SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which TWO of the following are features of Microsoft Purview Audit?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Records user and admin activities in the unified audit log
Microsoft Purview Audit provides detailed logging of user and admin activities, and allows searching the audit log for security investigations. It does not automatically block malicious activities (that's DLP or Defender), and it does not manage sensitivity labels (that's Information Protection). It does not provide real-time threat detection (that's Sentinel or Defender).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Manages sensitivity labels for documents
Why it's wrong here
Microsoft Purview Data Map can discover and classify data based on existing sensitivity labels, but the creation, publishing, and enforcement of these labels are primarily handled by Microsoft Purview Information Protection (formerly part of Azure Information Protection and Microsoft 365 compliance center). Purview's role is more about understanding where labeled data resides and applying governance policies, not the lifecycle management of the labels themselves.
- ✗
Provides real-time threat detection
Why it's wrong here
Microsoft Purview focuses on data governance, risk, and compliance, including data discovery, classification, and lifecycle management. Real-time threat detection, which involves monitoring for anomalous behavior, malware, and active attacks across endpoints, identities, and cloud apps, is a core function of Microsoft Defender XDR services and Microsoft Sentinel, which are dedicated security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solutions.
- ✗
Automatically blocks malicious activities
Why it's wrong here
While Microsoft Purview includes compliance features like Audit that log activities, it does not automatically block malicious actions. Active blocking and remediation of malicious activities are functions of security solutions such as Microsoft Defender for Endpoint, Defender for Cloud Apps, or Microsoft Sentinel, which are designed for real-time protection and automated responses to threats. Purview's role is more about identifying data risks and ensuring compliance, not real-time security enforcement.
- ✓
Records user and admin activities in the unified audit log
Why this is correct
Microsoft Purview's Audit solution is responsible for capturing and retaining a comprehensive record of user and administrator activities across various Microsoft 365 services, Azure, and other integrated platforms. This unified audit log provides a forensic trail of actions, including file access, mailbox operations, and configuration changes, which is crucial for security investigations, compliance adherence, and internal audits. It centralizes logging for easier management and analysis.
- ✓
Allows searching and investigating audit log entries
Why this is correct
A key feature of Microsoft Purview Audit is the ability to search and investigate the extensive entries within the unified audit log. This functionality allows compliance officers, security analysts, and IT administrators to perform targeted searches based on specific users, activities, date ranges, or services, enabling forensic analysis, incident response, and compliance reporting. The audit log search tool provides a powerful interface for detailed examination of recorded events.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Information protection
Information protection refers to the policies, procedures, and technologies used to safeguard data from unauthorized access, disclosure, alteration, or destruction.
Key term
Audit log
An audit log is a chronological record of security-relevant events and user activities within a system, used for monitoring, compliance, and forensic analysis.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.