SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE of the following are capabilities of Microsoft Purview Compliance Manager? (Choose three.)
⚠ Common exam trap
SC-900 often tests the boundary between Purview Compliance Manager and other Purview/Entra features — candidates pick 'manage user identities' or 'create DLP policies' because they sound compliance-related, but those belong to Entra ID and Purview DLP respectively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated testing of controls
Option A (Automated testing of controls) is correct because Compliance Manager can automatically test certain Microsoft cloud controls against your tenant configuration — for example, verifying MFA enforcement or password policies — and update their status without manual evidence collection. Option C (Improvement actions) is correct because Compliance Manager provides a catalog of improvement actions that map to controls and standards, letting you assign owners, set implementation status, and track remediation steps to raise your compliance posture. Option E (Compliance score) is correct because Compliance Manager calculates a compliance score that quantifies your progress based on completed improvement actions and passed assessments, weighted by control importance. Option B (Manage user identities) is not a Compliance Manager capability; identity lifecycle and authentication are handled by Microsoft Entra ID. Option D (Create data loss prevention policies) is not a Compliance Manager capability; DLP policies are authored and enforced through Microsoft Purview Data Loss Prevention in the compliance portal, not through Compliance Manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automated testing of controls
Why this is correct
Compliance Manager performs automated testing of controls against your Microsoft 365 environment, continuously assessing configurations and comparing them with regulatory standards. This satisfies the requirement by identifying which controls pass or fail without manual evidence collection, feeding results into the compliance score.
- ✗
Manage user identities
Why it's wrong here
Compliance Manager reports on control compliance and remediation; identity lifecycle and access management are handled by Microsoft Entra ID. It is tempting because compliance assessments reference identity controls, and Entra ID is correct when the task is provisioning, authenticating, or governing user accounts.
- ✓
Improvement actions
Why this is correct
Improvement actions are recommended steps within Compliance Manager that guide remediation of controls not meeting a standard. Each action details implementation guidance and potential score impact, satisfying the requirement by giving organisations concrete tasks to raise compliance posture.
- ✗
Create data loss prevention policies
Why it's wrong here
Compliance Manager assesses compliance posture, assigns improvement actions, and tracks regulatory scores; it does not author DLP rules, which belong to Microsoft Purview Data Loss Prevention. It is tempting because both sit within Microsoft Purview, and DLP is the right tool when the requirement is detecting sensitive data in motion.
- ✓
Compliance score
Why this is correct
The compliance score quantifies overall progress against configured standards and regulations, weighting improvement actions by their risk impact. This satisfies the requirement by providing a measurable, continuously updated metric that reflects how well controls are meeting compliance obligations.
Go deeper
Related to this question
Learn chapter
Identity Governance in Microsoft Entra
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.