SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Which TWO of the following are valid uses for Microsoft Purview eDiscovery?
⚠ Common exam trap
Candidates often confuse eDiscovery's legal hold capability with retention policies, or mistakenly think eDiscovery includes classification or audit log review, because all are part of Microsoft Purview but serve distinct compliance roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Placing legal holds on content
Option A is correct because Microsoft Purview eDiscovery (Standard and Premium) supports creating holds, including Litigation Hold and eDiscovery Hold, to preserve mailbox and site content in place for legal or investigative purposes. Option E is correct because eDiscovery provides Content Search and search-and-collection tools that query Exchange mailboxes, SharePoint sites, OneDrive accounts, and Teams content using keyword, KQL, and condition-based queries. Option B is not an eDiscovery use; sensitivity labels are configured through Microsoft Purview Information Protection to classify and protect content, not to identify or preserve it for legal matters. Option C is not an eDiscovery use; reviewing audit logs is performed with Microsoft Purview Audit (Standard/Premium) via the unified audit log, not through eDiscovery cases. Option D is not an eDiscovery use; retention policies and retention labels are managed through Microsoft Purview Data Lifecycle Management to govern content lifecycle, whereas eDiscovery holds are case-scoped preservation mechanisms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Placing legal holds on content
Why this is correct
Microsoft Purview eDiscovery provides the functionality to place legal holds on content, ensuring that data relevant to litigation or investigations is preserved and cannot be altered or deleted. These holds are crucial for maintaining the integrity of electronically stored information (ESI) across various Microsoft 365 services, including Exchange mailboxes, SharePoint sites, and Teams. This capability prevents data spoliation, which is essential for regulatory compliance and legal proceedings.
- ✗
Classifying content with sensitivity labels
Why it's wrong here
Classifying content with sensitivity labels is a core function of Microsoft Purview Information Protection, not eDiscovery. While eDiscovery can *find* content that has been labeled during a search, it does not apply or manage these labels itself. Information Protection is responsible for defining, publishing, and automatically or manually applying sensitivity labels to classify and protect data based on its sensitivity level.
- ✗
Reviewing audit logs for user activity
Why it's wrong here
Reviewing audit logs for user activity is primarily a function of Microsoft Purview Audit, which captures and records user and admin activities across Microsoft 365 services. Although eDiscovery cases might leverage audit data to understand context around specific content or user actions, eDiscovery itself is not the primary tool for general audit log review. Purview Audit provides detailed logs for forensic investigations and compliance monitoring, distinct from eDiscovery's content preservation and search capabilities.
- ✗
Applying retention policies to prevent deletion
Why it's wrong here
Applying retention policies to prevent deletion is a capability of Microsoft Purview Data Lifecycle Management, which defines how long data should be kept or deleted according to organizational policies. While both retention policies and legal holds preserve data, they serve different purposes; retention policies are proactive organizational mandates, whereas legal holds are reactive, specific to legal or investigative matters. eDiscovery places specific, targeted legal holds rather than applying broad retention policies across an organization.
- ✓
Searching for content across mailboxes and sites
Why this is correct
Microsoft Purview eDiscovery is specifically designed to enable comprehensive searching for electronically stored information (ESI) across a wide array of Microsoft 365 data sources. This includes mailboxes, SharePoint Online sites, OneDrive for Business accounts, Microsoft Teams, and Yammer. Its advanced search capabilities allow legal and compliance teams to quickly identify and collect relevant content pertinent to investigations or legal cases by using keywords, conditions, and date ranges.
Go deeper
Related to this question
Learn chapter
Sensitivity Labels and Information Protection
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Audit log
An audit log is a chronological record of security-relevant events and user activities within a system, used for monitoring, compliance, and forensic analysis.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.