they use?
Quick Answer
The answer is Compliance Manager assessments, as this is the specific component within Microsoft Purview designed to track compliance progress and assign improvement actions against a regulatory standard. Each assessment maps to a chosen regulation—like GDPR or ISO 27001—and contains a set of improvement actions that can be assigned to different teams with due dates and status updates, giving you a clear progress score. On the SC-900 exam, this question tests your ability to distinguish Compliance Manager’s core purpose from other Purview tools; a common trap is confusing it with Data Loss Prevention (DLP), which focuses on protecting sensitive data rather than tracking regulatory compliance. Remember that if you need to measure your compliance posture and delegate tasks, you are working with an assessment. For a quick memory tip: think of an assessment as your compliance report card, where improvement actions are the homework you assign to different teams.
⚠ Common exam trap
Test-takers frequently confuse Compliance Manager assessments with general compliance features like DLP or eDiscovery, but the question specifically asks for a component that tracks progress against a regulatory standard and assigns improvement actions, which is unique to assessments within Compliance Manager.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance Manager assessments
Compliance Manager assessments are the correct component because they allow you to track progress against a specific regulatory standard (e.g., ISO 27001, SOC 2) by creating an assessment that maps controls to that standard. Improvement actions are the granular tasks within an assessment that can be assigned to different teams for remediation, directly supporting the need to track progress and assign work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compliance Manager assessments
Why this is correct
Assessments in Compliance Manager allow tracking against standards and assigning improvement actions.
- ✗
eDiscovery
Why it's wrong here
eDiscovery is for legal discovery, not compliance scoring.
- ✗
Data Loss Prevention
Why it's wrong here
DLP is not for compliance management tracking.
- ✗
Audit logs
Why it's wrong here
Audit logs provide activity records, not compliance progress.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A multinational corporation must comply with the General Data Protection Regulation (GDPR). They use Microsoft Purview Compliance Manager to manage compliance activities. The compliance manager wants to automatically assign each control to the appropriate team member for remediation. What should they configure?
hard- A.Create new assessments for each regulation
- ✓ B.Configure improvement actions with owners
- C.Set up connectors to import external risk data
- D.Use the Microsoft 365 admin center to delegate tasks
Why B: To automatically assign each control to the appropriate team member for remediation in Microsoft Purview Compliance Manager, you must configure improvement actions with owners. Each improvement action can be assigned to a specific user who is responsible for implementing the remediation steps, and this assignment triggers automatic notifications and tracking within the compliance score.
Variation 2. A multinational corporation must comply with several regulatory frameworks, including GDPR, SOX, and HIPAA. The compliance officer wants to continuously assess the organization's compliance posture against these regulations, receive prioritized improvement actions, and track the implementation progress of those actions. Which Microsoft Purview solution should the compliance officer use?
hard- A.Information Protection
- ✓ B.Compliance Manager
- C.Data Lifecycle Management
- D.Insider Risk Management
Why B: Compliance Manager is the correct solution because it provides a centralized dashboard for continuously assessing compliance posture against multiple regulatory frameworks (GDPR, SOX, HIPAA), generates prioritized improvement actions based on built-in assessments, and tracks implementation progress of those actions through a task-based workflow. It uses automated control mapping and continuous monitoring to help organizations meet evolving compliance requirements.
Variation 3. A multinational corporation must comply with several regulations including GDPR, ISO 27001, and NIST. They need a single solution that provides a compliance score, tracks their progress, and recommends specific improvement actions that can be assigned to different departments. Which Microsoft Purview solution meets these requirements?
medium- ✓ A.A
- B.B
- C.C
- D.D
Why A: Microsoft Purview Compliance Manager provides a unified compliance score, tracks progress over time, and offers recommended improvement actions that can be assigned to specific departments. It supports multiple regulations like GDPR, ISO 27001, and NIST by mapping controls to these frameworks, making it the correct solution for the multinational corporation's needs.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.