SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Your organization uses Microsoft Purview Audit to investigate a security incident. You need to search for activities performed by a specific user over the past 90 days. Which solution should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Audit (Standard)
Microsoft Purview Audit (Standard) provides 90-day retention for audit logs, which meets the requirement to search for user activities over the past 90 days. Option B (Audit Premium) offers longer retention but is not necessary for this 90-day search. Option C (Microsoft Defender XDR Advanced Hunting) is used for advanced threat hunting, not for auditing user activities. Option D (eDiscovery Standard) is designed for legal and compliance searches, not for routine audit log searches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Audit (Standard)
Why this is correct
Microsoft Purview Audit (Standard) is the appropriate service for general investigations requiring access to audit logs. It provides a default retention period of 90 days for most audited activities, which directly supports the requirement for a 90-day search. This service captures user and admin activities across various Microsoft 365 services, making it the foundational tool for compliance and forensic analysis within that timeframe.
- ✗
Microsoft Purview Audit (Premium)
Why it's wrong here
Microsoft Purview Audit (Premium) offers enhanced auditing capabilities, including longer retention periods of up to 10 years and access to critical high-value events like MailItemsAccessed. While it provides more extensive data, it is an unnecessary and over-provisioned solution if the investigation only requires audit logs for a 90-day period. Standard auditing already covers this specific retention requirement without the additional licensing cost and complexity of Premium features.
- ✗
Microsoft Defender XDR Advanced Hunting
Why it's wrong here
Microsoft Defender XDR Advanced Hunting is primarily designed for proactive security threat hunting and incident response across endpoint, identity, email, and cloud applications. It leverages Kusto Query Language (KQL) to query raw security signals and detect sophisticated threats, rather than serving as a general compliance audit log search tool. Its focus is on identifying malicious activity and vulnerabilities, not on routine compliance investigations of user and admin actions within Microsoft 365 services.
- ✗
Microsoft Purview eDiscovery (Standard)
Why it's wrong here
Microsoft Purview eDiscovery (Standard) is a specialized tool used for identifying, preserving, collecting, and managing electronic content for legal cases or internal investigations requiring specific holds. It is designed for managing the entire eDiscovery workflow, including placing legal holds and exporting data for review, rather than providing direct, general-purpose search functionality for raw audit logs. While it can leverage audit data, its primary function is case management and legal preservation, not a direct audit log search.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.