SC-900 Data Lifecycle Management Practice Question
You are a compliance administrator for Contoso, a multinational company that uses Microsoft 365. The company has the following requirements: 1. Automatically retain all documents containing personally identifiable information (PII) for 7 years. 2. Prevent users from sharing PII via email with external recipients unless they provide a business justification. 3. Monitor and alert when users access sensitive data outside of business hours. 4. Generate a compliance score for GDPR and ISO 27001. You need to configure the appropriate Microsoft Purview solutions. For each requirement, match the correct solution. Which combination of solutions should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Lifecycle Management for retention; DLP for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
Requirement 1 (retain PII for 7 years) is met by a retention label or policy from Data Lifecycle Management (not Information Protection, which is for classification). Requirement 2 (prevent sharing without justification) is met by a Data Loss Prevention (DLP) policy that can block sharing and require user override with business justification. Requirement 3 (monitor access outside business hours) is met by Insider Risk Management, which can detect anomalous access patterns. Requirement 4 (compliance score) is met by Compliance Manager. Option A is wrong because Information Protection labels are for classification, not retention; also monitoring access outside hours needs Insider Risk Management, not DLP. Option B is wrong because Communication Compliance is for monitoring communications, not for preventing sharing via email; DLP is needed for that. Option D is wrong because eDiscovery is for legal discovery, not for access monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Information Protection for retention; DLP for sharing; Data Lifecycle Management for monitoring; Compliance Manager for scoring
Why it's wrong here
Information Protection does not handle retention; Data Lifecycle Management does not monitor access.
- ✗
Data Lifecycle Management for retention; Communication Compliance for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
Why it's wrong here
Communication Compliance is for communications, not DLP.
- ✓
Data Lifecycle Management for retention; DLP for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
Why this is correct
Each component maps to one requirement: Data Lifecycle Management applies retention labels for the 7-year PII hold; DLP blocks external email sharing with justification override; Insider Risk Management detects out-of-hours access; Compliance Manager scores GDPR and ISO 27001 posture.
- ✗
Information Protection for retention; eDiscovery for sharing; Insider Risk Management for monitoring; Compliance Manager for scoring
Why it's wrong here
Information Protection does not handle retention; eDiscovery is not for sharing prevention.
Go deeper
Related to this question
Learn chapter
Compliance Frameworks: ISO 27001, NIST, SOC 2
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
Key term
ISO 27001
ISO 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.