SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Which TWO Microsoft Purview solutions can help detect and prevent data exfiltration?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Purview Audit (logging) with a detection or prevention capability, or assume Compliance Manager or eDiscovery have a security monitoring role, when in fact they serve compliance and legal functions respectively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Insider Risk Management
Microsoft Purview Insider Risk Management (A) is correct because it uses behavioral analytics and signals (e.g., file downloads, exfiltration to personal cloud storage, USB activity) to detect risky user activity and trigger alerts, policies, and remediation workflows aimed at preventing data exfiltration. Microsoft Purview Data Loss Prevention (C) is correct because DLP policies detect and block sensitive data (based on sensitive information types, trainable classifiers, or labels) as it is shared across endpoints, Exchange Online, SharePoint, OneDrive, Teams, and other locations, directly preventing exfiltration. Microsoft Purview Audit (B) only records and searches activity logs for later investigation; it does not detect or prevent exfiltration in real time. Microsoft Purview Compliance Manager (D) assesses and tracks regulatory compliance posture via assessments and improvement actions, not data exfiltration. Microsoft Purview eDiscovery (E) is used to identify, preserve, collect, and review content for legal or investigative cases, not to detect or block exfiltration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Insider Risk Management
Why this is correct
Microsoft Purview Insider Risk Management proactively detects and acts on malicious or inadvertent insider activities that could lead to data exfiltration. It leverages machine learning and behavioral analytics across Microsoft 365 services to identify unusual or risky user behaviors, such as downloading large amounts of sensitive data or sharing it externally, providing alerts and enabling remediation actions to prevent data loss.
- ✗
Microsoft Purview Audit
Why it's wrong here
Microsoft Purview Audit records user and admin activity for later investigation, so it provides after-the-fact visibility rather than the detection and prevention controls the question demands. It cannot block a file transfer, apply a DLP policy or trigger a protective action. Audit is the right choice when the requirement is to search and retain activity logs for compliance or forensic review, not to stop exfiltration in progress.
- ✓
Microsoft Purview Data Loss Prevention
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) is engineered to identify, monitor, and automatically protect sensitive information across endpoints, cloud apps, and on-premises repositories. It enforces policies to prevent data exfiltration by blocking inappropriate sharing, encrypting files, or notifying administrators when sensitive data attempts to leave the organizational boundary, based on predefined rules and sensitive info types.
- ✗
Microsoft Purview Compliance Manager
Why it's wrong here
Microsoft Purview Compliance Manager is a workflow-based solution designed to help organizations manage their compliance posture by providing a centralized view of regulatory requirements, recommended actions, and progress tracking. It assists in assessing, improving, and reporting on compliance with various standards and regulations, but it does not directly detect or prevent data exfiltration incidents; its focus is on organizational compliance management.
- ✗
Microsoft Purview eDiscovery
Why it's wrong here
Microsoft Purview eDiscovery (Standard and Premium) is specifically designed to identify, preserve, collect, process, review, and analyze electronically stored information (ESI) for legal or investigative purposes. Its function is to support litigation, regulatory requests, or internal investigations by providing tools to manage the discovery process, not to proactively detect or prevent data loss or exfiltration from occurring in the first place.
Go deeper
Related to this question
Learn chapter
eDiscovery and Audit
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.