SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Your organization is implementing Microsoft 365 and needs to prevent sensitive data from being copied to USB drives. Which Microsoft Purview solution should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse Sensitivity labels with DLP, not realizing labels only classify and encrypt data but lack the endpoint-level enforcement to block physical device transfers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint data loss prevention (Endpoint DLP)
Endpoint DLP (Data Loss Prevention) monitors and controls actions users take on devices, such as copying sensitive data to USB drives. It enforces policies directly on Windows, macOS, and other endpoints to block unauthorized transfers, making it the correct solution for preventing data exfiltration via removable media.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit logs
Why it's wrong here
Audit logs provide forensic data and visibility into user and admin activities across Microsoft 365 services, recording events such as file access, policy changes, and communication activities. While crucial for compliance and security investigations, they are a reactive tool that records events *after* they occur. Audit logs do not possess the capability to actively prevent or block specific user actions, such as copying data to a USB drive, making them unsuitable for proactive data loss prevention.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance is designed to help organizations detect, capture, and act on inappropriate messages within internal and external communications, such as Microsoft Teams, Exchange email, and Yammer. Its primary function is to identify policy violations related to harassment, sensitive information sharing, or regulatory compliance within communication channels. It operates at the communication layer and has no functionality to monitor or block actions occurring directly on user endpoints, like data transfers to removable media.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels allow organizations to classify and protect sensitive data across documents and emails by applying encryption, visual markings, and access restrictions based on the data's sensitivity. While labels can trigger protective actions like encryption or restrict sharing, they primarily focus on the data itself and its inherent protection. They do not inherently provide the capability to directly block user actions on endpoints, such as preventing the copying of *any* data (labeled or not) to a USB drive, without integration with other DLP mechanisms.
- ✓
Endpoint data loss prevention (Endpoint DLP)
Why this is correct
Endpoint Data Loss Prevention (Endpoint DLP) extends DLP capabilities directly to Windows and macOS devices, enabling organizations to monitor and control sensitive information as it is used, shared, and transferred. It can detect when users attempt to copy sensitive data to removable media (like USB drives), network shares, cloud services, or print it, and then enforce policies to block, audit, or warn the user. This direct control over endpoint actions makes it the ideal solution for preventing data exfiltration via USB drives.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.