SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
You are the compliance administrator for a retail company that uses Microsoft 365 Business Premium. The company needs to: - Block customers' credit card numbers from being sent via email. - Retain all sales invoices for 3 years as per financial regulations. - Allow managers to search and export employee emails for HR investigations. - Ensure that only HR can access employee salary information. Which Microsoft Purview solutions should you use?
⚠ Common exam trap
Many candidates confuse Information Barriers (which restrict communication between groups) with DLP (which blocks sensitive data patterns), or assume Insider Risk Management or Communication Compliance can replace DLP for proactive blocking of credit card numbers in email.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DLP, Data Lifecycle Management, eDiscovery, and sensitivity labels
DLP (Data Loss Prevention) blocks credit card numbers from being sent via email, Data Lifecycle Management retains sales invoices for 3 years, eDiscovery allows managers to search and export employee emails for HR investigations, and sensitivity labels restrict access to salary information to HR only. Each requirement maps directly to a specific Purview solution: DLP for sensitive data protection, retention policies for compliance, eDiscovery for legal/HR investigations, and sensitivity labels for access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DLP, Information Barriers, eDiscovery, and sensitivity labels
Why it's wrong here
This option is incorrect because Information Barriers are designed to prevent specific groups of users from communicating with each other, which does not address data retention requirements. While DLP, eDiscovery, and sensitivity labels are crucial for data protection, legal holds, and classification, the solution lacks a component like Data Lifecycle Management to define and enforce retention and disposition policies for the company's data. Therefore, it fails to meet a fundamental compliance need for managing data over its lifecycle.
- ✓
DLP, Data Lifecycle Management, eDiscovery, and sensitivity labels
Why this is correct
This combination correctly addresses all implied compliance requirements. Data Loss Prevention (DLP) is essential for blocking the sharing of sensitive information like credit card numbers. Data Lifecycle Management (DLM) provides the necessary capabilities for defining and enforcing retention and disposition policies, ensuring data is kept for the required duration and then appropriately deleted. eDiscovery enables the organization to efficiently search, preserve, and produce electronic information for legal or investigative purposes, while sensitivity labels allow for data classification and protection, applying encryption or access restrictions based on content.
- ✗
Insider Risk Management, Data Lifecycle Management, eDiscovery, and sensitivity labels
Why it's wrong here
This option is incorrect because it includes Insider Risk Management, which focuses on identifying and mitigating risky user activities and behaviors, rather than directly preventing the sharing of specific sensitive data types. The critical component missing is Data Loss Prevention (DLP), which is explicitly designed to detect and block the unauthorized sharing of sensitive information, such as credit card numbers, outside defined boundaries. Without DLP, the solution cannot proactively prevent the leakage of confidential data, failing a primary compliance objective.
- ✗
Communication Compliance, Data Lifecycle Management, eDiscovery, and sensitivity labels
Why it's wrong here
This option is incorrect because Communication Compliance primarily focuses on detecting and reviewing inappropriate or non-compliant communications within an organization, flagging content for review rather than actively blocking it. It does not provide the real-time enforcement capabilities needed to prevent the sharing of sensitive data like credit card numbers. The solution lacks Data Loss Prevention (DLP), which is specifically engineered to identify and block the transmission of sensitive information, making this choice inadequate for preventing data leakage.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
Data protection
Data protection refers to the practices and technologies used to safeguard personal and sensitive information from unauthorized access, loss, or corruption.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.