SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which THREE of the following are features of Microsoft Purview Insider Risk Management?
⚠ Common exam trap
It's easy for candidates to confuse Insider Risk Management with broader security solutions like Defender for Office 365 or Defender for Endpoint, leading them to select phishing simulation or vulnerability scanning as features of Insider Risk Management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detection of repeated security policy violations by a user
Insider Risk Management (IRM) in Microsoft Purview is designed to detect, investigate, and act on risky user activity, so option C is correct because IRM policies can surface indicators of repeated security policy violations (e.g., repeated DLP rule matches or unusual downloads) as risk signals. Option D is correct because IRM correlates signals such as email events and DLP alerts to detect unauthorized data exfiltration via email, including sending sensitive content to personal or external recipients. Option E is correct because IRM includes forensic evidence capabilities, such as the forensic evidence add-on that captures user actions on onboarded devices (e.g., file copies, uploads, and keystrokes) for investigation. Option A is not part of IRM; phishing simulation campaigns are delivered by Microsoft Defender for Office 365 Attack simulation training. Option B is not part of IRM; vulnerability scanning of endpoints is handled by Microsoft Defender Vulnerability Management, not Insider Risk Management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Phishing simulation campaigns
Why it's wrong here
Phishing simulation campaigns are a core capability of Microsoft Defender for Office 365's Attack Simulation Training. This feature allows organizations to run realistic phishing attacks against their users to identify vulnerabilities in security awareness and measure user susceptibility. Microsoft Purview, however, focuses on data governance, risk management, and compliance, and does not include tools for actively simulating cyberattacks on users.
- ✗
Vulnerability scanning of network endpoints
Why it's wrong here
Vulnerability scanning of network endpoints is primarily a function of Microsoft Defender for Cloud, often integrated with Microsoft Defender for Endpoint. These services provide continuous monitoring, vulnerability assessments, and threat protection across servers, workstations, and other network-connected devices. Microsoft Purview's scope is centered on data discovery, classification, protection, and insider risk management, not on identifying software or configuration vulnerabilities on infrastructure endpoints.
- ✓
Detection of repeated security policy violations by a user
Why this is correct
Microsoft Purview's Insider Risk Management solution is specifically designed to detect and manage cumulative policy violations by users. It leverages signals from various sources, including Microsoft 365 services, Windows endpoints, and third-party platforms, to identify patterns of risky behavior, such as repeated attempts to access sensitive data or consistent non-compliance with data handling policies. This capability helps organizations proactively identify and mitigate potential insider threats before they escalate into significant incidents.
- ✓
Detection of unauthorized data exfiltration via email
Why this is correct
Microsoft Purview effectively detects unauthorized data exfiltration via email through its Data Loss Prevention (DLP) and Insider Risk Management capabilities. DLP policies can identify and block sensitive information from being sent outside the organization via email, while Insider Risk Management monitors email activity for suspicious patterns indicative of data theft or unauthorized sharing. These integrated features provide robust protection against sensitive data leaving the organization through electronic communications.
- ✓
Forensic evidence capturing user actions on devices
Why this is correct
Within Microsoft Purview's Insider Risk Management, the forensic evidence capturing feature allows security teams to collect detailed user activity logs on Windows endpoints. This capability provides an immutable record of user actions, such as file access, application usage, and web browsing, when a potential insider risk policy violation is detected. This granular forensic data is crucial for in-depth investigations, helping to understand the context and intent behind risky behaviors and supporting legal or HR actions.
Go deeper
Related to this question
Learn chapter
Records Management in Microsoft Purview
Key term
Defender for Office 365
Microsoft Defender for Office 365 is a cloud-based email security service that protects organizations against advanced threats like phishing, malware, and business email compromise by scanning emails, attachments, and links in real time.
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.