Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A company is deploying Microsoft 365 and needs to ensure that external sharing of sensitive documents is blocked. Which Microsoft Purview feature should they configure?

⚠ Common exam trap

MS-900 often tests the confusion between sensitivity labels (classification/protection) and DLP (enforcement/blocking), tempting candidates to pick labels when the requirement is to block sharing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention (DLP) policies

Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect and block sensitive information (credit cards, SSNs, custom sensitive types) from being shared externally across Exchange, SharePoint, OneDrive, and Teams. DLP can enforce actions like blocking external sharing, encrypting content, or notifying users, which directly addresses the requirement to prevent external sharing of sensitive documents.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data Loss Prevention (DLP) policies

    Why this is correct

    DLP policies inspect content and apply protective actions when sensitive information is detected, including blocking external sharing in SharePoint, OneDrive and Exchange. This directly satisfies the stem's constraint: preventing sensitive documents from leaving the tenant. Sensitivity labels classify and protect, but enforcement of sharing blocks relies on DLP rule conditions and actions.

  • ✗

    Sensitivity labels

    Why it's wrong here

    Sensitivity labels classify and protect content with encryption and markings, but on their own they do not block external sharing; that requires a DLP policy acting on the label. Labels are the right choice when the requirement is persistent classification and protection of documents themselves.

  • ✗

    Information Barriers

    Why it's wrong here

    Information Barriers restrict communication and collaboration between defined internal user segments, such as preventing a research group from contacting a trading group. They cannot block sharing with external recipients; a DLP policy is required to detect sensitive content and prevent it leaving the tenant.

  • ✗

    Retention policies

    Why it's wrong here

    Retention policies govern how long content is kept and when it is deleted, not who may access it externally. They are tempting because they do control document lifecycle, but blocking external sharing requires a data loss prevention policy that detects sensitive information and restricts sharing outside the tenant.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.