SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE of the following are capabilities of Microsoft Purview eDiscovery? (Choose three.)
⚠ Common exam trap
It's easy for candidates to confuse eDiscovery's search and hold capabilities with retention or DLP features, leading them to select options like automatic deletion or blocking sensitive data, which belong to separate Purview solutions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Export search results to a PST file
Option B is correct because Microsoft Purview eDiscovery supports exporting search results, and one of the available export formats is a PST file for mailbox content. Option C is correct because eDiscovery allows administrators to place legal holds (e.g., via Litigation Hold or eDiscovery holds) on Exchange Online mailboxes and SharePoint/OneDrive sites to preserve content. Option E is correct because eDiscovery searches can span Microsoft 365 workloads including Exchange Online, SharePoint Online, OneDrive for Business, and other sources. Option A is not an eDiscovery capability; blocking sensitive-data sharing via email is handled by Data Loss Prevention (DLP) policies in Microsoft Purview. Option D is not an eDiscovery capability; automatic deletion of emails older than 7 years is achieved through retention policies or retention labels, not eDiscovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block sharing of sensitive data via email
Why it's wrong here
Blocking the sharing of sensitive data via email is a proactive data protection measure implemented through Microsoft Purview Data Loss Prevention (DLP) policies, not eDiscovery. DLP policies are configured to identify sensitive information types and then enforce rules, such as blocking, notifying, or encrypting, when such data attempts to leave the organization or is shared inappropriately. eDiscovery, conversely, focuses on identifying, preserving, and collecting existing data for legal or investigative purposes after the fact.
- ✓
Export search results to a PST file
Why this is correct
Microsoft Purview eDiscovery provides the capability to export identified search results, including emails, documents, and other content, into a portable PST (Personal Storage Table) file format. This export functionality is crucial for transferring collected evidence to legal review platforms, external counsel, or for offline analysis. The PST file preserves the original metadata and folder structure, ensuring the integrity and usability of the collected data.
- ✓
Place a legal hold on mailboxes and sites
Why this is correct
Placing a legal hold on mailboxes and sites is a fundamental preservation capability within Microsoft Purview eDiscovery. When a legal hold is applied, it prevents the permanent deletion or modification of content within specified locations, such as Exchange Online mailboxes, SharePoint Online sites, and OneDrive for Business accounts, even if users attempt to delete items. This ensures that all potentially relevant electronically stored information (ESI) is retained for the duration of a legal matter or investigation.
- ✗
Automatically delete emails older than 7 years
Why it's wrong here
Automatically deleting emails older than a specified period, such as 7 years, is a function of Microsoft Purview retention policies, which are part of Information Governance, not eDiscovery. Retention policies are designed to manage the lifecycle of data by either retaining content for a minimum period or deleting it after a certain age, based on organizational compliance requirements. eDiscovery's role is to identify and preserve existing data, not to manage its automated lifecycle.
- ✓
Search for content across Exchange Online, SharePoint Online, and OneDrive for Business
Why this is correct
Microsoft Purview eDiscovery offers robust capabilities to search for content across a wide array of Microsoft 365 services from a single interface. This includes comprehensively querying email messages and attachments in Exchange Online, documents and files stored in SharePoint Online and OneDrive for Business, and even conversations and files within Microsoft Teams. This unified search ensures that investigators can locate all relevant electronically stored information (ESI) regardless of its specific storage location within the M365 ecosystem.
Go deeper
Related to this question
Learn chapter
Data Classification in Microsoft Purview
Key term
SPAN
A Switch Port Analyzer (SPAN) is a feature on network switches that copies traffic from one or more ports to a monitoring port for analysis without disrupting normal network operations.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.