20+ practice questions focused on Describe security, compliance, privacy, and trust in Microsoft 365 — one of the most tested topics on the Microsoft 365 Fundamentals MS-900 exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Describe security, compliance, privacy, and trust in Microsoft 365 PracticeAn organization is concerned about data leakage from sensitive emails. They want to enforce encryption on emails containing financial information automatically. Which Microsoft 365 solution should they configure?
Explanation: Microsoft Purview Message Encryption (Option B) is the correct solution because it enables organizations to send and receive encrypted email messages, and it can be configured with mail flow rules to automatically encrypt emails containing sensitive financial information. This service leverages Azure Rights Management (Azure RMS) to provide persistent protection that follows the email, ensuring only authorized recipients can decrypt and read the content.
A company needs to ensure that all email and document content is preserved for legal purposes, even if users permanently delete items. This requirement demands that content be kept indefinitely until the legal hold is released. Which Microsoft 365 feature should they enable?
Explanation: eDiscovery allows you to place an eDiscovery hold on all content locations, including Exchange mailboxes and SharePoint/OneDrive sites, preserving all items indefinitely until the hold is removed. Litigation hold is limited to mailboxes. Retention policies can also preserve content but are not specifically designed for legal hold with manual release.
A healthcare organization must protect patient health information (PHI) from being accidentally shared externally via email. They need to automatically block emails containing medical record numbers from being sent outside the organization and also encrypt any email that does contain PHI when it is allowed. Which two Microsoft Purview solutions should they combine? (Choose two.)
Explanation: Microsoft Purview Data Loss Prevention (DLP) detects sensitive data such as medical record numbers and can apply actions to block external transmission when needed. For cases where PHI is allowed to be sent, DLP can enforce encryption by integrating with Microsoft Purview Message Encryption, which secures the email for external recipients. Therefore, both DLP and Message Encryption are required: DLP for detection and policy enforcement, and Message Encryption for the actual encryption of allowed emails.
A company wants to ensure that only IT administrators can install browser extensions in Microsoft Edge. Which Microsoft 365 security feature should be used?
Explanation: Microsoft Intune is the correct choice because it provides mobile device management (MDM) and mobile application management (MAM) capabilities that allow administrators to configure Microsoft Edge settings via configuration profiles. Specifically, Intune can enforce the 'Installation of browser extensions' policy to restrict extension installation to IT administrators only, using the Administrative Templates for Edge within the Settings Catalog.
A compliance officer wants to ensure that all data in Microsoft 365 is encrypted using a key that the organization manages and stores in their own Azure Key Vault. Microsoft will not have access to the key. Which solution should they implement?
Explanation: Double Key Encryption (DKE) protects specific files using two keys: one in Azure Key Vault and one managed by Microsoft. It is not a tenant-wide encryption solution. For encrypting all Microsoft 365 data with a key that Microsoft cannot access, Microsoft 365 Customer Key is the appropriate feature, but it is not among the options.
+15 more Describe security, compliance, privacy, and trust in Microsoft 365 questions available
Practice all Describe security, compliance, privacy, and trust in Microsoft 365 questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Describe security, compliance, privacy, and trust in Microsoft 365. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Describe security, compliance, privacy, and trust in Microsoft 365 questions on the MS-900 frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Describe security, compliance, privacy, and trust in Microsoft 365 is tested as part of the Microsoft 365 Fundamentals MS-900 blueprint. Practicing with targeted Describe security, compliance, privacy, and trust in Microsoft 365 questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free MS-900 practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Describe security, compliance, privacy, and trust in Microsoft 365 is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Describe security, compliance, privacy, and trust in Microsoft 365 practice session with instant scoring and detailed explanations.
Start Describe security, compliance, privacy, and trust in Microsoft 365 Practice →