Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

You are the compliance administrator for a healthcare organization that must comply with HIPAA. You need to automatically detect and prevent patients' protected health information (PHI) from being shared via email. Additionally, you need to retain all emails containing PHI for 6 years. You also need to allow users to manually classify documents as 'Medical Record' with encryption that expires after 30 days. Which combination of Microsoft Purview solutions should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Loss Prevention (DLP) policy to block PHI; retention policy for 6 years on emails containing PHI; sensitivity label with encryption and expiration

DLP policies detect and prevent sharing of PHI via email; a retention policy retains emails containing PHI for 6 years; a sensitivity label allows users to manually apply encryption with expiration. Option B is incorrect because eDiscovery is for search and export, not for retention; retention is handled by a retention policy, not eDiscovery. Option C is incorrect because communication compliance monitors for policy violations but does not prevent sharing; additionally, a retention label alone does not enforce retention (a retention policy or auto-apply label policy would be needed). Option D is incorrect because it lacks a manual label with encryption and expiration; auto-labeling can apply retention but not encryption with expiration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP) policy to block PHI; retention policy for 6 years on emails containing PHI; sensitivity label with encryption and expiration

    Why this is correct

    DLP blocks sharing; retention policy retains; sensitivity label provides manual classification with encryption and expiration.

  • Data Loss Prevention (DLP) policy to block PHI; eDiscovery to retain emails; sensitivity label with encryption

    Why it's wrong here

    eDiscovery does not retain; it searches content.

  • Retention label for 6 years; sensitivity label with encryption; communication compliance to monitor sharing

    Why it's wrong here

    Communication compliance does not prevent sharing; DLP is needed to block.

  • Data Loss Prevention (DLP) policy to block PHI; auto-labeling policy to apply retention label; no manual label needed

    Why it's wrong here

    Auto-labeling for retention is possible, but manual label with expiration is also required per the scenario.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.