Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

You are investigating a potential data leak. You need to find all emails that contain the word 'confidential' sent to external recipients in the last 30 days. Which Microsoft Purview tool should you use?

⚠ Common exam trap

The SC-900 exam often tests the distinction between proactive DLP policies (which prevent leaks) and reactive Content Search (which finds existing leaks), causing candidates to mistakenly choose DLP policy when the question asks for a tool to find already-sent emails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Content Search

Content Search (option C) is the correct tool because it allows you to perform targeted eDiscovery searches across Exchange Online mailboxes, including searching for specific keywords like 'confidential' and filtering by date range and recipient type (external recipients). It provides the exact capability to locate all emails containing the word 'confidential' sent to external recipients in the last 30 days, making it the appropriate choice for investigating a potential data leak.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance is primarily a policy-based solution for monitoring user communications within Microsoft 365 for compliance risks, such as harassment or sensitive information sharing. It relies on predefined policies and machine learning to identify potential violations and facilitate review workflows. While it helps manage communication risks, it is not designed as an ad-hoc search tool to directly locate specific content across all data sources during an active data leak investigation.

  • Audit Log Search

    Why it's wrong here

    Audit Log Search in Microsoft 365 provides detailed records of user and administrator activities across various services, such as who accessed a file, who sent an email, or who modified a setting. While crucial for forensic analysis to understand *what actions occurred* and *who performed them*, it does not capture or allow searching of the actual *content* of emails, documents, or messages. Therefore, it cannot be used to directly find instances of specific sensitive data that may have been leaked.

  • Content Search

    Why this is correct

    Content Search, accessible through the Microsoft Purview compliance portal, is specifically engineered for eDiscovery and investigative purposes, enabling comprehensive searches across diverse content locations. It allows investigators to pinpoint specific keywords, phrases, sensitive information types, or other properties within mailboxes, SharePoint sites, OneDrive accounts, and Microsoft Teams chats. This capability makes it the ideal tool for locating and collecting potentially leaked data across an organization's digital repositories during an investigation.

  • Data loss prevention (DLP) policy

    Why it's wrong here

    Data Loss Prevention (DLP) policies are proactive security controls designed to prevent sensitive information from being inappropriately shared, transferred, or exfiltrated from the organization. DLP policies detect and block or warn about potential data leaks in real-time based on predefined rules and sensitive information types. While DLP generates alerts when a policy is violated, it is a preventive and detection mechanism, not an investigative tool for retrospectively searching for specific content that may have already leaked or resides in various locations.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.