SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Your organization uses Microsoft Purview to enforce retention policies. You need to retain all documents in a specific SharePoint site for 5 years after they are created, and then delete them permanently. What should you configure?
⚠ Common exam trap
SC-900 often tests the confusion between retention policies (location-scoped) and retention labels (item-scoped) — candidates pick labels thinking they're more precise, but the question's 'all documents in a site' phrasing points to a policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A retention policy set to retain for 5 years and then delete
A retention policy in Microsoft Purview is applied at the workload/location level (e.g., a specific SharePoint site) and can be configured to retain content for 5 years and then delete it. This matches the requirement of scoping retention to a site without relying on per-item labeling. Retention policies are the correct construct when you want location-based, automatic retention and deletion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A DLP policy with a retention rule
Why it's wrong here
DLP (Data Loss Prevention) policies in Microsoft Purview are specifically designed to identify, monitor, and protect sensitive information from being inappropriately shared, accessed, or transmitted outside organizational boundaries. While they can prevent data loss, they do not include "retention rules" as part of their core functionality. Their purpose is to enforce data protection controls, such as blocking sharing or encrypting content, rather than defining how long content should be retained or when it should be deleted within the organization's systems.
- ✓
A retention policy set to retain for 5 years and then delete
Why this is correct
A retention policy in Microsoft Purview is the correct mechanism for enforcing a consistent retention schedule across an entire location, such as a SharePoint site. By applying a retention policy to a SharePoint site, all content within that site will automatically inherit the specified retention period (e.g., retain for 5 years) and subsequent disposition action (e.g., then delete). This ensures comprehensive, site-wide compliance with data retention requirements without requiring individual item-level application.
- ✗
A retention label set to retain for 5 years and then delete
Why it's wrong here
A retention label alone is insufficient because it typically requires manual application to individual documents or an auto-apply policy based on content properties, rather than automatically enforcing retention on *all* documents within an entire SharePoint site. The scenario demands a blanket site-level policy. This option is tempting as labels define retention periods and are ideal for granular, item-level retention, allowing different documents within the same location to have distinct retention rules, or for user-driven content classification.
- ✗
A sensitivity label with a retention setting
Why it's wrong here
Sensitivity labels are primarily used for classifying and protecting sensitive content by applying visual markings, encryption, and access restrictions. Although a sensitivity label *can* be configured to include a retention setting, this retention is applied at the item level (e.g., to a specific document or email) when the label is published and applied. It is not designed to enforce a blanket retention schedule across *all* documents within an entire SharePoint site, which is the requirement implied by the scenario.
Go deeper
Related to this question
Learn chapter
Azure Policy for Compliance
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Retention policy
A retention policy is a set of rules that determines how long an organization keeps its data and what happens to it when the retention period expires.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.