SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Which THREE of the following are features of Microsoft Purview Compliance Manager?
⚠ Common exam trap
Many exam-takers confuse the broad capabilities of Microsoft Purview (like DLP and audit) with the specific features of Compliance Manager, which is solely focused on compliance assessment, scoring, and improvement tracking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Improvement actions with assigned owners
Compliance Manager is a Microsoft Purview solution that helps organizations assess and improve their compliance posture. Option B is correct because Compliance Manager provides improvement actions that can be assigned to owners, with implementation status and testing tracked per action. Option D is correct because Compliance Manager calculates a compliance score that quantifies progress toward completing improvement actions and assessments. Option E is correct because Compliance Manager includes pre-built assessments and templates for regulations and standards such as GDPR, ISO 27001, and NIST. Option A is not part of Compliance Manager; Data Loss Prevention policies are configured in Microsoft Purview Data Loss Prevention. Option C is not part of Compliance Manager; Audit log search is provided by Microsoft Purview Audit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Loss Prevention policies
Why it's wrong here
While Data Loss Prevention (DLP) policies are a critical component of the broader Microsoft Purview suite, focusing on preventing sensitive data from leaving an organization's control, they are distinct from the compliance assessment and management features found in Microsoft Purview Compliance Manager. DLP primarily addresses data protection in transit and at rest, whereas Compliance Manager focuses on evaluating and improving an organization's overall compliance posture through assessments and actionable tasks.
- ✓
Improvement actions with assigned owners
Why this is correct
Improvement actions with assigned owners are a core feature within Microsoft Purview Compliance Manager, representing specific tasks recommended to enhance an organization's compliance posture against various regulations and standards. These actions can be assigned to individual users or teams, ensuring clear accountability and enabling systematic tracking of progress as an organization works towards implementing necessary controls and demonstrating adherence to compliance requirements.
- ✗
Audit log search
Why it's wrong here
Audit log search is a fundamental capability provided by Microsoft Purview Audit, a distinct service within the Purview suite that offers comprehensive logging and search functionalities for user and administrator activities across Microsoft 365 services. While essential for forensic investigations, security monitoring, and demonstrating compliance through activity records, it is separate from the proactive compliance assessment and management functions offered by Compliance Manager.
- ✓
Compliance score
Why this is correct
The compliance score is a quantifiable metric within Microsoft Purview Compliance Manager that provides an objective measure of an organization's progress in meeting specific regulatory requirements and industry standards. This score is dynamically calculated based on the completion status of various improvement actions, offering a clear, actionable benchmark to track compliance posture over time and effectively communicate an organization's adherence to stakeholders.
- ✓
Pre-built assessments for regulations like GDPR
Why this is correct
Pre-built assessments for regulations like GDPR are a key feature of Microsoft Purview Compliance Manager, offering templated frameworks designed to help organizations evaluate their adherence to a wide array of international, governmental, and industry-specific compliance standards. These assessments include predefined controls and recommended improvement actions, significantly simplifying the complex process of understanding, implementing, and demonstrating compliance with diverse regulatory obligations.
Go deeper
Related to this question
Learn chapter
Retention Policies and Labels
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.