SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
You are designing a compliance solution for a global company. You need to ensure that data stored in SharePoint Online is not accessible from a specific geographic region. Which Microsoft Purview feature should you use?
⚠ Common exam trap
The trap is that candidates often mistakenly believe Compliance boundaries can control data access by location, when in fact they are limited to eDiscovery and audit scoping. For geographic access restrictions, you would need Conditional Access (Entra ID) or Multi-Geo, which are not Purview features.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance boundaries
This question is problematic because no Microsoft Purview feature listed directly restricts SharePoint Online data access based on geographic region. Compliance boundaries (A) are for eDiscovery scoping, not access control. Data loss prevention policies (B) prevent data loss but do not block access by region. Retention policies (C) manage data lifecycle, not access. Sensitivity labels (D) classify and protect data but cannot enforce geographic restrictions on their own. For this requirement, you would use a non-Purview feature such as Conditional Access in Microsoft Entra ID or Multi-Geo capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compliance boundaries
Why this is correct
Compliance boundaries are used to define eDiscovery and audit scoping, not to restrict data access based on geographic region. They do not block access from a specific region.
- ✗
Data loss prevention policy
Why it's wrong here
Data loss prevention policies help prevent unauthorized sharing of sensitive data, but they do not restrict direct access to SharePoint Online content by geographic location.
- ✗
Retention policy
Why it's wrong here
Retention policies control how long data is kept or when it is deleted, but they do not influence access based on geographic region.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels apply classification and protection settings, but they cannot restrict access solely based on geographic region. Conditional Access would be needed for that.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.