SC-900 - Microsoft Compliance Solutions (22% of the exam) - Section 4.2

Describe the compliance management capabilities of Microsoft Purview.

Describe the Microsoft Purview portal as the unified interface for accessing compliance tools, and explain how Compliance Manager translates regulatory requirements into actionable improvement actions. Use the compliance score to track progress, prioritise controls, and communicate risk posture to stakeholders.

Microsoft Purview portalCompliance Managercompliance score

Practice question for this objective

Free sampleMicrosoft Compliance Solutionsmedium

A governance lead is rolling out Microsoft Purview Compliance Manager and wants to describe what Compliance Manager actually does for the organisation. Which TWO statements correctly describe Compliance Manager? Select TWO.

  • AIt hosts the downloadable third-party audit reports for Microsoft cloud services
  • BIt applies sensitivity labels to documents to encrypt them as they travel
  • CIt translates regulatory requirements into recommended improvement actions to work through Correct
  • DIt preserves mailbox content under legal hold for an active investigation
  • EIt calculates a compliance score that reflects progress on those recommended actions Correct
Compliance Manager maps regulatory requirements to improvement actions and produces a compliance score measuring progress against those actions. Compliance Manager exists to operationalise regulations: it breaks them into improvement actions and tracks a compliance score as those actions complete. Audit reports, labelling, and legal holds are separate capabilities in the Service Trust Portal, information protection, and eDiscovery respectively.

Why A is wrong: Audit reports are published on the Service Trust Portal, not generated inside Compliance Manager, so this swaps the two tools.

Why B is wrong: Label-based encryption is an information protection capability, unrelated to Compliance Manager's assessment role.

Why C is correct: Compliance Manager maps controls from regulations onto concrete improvement actions the organisation can complete.

Why D is wrong: Legal hold is an eDiscovery function; Compliance Manager assesses controls and does not place holds.

Why E is correct: Compliance Manager produces a risk-based compliance score that rises as recommended actions are completed.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Compliance Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • In Compliance Manager, the solution that holds assessments, controls, and improvement actions.

    Why it is wrong: Compliance Manager handles assessments and improvement actions; the grounding states Privacy Risk Management moved to the Microsoft Priva portal, not into Compliance Manager.

  • Data Loss Prevention, which detects and helps block the sharing of sensitive information.

    Why it is wrong: Data Loss Prevention restricts sensitive-data sharing; it does not supply the assessment-progress posture cards the grounding ties to Compliance Manager.

  • It replaces the need for Microsoft Entra ID to authenticate the administrators who sign in

    Why it is wrong: Sign-in still relies on Entra ID for identity; the portal is a management surface, not an identity provider.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.