Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Which TWO Microsoft Purview solutions can be used to protect sensitive data in Microsoft Teams chats and channels? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse Sensitivity Labels with DLP, thinking labels alone can prevent data leakage in chats, but labels only apply classification and encryption to files, not real-time scanning of message content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Communication Compliance

Microsoft Purview Communication Compliance is correct because it helps organizations detect and act on inappropriate or sensitive messages in Teams chats and channels by analyzing communications for policy violations such as offensive language, harassment, or sharing of sensitive data. Microsoft Purview Data Loss Prevention (DLP) policies are correct because they can be configured to automatically detect and prevent the sharing of sensitive information (e.g., credit card numbers, social security numbers) in Teams chats and channels by scanning messages and attachments in real time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Communication Compliance

    Why this is correct

    Microsoft Purview Communication Compliance is a powerful solution designed to actively scan and analyze communications, such as Microsoft Teams chats and emails, for policy violations. It leverages machine learning and predefined or custom policies to detect inappropriate sharing of sensitive information, harassment, or regulatory non-compliance. This solution enables organizations to identify risky content, investigate potential issues, and take remediation actions, directly addressing the protection of sensitive data within communication channels.

  • Microsoft Purview Data Loss Prevention (DLP) policies

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations, including Microsoft Teams, Exchange Online, SharePoint Online, and OneDrive. By defining rules based on sensitive info types (SITs) and conditions, DLP can effectively prevent the accidental or intentional sharing of sensitive data outside organizational boundaries, thereby directly protecting it from unauthorized disclosure in real-time.

  • Microsoft Purview Sensitivity Labels

    Why it's wrong here

    While Microsoft Purview Sensitivity Labels are crucial for classifying and applying persistent protection to data through encryption, visual markings, and access restrictions, their primary application is to documents, emails, and containers like SharePoint sites. They do not directly classify or protect the real-time content of individual chat messages within communication platforms such as Teams, making them unsuitable for directly preventing sensitive data sharing within a live conversation.

  • Microsoft Purview Information Barriers

    Why it's wrong here

    Microsoft Purview Information Barriers (IBs) are specifically designed to prevent or restrict communication between defined groups of users, primarily to address regulatory compliance requirements like preventing conflicts of interest. While they effectively control *who* can communicate with whom, IBs do not inspect the *content* of communications for sensitive data or apply protective actions to the data itself, thus they do not directly protect sensitive information from being shared inappropriately within permitted communications.

  • Microsoft Purview Retention Policies

    Why it's wrong here

    Microsoft Purview Retention Policies are utilized to manage the lifecycle of data by defining how long specific content should be kept or permanently deleted across various Microsoft 365 services. Their primary purpose is to meet regulatory, legal, or business record-keeping requirements, ensuring data availability or deletion as needed. These policies do not actively monitor, detect, or prevent the *sharing* of sensitive information, nor do they apply real-time protection against data loss.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.