SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Your organization is required to retain all HR-related documents for 7 years after an employee leaves. After that period, the documents must be permanently deleted. Which two Microsoft Purview features should you use together?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retention labels and retention policies
Retention labels and retention policies (option D) are the correct combination because retention labels can be applied to individual HR documents to trigger deletion 7 years after an event such as an employee's departure, while retention policies apply retention and deletion settings broadly across workloads. Together they ensure documents are kept for the required period and then permanently deleted. eDiscovery and audit logs (A) are for investigation and monitoring, not enforcement of retention/deletion. DLP policies and sensitivity labels (B), and sensitivity labels with auto-labeling (C), focus on classification and preventing data loss, not on time-based retention and deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
eDiscovery and audit logs
Why it's wrong here
eDiscovery tools, such as Microsoft Purview eDiscovery, are designed to identify, preserve, collect, and produce electronically stored information (ESI) for legal or investigative purposes. Audit logs record user and admin activities across Microsoft 365 services, providing an immutable record of actions taken. While both are crucial for compliance, they serve search and logging functions, not the proactive, long-term enforcement of data retention or deletion schedules.
- ✗
DLP policies and sensitivity labels
Why it's wrong here
Data Loss Prevention (DLP) policies are designed to identify, monitor, and protect sensitive information across various locations, preventing its unauthorized sharing or transfer outside the organization. Sensitivity labels classify data based on its sensitivity, applying protective actions like encryption or visual markings. While both are critical for data protection and governance, they do not inherently define or enforce how long data must be kept or when it should be disposed of according to regulatory requirements.
- ✗
Sensitivity labels and auto-labeling
Why it's wrong here
Sensitivity labels are used to classify data, applying protective actions such as encryption, access restrictions, or visual markings based on the content's sensitivity. Auto-labeling for sensitivity labels automates this classification process by identifying sensitive information types or keywords. However, the primary function of sensitivity labels, even when automatically applied, is data protection and classification, not the enforcement of specific retention periods or the scheduled disposition of content.
- ✓
Retention labels and retention policies
Why this is correct
Retention labels are applied directly to individual items like emails or documents, allowing for granular control over their retention and disposition based on content type or business function. Retention policies, conversely, are applied to entire locations such as Exchange mailboxes, SharePoint sites, or Teams channels, enforcing a baseline retention schedule for all content within that location. Together, these mechanisms ensure that data is retained for its required lifecycle and then appropriately disposed of, meeting regulatory and organizational compliance obligations.
Go deeper
Related to this question
Learn chapter
Content Explorer for Data Discovery
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.