Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Your organization uses Microsoft Purview to manage insider risk. You need to create a policy that detects users who exfiltrate sensitive data by copying it to personal cloud storage services like Dropbox. Which solution should you use?

⚠ Common exam trap

A common mix-up: candidates confuse Audit (Premium) with proactive detection, but Audit only provides logging after the fact, whereas Insider Risk Management offers real-time detection and alerting for risky behaviors like data exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Insider Risk Management

Insider Risk Management in Microsoft Purview is specifically designed to detect, investigate, and act on risky user activities, including the exfiltration of sensitive data to personal cloud storage services like Dropbox. It uses predefined or custom policies with indicators such as copying files to unauthorized cloud apps, which aligns directly with the requirement to detect data exfiltration to personal cloud storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • eDiscovery (Premium)

    Why it's wrong here

    eDiscovery (Premium) is primarily a legal and compliance tool designed for identifying, preserving, collecting, and reviewing electronic content in response to legal requests or investigations. While it can locate data, it operates retrospectively on existing content and is not engineered for real-time monitoring or proactive detection of ongoing data exfiltration attempts to personal cloud services.

  • Audit (Premium)

    Why it's wrong here

    Audit (Premium) provides detailed logging of user and admin activities across Microsoft 365 services, offering forensic capabilities to investigate security incidents or compliance breaches post-event. Although it records actions that could indicate exfiltration, it functions as a historical record and lacks the real-time behavioral analytics and policy enforcement mechanisms necessary for proactive detection and management of insider risks.

  • Insider Risk Management

    Why this is correct

    Insider Risk Management in Microsoft Purview is specifically designed to identify, analyze, and act on potential insider risks, including data exfiltration to unauthorized locations like personal cloud services. It leverages machine learning and customizable policies to detect risky activities based on behavioral indicators, enabling organizations to proactively address potential data loss before it escalates into a major incident.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance focuses on detecting and preventing policy violations within an organization's internal and external communications, such as harassment, inappropriate content, or regulatory non-compliance. While it monitors message content, its primary function is not to track or prevent the unauthorized movement of sensitive files or data exfiltration to external storage services, making it unsuitable for this specific scenario.

Go deeper

Related to this question

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.