Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which TWO of the following are features of Microsoft Purview Audit?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Records user and admin activities in the unified audit log

Microsoft Purview Audit provides detailed logging of user and admin activities, and allows searching the audit log for security investigations. It does not automatically block malicious activities (that's DLP or Defender), and it does not manage sensitivity labels (that's Information Protection). It does not provide real-time threat detection (that's Sentinel or Defender).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Manages sensitivity labels for documents

    Why it's wrong here

    Microsoft Purview Data Map can discover and classify data based on existing sensitivity labels, but the creation, publishing, and enforcement of these labels are primarily handled by Microsoft Purview Information Protection (formerly part of Azure Information Protection and Microsoft 365 compliance center). Purview's role is more about understanding where labeled data resides and applying governance policies, not the lifecycle management of the labels themselves.

  • Provides real-time threat detection

    Why it's wrong here

    Microsoft Purview focuses on data governance, risk, and compliance, including data discovery, classification, and lifecycle management. Real-time threat detection, which involves monitoring for anomalous behavior, malware, and active attacks across endpoints, identities, and cloud apps, is a core function of Microsoft Defender XDR services and Microsoft Sentinel, which are dedicated security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solutions.

  • Automatically blocks malicious activities

    Why it's wrong here

    While Microsoft Purview includes compliance features like Audit that log activities, it does not automatically block malicious actions. Active blocking and remediation of malicious activities are functions of security solutions such as Microsoft Defender for Endpoint, Defender for Cloud Apps, or Microsoft Sentinel, which are designed for real-time protection and automated responses to threats. Purview's role is more about identifying data risks and ensuring compliance, not real-time security enforcement.

  • Records user and admin activities in the unified audit log

    Why this is correct

    Microsoft Purview's Audit solution is responsible for capturing and retaining a comprehensive record of user and administrator activities across various Microsoft 365 services, Azure, and other integrated platforms. This unified audit log provides a forensic trail of actions, including file access, mailbox operations, and configuration changes, which is crucial for security investigations, compliance adherence, and internal audits. It centralizes logging for easier management and analysis.

  • Allows searching and investigating audit log entries

    Why this is correct

    A key feature of Microsoft Purview Audit is the ability to search and investigate the extensive entries within the unified audit log. This functionality allows compliance officers, security analysts, and IT administrators to perform targeted searches based on specific users, activities, date ranges, or services, enabling forensic analysis, incident response, and compliance reporting. The audit log search tool provides a powerful interface for detailed examination of recorded events.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.