SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Which TWO of the following are required to use Microsoft Purview Audit (Premium)?
⚠ Common exam trap
Candidates often assume an Azure subscription or additional services like Sentinel are required for premium auditing, when in fact the only prerequisites are the unified audit log being enabled and an E5/A5 license per user.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unified audit log enabled in the Microsoft 365 Defender portal
Option A is correct because Microsoft Purview Audit (Premium) builds on the unified audit log, so auditing must first be turned on in the Microsoft 365 Defender portal (or via Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true) before premium features such as longer retention and high-value events can be captured. Option B is correct because Audit (Premium) capabilities are licensed through Microsoft 365 E5/A5 (or the E5/A5 Compliance add-on) assigned to each user whose premium audit data is generated. Option C is not required because audit records are stored in Microsoft's service, not in a customer Azure subscription. Option D is not required because Power BI Pro is unrelated to audit ingestion or retention. Option E is not required because Microsoft Sentinel is a separate SIEM product and is not a prerequisite for Audit (Premium).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Unified audit log enabled in the Microsoft 365 Defender portal
Why this is correct
Microsoft Purview's auditing capabilities, including Audit (Standard) and Audit (Premium), fundamentally rely on the Unified Audit Log (UAL). The UAL captures a comprehensive record of user and administrator activities across various Microsoft 365 services, making it essential for forensic investigations, compliance, and regulatory adherence. Without the UAL enabled, Purview cannot collect the necessary activity data to provide audit insights or support eDiscovery.
- ✓
An E5 or A5 license for each user
Why this is correct
Many advanced features within Microsoft Purview, particularly Audit (Premium), Advanced eDiscovery, and Communication Compliance, necessitate an E5 or A5 license for each user whose data or activities are being governed. While some basic Purview features are available with lower-tier licenses, the comprehensive compliance and governance capabilities that define Purview's full potential are unlocked by these premium subscriptions. These licenses provide the necessary entitlements for long-term audit retention, intelligent insights, and automated policy enforcement.
- ✗
An Azure subscription for log storage
Why it's wrong here
Microsoft 365 audit logs, including those collected by the Unified Audit Log for Purview, are primarily stored within the Microsoft 365 compliance boundary, not directly in a customer's dedicated Azure subscription for general log storage. While some advanced scenarios might involve exporting logs to Azure Monitor or Azure Storage for long-term retention or SIEM integration, a standalone Azure subscription specifically for storing these core audit logs is not a prerequisite for Purview's operation. The service manages its own log infrastructure.
- ✗
Power BI Pro licenses for all users
Why it's wrong here
Power BI Pro licenses are required for users who need to create, share, and consume advanced interactive reports and dashboards using Microsoft Power BI. While Power BI can be used to visualize data exported from Microsoft Purview (e.g., audit logs or compliance reports), it is not a foundational requirement for Purview itself to function or for its core auditing capabilities. Purview's compliance features operate independently of Power BI for data collection and policy enforcement.
- ✗
Microsoft Sentinel enabled
Why it's wrong here
Microsoft Sentinel is a cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides centralized security analytics across an enterprise. While Sentinel can ingest data from Microsoft Purview (such as audit logs or alerts) for consolidated security monitoring and incident response, it is an optional integration for advanced security operations, not a mandatory component for Purview to operate its compliance and governance functions. Purview can function fully without Sentinel enabled.
Go deeper
Related to this question
Learn chapter
eDiscovery Standard vs Premium
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.