Courseiva

How to Use Trainable Classifiers in Microsoft Purview Communication Compliance to Minimize False Positives

Your organization is implementing Microsoft Purview Communication Compliance to detect potential regulatory violations. You need to configure a policy that alerts when employees discuss insider trading in emails and Microsoft Teams messages. The solution should minimize false positives. Which action should you take?

Quick Answer

The answer is to use a trainable classifier and train it with sample data. This is correct because trainable classifiers in Microsoft Purview Communication Compliance use machine learning to analyze the specific language and context of your organization’s communications, learning from curated examples of insider trading discussions to accurately flag violations while ignoring benign messages. On the SC-900 exam, this concept tests your understanding of how to balance detection accuracy with minimizing false positives—a common trap is confusing sensitivity thresholds with classifier training, but remember that thresholds only adjust alert volume, not precision. A key memory tip is to think of trainable classifiers as “smart filters” that learn from your data, unlike static keyword lists which are prone to noise.

⚠ Common exam trap

Many exam-takers assume a keyword list or sensitivity threshold is sufficient for compliance, overlooking that trainable classifiers are specifically designed to minimize false positives by learning from sample data rather than relying on static rules.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Use a trainable classifier and train it with sample data

Trainable classifiers use machine learning to identify content based on patterns learned from sample data, which significantly reduces false positives compared to static keyword lists. By training the classifier with relevant examples of insider trading discussions, the policy can accurately distinguish between genuine regulatory violations and benign uses of similar terms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Include all message types without filtering

    Why it's wrong here

    Including all messages increases volume and false positives.

  • Use a trainable classifier and train it with sample data

    Why this is correct

    Trainable classifiers learn from examples and improve detection accuracy.

  • Create a global keyword list of insider trading terms

    Why it's wrong here

    Keyword lists are less accurate and can produce many false positives.

  • Set the policy sensitivity threshold to 90%

    Why it's wrong here

    A high threshold may miss many actual violations, increasing false negatives.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization uses Microsoft Purview Communication Compliance to detect harassing messages. You receive an alert for a message that appears to be a joke between colleagues. What should you do to prevent similar false positives?

hard
  • A.Train users not to joke about sensitive topics
  • B.Delete the alert and ignore future similar messages
  • C.Refine the policy conditions to exclude certain keywords or users
  • D.Turn off the policy and use a different solution

Why C: Microsoft Purview Communication Compliance policies are configurable to reduce false positives. You can refine the policy by adding conditions to exclude specific keywords (e.g., 'joke' or 'just kidding') or specific users (e.g., known colleagues) from triggering alerts, without disabling the policy or relying on user behavior changes.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.