SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Which TWO Microsoft Purview solutions can be used to protect sensitive data in Microsoft Teams?
⚠ Common exam trap
Watch out — candidates often confuse Information barriers (which control who can communicate) with DLP (which controls what data can be shared), or they mistakenly think Communication compliance is a protective measure when it is actually a detective and review tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) is correct because Microsoft Purview DLP policies can be scoped to Microsoft Teams chat and channel messages, detecting sensitive information types (for example, credit card or Social Security numbers) and taking protective actions such as blocking the message or generating alerts. Sensitivity labels are correct because they can be applied to Teams sites, channels, and files shared in Teams, and they enforce protection such as encryption and access restrictions that travel with the content. Information barriers are not the best fit here because they restrict communication between groups rather than protect sensitive data content itself. Communication compliance is designed to detect and remediate inappropriate or risky communications for compliance review, not to apply data protection controls. eDiscovery is used for identifying, preserving, and collecting content for legal or investigative purposes, not for preventing sensitive data exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Information barriers
Why it's wrong here
Information barriers restrict communication between defined user segments, such as conflicting departments, rather than protecting sensitive data itself within Teams. It tempts because it governs Teams interactions, but the question asks which solutions protect sensitive data, which labels and DLP accomplish.
- ✗
Communication compliance
Why it's wrong here
Communication compliance detects and reviews risky or inappropriate messages, including regulatory breaches, but does not apply encryption or labels to sensitive content in Teams. It tempts because it does monitor Teams communications, yet protection of sensitive data requires sensitivity labels and DLP.
- ✓
Data Loss Prevention (DLP)
Why this is correct
DLP policies evaluate Teams chat and channel messages for sensitive information types, blocking or warning on sharing. This protects sensitive data in Teams because policy tips and enforcement act at the point of message transmission, satisfying the requirement to safeguard content within that workload.
- ✓
Sensitivity labels
Why this is correct
Sensitivity labels classify Teams content and can enforce encryption, so labelled data stays protected regardless of where it is shared. This protects sensitive data in Teams by applying persistent protection at the item level, complementing DLP's transmission-time inspection.
- ✗
eDiscovery
Why it's wrong here
eDiscovery identifies, holds and exports content for legal or investigative purposes; it does not prevent or encrypt sensitive data in Teams. It tempts because it surfaces Teams content during cases, but preservation and collection are reactive, not the protective controls the question requires.
Go deeper
Related to this question
Learn chapter
Trainable Classifiers for Content Classification
Key term
Exposure
Exposure is the measure of potential loss or harm to an organization's assets when a vulnerability is exploited by a threat, often expressed as the window of time or degree of access an attacker has.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.