Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Which TWO of the following are required to use Microsoft Purview Audit (Premium)?

⚠ Common exam trap

Candidates often assume an Azure subscription or additional services like Sentinel are required for premium auditing, when in fact the only prerequisites are the unified audit log being enabled and an E5/A5 license per user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unified audit log enabled in the Microsoft 365 Defender portal

Option A is correct because Microsoft Purview Audit (Premium) builds on the unified audit log, so auditing must first be turned on in the Microsoft 365 Defender portal (or via Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true) before premium features such as longer retention and high-value events can be captured. Option B is correct because Audit (Premium) capabilities are licensed through Microsoft 365 E5/A5 (or the E5/A5 Compliance add-on) assigned to each user whose premium audit data is generated. Option C is not required because audit records are stored in Microsoft's service, not in a customer Azure subscription. Option D is not required because Power BI Pro is unrelated to audit ingestion or retention. Option E is not required because Microsoft Sentinel is a separate SIEM product and is not a prerequisite for Audit (Premium).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Unified audit log enabled in the Microsoft 365 Defender portal

    Why this is correct

    Microsoft Purview's auditing capabilities, including Audit (Standard) and Audit (Premium), fundamentally rely on the Unified Audit Log (UAL). The UAL captures a comprehensive record of user and administrator activities across various Microsoft 365 services, making it essential for forensic investigations, compliance, and regulatory adherence. Without the UAL enabled, Purview cannot collect the necessary activity data to provide audit insights or support eDiscovery.

  • ✓

    An E5 or A5 license for each user

    Why this is correct

    Many advanced features within Microsoft Purview, particularly Audit (Premium), Advanced eDiscovery, and Communication Compliance, necessitate an E5 or A5 license for each user whose data or activities are being governed. While some basic Purview features are available with lower-tier licenses, the comprehensive compliance and governance capabilities that define Purview's full potential are unlocked by these premium subscriptions. These licenses provide the necessary entitlements for long-term audit retention, intelligent insights, and automated policy enforcement.

  • ✗

    An Azure subscription for log storage

    Why it's wrong here

    Microsoft 365 audit logs, including those collected by the Unified Audit Log for Purview, are primarily stored within the Microsoft 365 compliance boundary, not directly in a customer's dedicated Azure subscription for general log storage. While some advanced scenarios might involve exporting logs to Azure Monitor or Azure Storage for long-term retention or SIEM integration, a standalone Azure subscription specifically for storing these core audit logs is not a prerequisite for Purview's operation. The service manages its own log infrastructure.

  • ✗

    Power BI Pro licenses for all users

    Why it's wrong here

    Power BI Pro licenses are required for users who need to create, share, and consume advanced interactive reports and dashboards using Microsoft Power BI. While Power BI can be used to visualize data exported from Microsoft Purview (e.g., audit logs or compliance reports), it is not a foundational requirement for Purview itself to function or for its core auditing capabilities. Purview's compliance features operate independently of Power BI for data collection and policy enforcement.

  • ✗

    Microsoft Sentinel enabled

    Why it's wrong here

    Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides centralized security analytics across an enterprise. While Sentinel can ingest data from Microsoft Purview (such as audit logs or alerts) for consolidated security monitoring and incident response, it is an optional integration for advanced security operations, not a mandatory component for Purview to operate its compliance and governance functions. Purview can function fully without Sentinel enabled.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.