SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Your company uses Microsoft Purview to manage records. You need to ensure that financial records are retained for 7 years and then permanently deleted. Which type of policy should you create?
⚠ Common exam trap
Many exam-takers confuse a retention label with a retention policy, thinking a label is required for deletion, but a retention policy can enforce deletion at the container level without needing a label or human review.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A retention policy with a retention period of 7 years and then delete
A retention policy with a retention period of 7 years and then delete is correct because it applies a time-based retention rule to financial records at the container or folder level, ensuring they are kept for exactly 7 years and then permanently removed without human intervention. This meets the requirement for automatic deletion after the retention period, as opposed to a disposition review which requires manual approval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A retention policy with a retention period of 7 years and then delete
Why this is correct
A retention policy with a retention period of 7 years and then delete is the correct solution because retention policies are designed to automatically apply retention and deletion actions across entire locations, such as SharePoint sites or Exchange mailboxes. This policy ensures that content is retained for the specified 7 years and then permanently deleted without requiring any manual intervention, directly fulfilling the requirement for automatic disposition.
- ✗
A sensitivity label set to 'Financial' with auto-labeling
Why it's wrong here
Sensitivity labels control classification and protection through encryption or visual markings, not retention or deletion schedules. This scenario requires a retention policy or retention label to enforce a 7-year lifecycle with permanent deletion, which sensitivity labels cannot trigger. The option is tempting because auto-labeling can apply a 'Financial' label based on sensitive content, making it seem like a records management tool, but it would be correct only for classifying documents or applying access restrictions, not for automated disposition.
- ✗
A retention label that triggers a disposition review after 7 years
Why it's wrong here
A retention label that triggers a disposition review after 7 years is incorrect because, while retention labels define a retention period, triggering a disposition review introduces a mandatory manual step. After the 7-year period, a designated reviewer would need to approve the deletion of the content, preventing the fully automatic deletion required by the scenario. This option provides granular control but sacrifices automation for human oversight.
- ✗
A DLP policy that blocks sharing of financial records
Why it's wrong here
A DLP policy that blocks sharing of financial records is incorrect because Data Loss Prevention (DLP) policies are fundamentally designed to prevent sensitive information from being inappropriately shared, transferred, or accessed. DLP policies focus on data protection and compliance with data handling rules, not on managing the lifecycle of records, such as their retention period or automatic deletion after a set time. Therefore, a DLP policy cannot fulfill the requirement for automatic content disposition.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Retention policy
A retention policy is a set of rules that determines how long an organization keeps its data and what happens to it when the retention period expires.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.