SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Which TWO Microsoft Purview solutions help organizations respond to data subject requests under GDPR?
⚠ Common exam trap
Candidates often mistakenly think that Data Loss Prevention (DLP) can directly respond to data subject requests, but DLP only prevents data leaks and does not provide the search, export, or deletion workflows required for GDPR rights.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
eDiscovery
eDiscovery (A) is correct because it enables organizations to search for and export personal data across Microsoft 365 workloads (Exchange, SharePoint, OneDrive, Teams) to fulfill data subject access and export requests under GDPR Article 15. Data Lifecycle Management (C) is correct because it allows organizations to retain personal data for the minimum necessary period and permanently delete it when no longer needed, supporting the right to erasure under GDPR Article 17.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
eDiscovery
Why this is correct
eDiscovery in Microsoft Purview is specifically designed to identify, preserve, collect, process, review, and export electronically stored information (ESI). This functionality is crucial for responding to legal requests, regulatory investigations, and data subject access requests (DSARs) by allowing organizations to efficiently locate and retrieve relevant data across various Microsoft 365 services. It centralizes the search and collection process for compliance needs.
- ✗
Information barriers
Why it's wrong here
Information barriers are a compliance solution in Microsoft Purview that prevents specific groups of users from communicating with each other, or allows communication only between certain groups. Its primary purpose is to avoid conflicts of interest or maintain confidentiality within highly regulated industries by segmenting communication flows, not to facilitate the search or management of data for individual subject access requests.
- ✓
Data Lifecycle Management
Why this is correct
Data Lifecycle Management (DLM), often implemented through Microsoft Purview's retention policies and labels, enables organizations to define how long data is kept and when it is deleted. This capability is fundamental for responding to data subject access requests (DSARs) by ensuring data is retained only as long as necessary and can be defensibly deleted, directly impacting the scope and availability of data for such requests.
- ✗
Data Loss Prevention (DLP)
Why it's wrong here
Data Loss Prevention (DLP) policies in Microsoft Purview are engineered to identify, monitor, and protect sensitive information across various locations, preventing its unauthorized sharing or transfer outside the organization. While critical for data security and compliance, DLP's core function is proactive prevention of data exfiltration, not the reactive search, collection, or management of data in response to a data subject's request for their personal information.
- ✗
Communication compliance
Why it's wrong here
Communication compliance in Microsoft Purview helps organizations detect, capture, and act on inappropriate messages within their internal and external communications, often leveraging machine learning to identify policy violations. Its primary role is to mitigate risks like harassment, regulatory non-compliance, or intellectual property theft by monitoring content, not to provide tools for searching or managing specific data for individual subject access requests.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Data lifecycle management
Data lifecycle management is the process of managing data from its creation to its deletion, ensuring it is stored, used, and disposed of in a way that meets security, compliance, and business needs.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.