MS-102 Deploy and manage a Microsoft 365 tenant Practice Question
Your organization is deploying Microsoft 365 Copilot. You need to ensure that data security is maintained. Which THREE actions should you take?
⚠ Common exam trap
Candidates often assume blocking external sharing (Option B) is a primary security control for Copilot, when in fact Copilot's data security risks are more about internal data leakage through AI processing, which requires audit logging, DLP, and sensitivity labels to mitigate.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable audit logging in Microsoft 365.
Enabling audit logging in Microsoft 365 is essential for tracking user interactions with Microsoft 365 Copilot, including prompts, responses, and data access events. This provides a forensic trail to detect unauthorized data exposure or misuse, which is a foundational requirement for maintaining data security in AI-powered workloads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable Microsoft 365 Copilot for all users.
Why it's wrong here
Disabling Copilot tenant-wide removes the intended productivity benefit and does nothing to mitigate the underlying risk of data exposure. Copilot inherits the existing access control, so security should focus on auditing, classification, and loss prevention rather than service unavailability. A full feature off-switch is a blunt operational action, not a security control, and leaves no forensic trail for compliance.
- ✗
Block all external sharing for SharePoint and OneDrive.
Why it's wrong here
Blocking all external sharing for SharePoint and OneDrive is an overbroad availability control that prevents legitimate cross-tenant collaboration but fails to restrict what Copilot can infer or combine from internal content. Copilot does not respect external sharing block as a data protection boundary; it reasons over the content a user can already access. This action also provides no audit logging or policy enforcement, so sensitive data exposure through prompts could still go undetected.
- ✓
Enable audit logging in Microsoft 365.
Why this is correct
Enable audit logging in Microsoft 365 so that Copilot user prompts and responses, along with related file access events, are recorded in the unified audit log. This telemetry is essential for security teams to detect abnormal Copilot usage, investigate data exfiltration attempts, and produce evidence for compliance. Without audit logging, administrators lack the visibility needed to confirm whether Copilot is being used appropriately.
- ✓
Configure data loss prevention (DLP) policies.
Why this is correct
Configure DLP policies in Microsoft 365 to scan Copilot interactions for sensitive information types, such as credit card numbers or personally identifiable information, and automatically block access or trigger policy tips. DLP acts inline during Copilot prompt and response processing, preventing sensitive data from being shared or exposed via generated content. This complements sensitivity labels by adding content-level enforcement on top of classification.
- ✓
Create sensitivity labels to classify and protect data.
Why this is correct
Create sensitivity labels to classify and protect files so Copilot can enforce restrictions based on the label, such as encryption, rights permissions, and conditional access rules. When a user prompts Copilot, labels influence whether Copilot can access or summarize a document, and they also enable persistent protection on the data itself. This granular classification layer reduces the risk that Copilot uncovers data beyond the user's authorization.
Go deeper
Related to this question
Learn chapter
Audit Log Search and Retention
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.