Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

You are the compliance administrator for a healthcare organization that must comply with HIPAA. You need to automatically detect and prevent patients' protected health information (PHI) from being shared via email. Additionally, you need to retain all emails containing PHI for 6 years. You also need to allow users to manually classify documents as 'Medical Record' with encryption that expires after 30 days. Which combination of Microsoft Purview solutions should you implement?

⚠ Common exam trap

SC-900 often tests the confusion between retention policies, retention labels, and eDiscovery, and between DLP (prevention) and communication compliance (monitoring), causing candidates to pick a combination that misses either prevention or the manual label requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention (DLP) policy to block PHI; retention policy for 6 years on emails containing PHI; sensitivity label with encryption and expiration

The correct combination is a DLP policy to detect and block PHI in email, a retention policy for 6 years on emails containing PHI, and a sensitivity label with encryption and expiration for manual classification. DLP handles prevention, retention handles the 6-year hold, and the sensitivity label provides user-driven classification with encryption that expires after 30 days.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data Loss Prevention (DLP) policy to block PHI; retention policy for 6 years on emails containing PHI; sensitivity label with encryption and expiration

    Why this is correct

    DLP blocks sharing; retention policy retains; sensitivity label provides manual classification with encryption and expiration.

  • ✗

    Data Loss Prevention (DLP) policy to block PHI; eDiscovery to retain emails; sensitivity label with encryption

    Why it's wrong here

    eDiscovery does not retain; it searches content.

  • ✗

    Retention label for 6 years; sensitivity label with encryption; communication compliance to monitor sharing

    Why it's wrong here

    Communication compliance does not prevent sharing; DLP is needed to block.

  • ✗

    Data Loss Prevention (DLP) policy to block PHI; auto-labeling policy to apply retention label; no manual label needed

    Why it's wrong here

    Auto-labeling for retention is possible, but manual label with expiration is also required per the scenario.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.