Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which TWO of the following are features of Microsoft Purview Audit?

⚠ Common exam trap

SC-900 often tests the difference between Purview Audit (logging and search) and other Purview solutions like DLP or Information Protection; candidates may confuse auditing with active enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Records user and admin activities in the unified audit log

Microsoft Purview Audit is the auditing solution that captures user and administrator activity across Microsoft 365 services and writes those events to the unified audit log, which is exactly what option D describes, so D is correct. It also provides the audit search and investigation tooling (in the Microsoft Purview portal or via Search-UnifiedAuditLog / the Office 365 Management Activity API) that lets organizations query, filter, and investigate those recorded events, which is what option E describes, so E is correct. Option A is wrong because sensitivity label management is a function of Microsoft Purview Information Protection (sensitivity labels), not the Audit solution. Option B is wrong because real-time threat detection is provided by Microsoft Defender for Office 365 / Microsoft 365 Defender alerting, not by Purview Audit, which is a logging and investigation capability. Option C is wrong because Purview Audit is passive/record-keeping and does not automatically block malicious activities; blocking is performed by DLP, Defender, or Conditional Access policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Manages sensitivity labels for documents

    Why it's wrong here

    Microsoft Purview Data Map can discover and classify data based on existing sensitivity labels, but the creation, publishing, and enforcement of these labels are primarily handled by Microsoft Purview Information Protection (formerly part of Azure Information Protection and Microsoft 365 compliance center). Purview's role is more about understanding where labeled data resides and applying governance policies, not the lifecycle management of the labels themselves.

  • ✗

    Provides real-time threat detection

    Why it's wrong here

    Microsoft Purview focuses on data governance, risk, and compliance, including data discovery, classification, and lifecycle management. Real-time threat detection, which involves monitoring for anomalous behavior, malware, and active attacks across endpoints, identities, and cloud apps, is a core function of Microsoft Defender XDR services and Microsoft Sentinel, which are dedicated security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solutions.

  • ✗

    Automatically blocks malicious activities

    Why it's wrong here

    While Microsoft Purview includes compliance features like Audit that log activities, it does not automatically block malicious actions. Active blocking and remediation of malicious activities are functions of security solutions such as Microsoft Defender for Endpoint, Defender for Cloud Apps, or Microsoft Sentinel, which are designed for real-time protection and automated responses to threats. Purview's role is more about identifying data risks and ensuring compliance, not real-time security enforcement.

  • ✓

    Records user and admin activities in the unified audit log

    Why this is correct

    Microsoft Purview's Audit solution is responsible for capturing and retaining a comprehensive record of user and administrator activities across various Microsoft 365 services, Azure, and other integrated platforms. This unified audit log provides a forensic trail of actions, including file access, mailbox operations, and configuration changes, which is crucial for security investigations, compliance adherence, and internal audits. It centralizes logging for easier management and analysis.

  • ✓

    Allows searching and investigating audit log entries

    Why this is correct

    A key feature of Microsoft Purview Audit is the ability to search and investigate the extensive entries within the unified audit log. This functionality allows compliance officers, security analysts, and IT administrators to perform targeted searches based on specific users, activities, date ranges, or services, enabling forensic analysis, incident response, and compliance reporting. The audit log search tool provides a powerful interface for detailed examination of recorded events.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.