MS-102 Manage compliance by using Microsoft Purview Practice Question
You are a compliance administrator for Contoso Ltd. The company uses Microsoft Purview Information Protection with sensitivity labels. A new regulation requires that all documents labeled 'Highly Confidential' must be encrypted and only accessible by members of the 'Legal' group, even when shared externally. You have published a label named 'Highly Confidential' with encryption settings. You need to ensure that the label enforces these requirements when applied to documents in Office apps. What should you configure in the label's encryption settings?
⚠ Common exam trap
The trap here is assuming that any permission assignment to the Legal group automatically excludes others, when in fact user-assigned permissions could allow broader access if not disabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign permissions to the 'Legal' group with 'Viewer' role, and clear the option 'Let users assign permissions'.
To enforce that only the Legal group can access documents labeled 'Highly Confidential', the encryption settings must assign permissions exclusively to that group and prevent users from changing those permissions. Assigning Viewer role limits access to read-only for Legal, and disabling user assignment ensures the label's protection cannot be overridden. This meets the regulatory requirement for encryption and access control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign permissions to the 'Legal' group with 'Viewer' role, and clear the option 'Let users assign permissions'.
Why this is correct
Assigning Viewer permissions to the Legal group ensures that only members of that group can read the content, and clearing 'Let users assign permissions' prevents users from altering the permissions when applying the label. This enforces the encryption and access restriction required by the regulation, ensuring that only Legal can access the documents.
- ✗
Assign permissions to the 'Legal' group with 'Viewer' role and set 'Do not forward' for the content.
Why it's wrong here
The 'Do not forward' option is a restriction that prevents forwarding, but it does not enforce encryption or limit access to a specific group. It is typically used in conjunction with encryption, but alone it does not meet the requirement. Encryption must be configured with explicit permissions to restrict access to the Legal group.
- ✗
Assign permissions to the 'Legal' group with 'Viewer' role and enable 'Let users assign permissions'.
Why it's wrong here
Enabling 'Let users assign permissions' allows users to change the permissions when they apply the label, which could let them grant access to unauthorized individuals. The requirement is to enforce that only the Legal group can access the content, so user overrides must be prevented. This setting would weaken the protection.
- ✗
Assign permissions to the 'Legal' group with 'Co-Author' role and set an expiration date for the content.
Why it's wrong here
Assigning Co-Author permissions to the Legal group grants them edit rights, but does not restrict access to only that group. Other users might still have access if they are granted permissions elsewhere. An expiration date controls how long the content is accessible, not who can access it. This does not meet the requirement of exclusive access for the Legal group.
Go deeper
Related to this question
Learn chapter
Intune and Conditional Access Integration
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.