SC-900 - Microsoft Compliance Solutions (22% of the exam) - Section 4.4

Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview.

Describe insider risk management in Microsoft Purview as the capability that detects and acts on potentially harmful user activity without exposing unnecessary personal data. Distinguish eDiscovery solutions, which support legal hold and content search for litigation, from audit solutions, which provide a record of user and admin activity for forensic investigation.

insider risk managementeDiscovery solutionsaudit solutions

Practice question for this objective

Free sampleMicrosoft Compliance Solutionsmedium

A security and compliance team is sorting three Microsoft Purview solutions by purpose: insider risk management, eDiscovery, and audit. Which THREE statements correctly match each solution to what it does? Select THREE.

  • AInsider risk management detects and helps act on risky activity by an organisation's own users Correct
  • BAudit applies encryption and a watermark to sensitive documents as they are shared
  • CeDiscovery identifies, holds, and exports content that may serve as evidence in legal matters Correct
  • DeDiscovery calculates the organisation's compliance score from completed actions
  • EAudit provides a searchable record of user and administrator activity across services Correct
Insider risk management addresses internal user activity, eDiscovery preserves and exports legal evidence, and audit records user and admin activity for later search. Each solution owns a distinct job: insider risk watches internal behaviour, eDiscovery handles legal preservation and export, and audit keeps a searchable activity record. The distractors borrow capabilities from sensitivity labels and Compliance Manager, which sit outside all three.

Why A is correct: Insider risk management is purpose-built to surface and respond to malicious or inadvertent internal user activity.

Why B is wrong: Encryption and watermarking are sensitivity label functions; audit only records activity and protects nothing.

Why C is correct: eDiscovery preserves and produces electronically stored information for investigations and legal cases.

Why D is wrong: The compliance score is produced by Compliance Manager, not eDiscovery, which deals with legal content rather than scoring.

Why E is correct: Audit logs user and admin operations so teams can search them during security or compliance investigations.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Compliance Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Scoring internal users more aggressively when their role carries higher risk

    Why it is wrong: Aggressive scoring of high-risk users is an insider risk management construct, not part of eDiscovery.

  • The Microsoft Entra admin centre, the experience for managing users, groups, and sign-in access.

    Why it is wrong: The Entra admin centre manages identity and access; the grounding gives the unified data governance, protection, and compliance experience to the Microsoft Purview portal.

  • A Data leaks policy, which scores leak indicators after you define the policy conditions.

    Why it is wrong: A Data leaks policy must be created and configured before it scores activity, so it cannot give the pre-policy evaluation the grounding attributes to analytics.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.