Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Your organization wants to audit all activities related to accessing sensitive files in Microsoft SharePoint. Which Microsoft Purview solution should you use?

⚠ Common exam trap

Many candidates confuse Data Loss Prevention (DLP) with auditing, because DLP also monitors sensitive files, but DLP focuses on preventing data exfiltration rather than providing a retrospective audit trail of all access activities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Audit (Premium)

Audit (Premium) in Microsoft Purview provides detailed logging of user and admin activities, including granular events like file access, modification, and permission changes in SharePoint. This solution enables organizations to investigate and audit all activities related to sensitive files by capturing and retaining audit records with high-volume event support and custom alerting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Audit (Premium)

    Why this is correct

    Microsoft Purview Audit (Premium) provides advanced auditing capabilities, including extended retention of audit logs (up to 10 years), intelligent insights, and access to high-value audit events crucial for forensic investigations. It captures a comprehensive record of user and admin activities across Microsoft 365 services, enabling organizations to track who accessed what, when, and from where, which is essential for security and compliance audits.

  • Data lifecycle management

    Why it's wrong here

    Data lifecycle management governs retention and deletion policies for content, not access activity auditing. It is tempting because it manages SharePoint files, but the requirement is to audit *who accessed* sensitive files, which demands the audit log and alerting capabilities of Microsoft Purview Audit (Standard or Premium). Data lifecycle management would be correct if the scenario required automatically deleting sensitive files after a compliance period.

  • Information barriers

    Why it's wrong here

    Information barriers are a compliance solution in Microsoft 365 designed to prevent specific groups of users from communicating or collaborating with each other, such as segregating traders from research analysts. While crucial for preventing conflicts of interest and regulatory compliance, information barriers do not provide any logging or auditing of user activities or access to files; their function is purely preventative.

  • Data loss prevention

    Why it's wrong here

    Data loss prevention (DLP) policies are designed to identify, monitor, and protect sensitive information across Microsoft 365 services by preventing its unauthorized sharing or transmission. DLP can detect sensitive data in emails, documents, and chats, then block or warn users based on policy rules. However, DLP's primary function is data protection and prevention, not comprehensive auditing of all user activities or access patterns, although it can generate alerts when a policy is matched.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.