Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Which TWO actions can be performed using Microsoft Purview Data Lifecycle Management?

⚠ Common exam trap

Watch out — candidates often confuse the capabilities of Microsoft Purview Data Lifecycle Management with those of Information Protection or Communication Compliance, leading them to select options related to monitoring, blocking, or classifying data, which belong to other compliance solutions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a retention policy to keep financial records for 7 years

Microsoft Purview Data Lifecycle Management allows administrators to create retention policies that specify how long data must be kept to meet regulatory or business requirements, such as retaining financial records for 7 years. Option C is correct because the same solution enables deletion policies that automatically remove outdated content, like drafts older than 30 days, ensuring data is not kept longer than necessary.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a retention policy to keep financial records for 7 years

    Why this is correct

    Microsoft Purview Data Lifecycle Management (DLM) is specifically designed to help organizations manage their data throughout its entire lifecycle, including long-term preservation. Creating a retention policy to keep financial records for a specified duration, such as seven years, is a fundamental capability within DLM. These policies ensure compliance with legal, regulatory, and business requirements by preventing premature deletion and ensuring data availability.

  • Monitor internal emails for policy violations

    Why it's wrong here

    Monitoring internal emails for policy violations is a distinct function performed by Microsoft Purview Communication Compliance, not Data Lifecycle Management. Communication Compliance is engineered to detect and remediate inappropriate content, regulatory compliance issues, or policy violations within an organization's communication channels. Data Lifecycle Management, in contrast, focuses on the retention and deletion of data based on its age or other attributes.

  • Create a deletion policy to remove old drafts after 30 days

    Why this is correct

    Microsoft Purview Data Lifecycle Management (DLM) encompasses the ability to create and enforce deletion policies, which are crucial for managing data sprawl and ensuring compliance. Configuring a deletion policy to automatically remove old drafts after 30 days is a direct application of DLM's capabilities. This action helps organizations reduce storage costs, minimize data risk, and ensure that outdated or irrelevant information is systematically purged from their systems.

  • Block sharing of sensitive files with external users

    Why it's wrong here

    Blocking the sharing of sensitive files with external users is a primary function of Microsoft Purview Data Loss Prevention (DLP) policies, not Data Lifecycle Management. DLP policies are specifically designed to identify, monitor, and protect sensitive information across various locations and prevent its unauthorized sharing or exfiltration. Data Lifecycle Management, conversely, is concerned with the long-term retention and eventual disposition of data.

  • Automatically classify documents containing PII

    Why it's wrong here

    Automatically classifying documents containing Personally Identifiable Information (PII) is a core capability of Microsoft Purview Information Protection, typically achieved through sensitivity labels and auto-labeling policies. While classification is a critical precursor that informs Data Lifecycle Management, it is a distinct process that identifies the sensitivity of data. Data Lifecycle Management then leverages this classification to apply appropriate retention or deletion actions, rather than performing the initial classification itself.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.