Exam objective

SC-900

Describe insider risk, eDiscovery, and audit capabilities in Microsoft Purview

This objective sits in Describe capabilities of Microsoft compliance solutions, which carries 22% of the Security, Compliance, and Identity Fundamentals exam. The questions below are original, written from the official objective title above, and each explanation cites the Microsoft Azure page it rests on.

Objective title verbatim from the official objectives. Microsoft Azure exam page ↗

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Describe capabilities of Microsoft compliance solutions

An organization with Audit (Standard) needs to investigate mailbox activity from ten months ago. Why will the search fail?

Audit (Standard) keeps records for 180 daysCorrect · your answerCorrect.
Audit records are exported only to a SIEMResults can be exported to CSV; SIEM export is not the only path.
Audit (Standard) must be enabled firstAudit (Standard) is enabled by default for organizations with the appropriate subscription.
Audit logs cannot be searched by dateThe search lets you find specific activities, users and date ranges.

Correct.

Checked against learn.microsoft.com, September 2026

Concept

An audit log is only as useful as its retention window, and the baseline tier's window is shorter than many investigations need.

Why A

The source says Audit (Standard) retains records for 180 days, enough to search activities within roughly the past six months, while Audit (Premium) adds longer retention of audit records.

Source

180-day audit log retention. Audit (Standard) retains records for 180 days-enough to search for activities within approximately the past six months.

Describe Microsoft Purview Audit, checked September 2026
#audit#retention#scenario

Now you: practice questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Describe capabilities of Microsoft compliance solutions

In a Microsoft Purview eDiscovery case, an investigator adds search results to a review set. What happens to the collected items?

Sample question 2 of 3

Describe capabilities of Microsoft compliance solutions

A SOC analyst investigating a Defender XDR incident wants alert data about a possibly malicious insider's activities included in the incident story. Which Microsoft Purview capability supplies that signal to Defender XDR?

Sample question 3 of 3

Describe capabilities of Microsoft compliance solutions

Insider Risk Management is described as built with privacy by design. Which default supports that claim?

Full Security, Compliance, and Identity Fundamentals question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Describe capabilities of Microsoft compliance solutions