MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A company is deploying Microsoft 365 and wants to ensure that customer financial data remains within the European Union. Which Microsoft 365 feature should the administrator configure?
⚠ Common exam trap
Test-takers frequently confuse data residency controls (Data Location settings) with data protection mechanisms like sensitivity labels or DLP, assuming any security feature can enforce geographic storage, but only Data Location settings directly control physical data storage regions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Data Location settings in the Microsoft 365 admin center.
The Data Location settings in the Microsoft 365 admin center allow administrators to specify the geographic region where data at rest is stored, including the European Union. This ensures compliance with data residency requirements by controlling where customer financial data is physically stored, leveraging Microsoft's commitment to data sovereignty within defined geo-boundaries.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply sensitivity labels using Microsoft Purview.
Why it's wrong here
Sensitivity labels in Microsoft Purview provide classification and protection through encryption, visual markings, and access restrictions. However, these controls act on the content itself and do not influence or change the geographic location where the underlying data is stored at rest. They are a data governance/security control, not an infrastructure placement setting, so they cannot satisfy a residency requirement.
- ✓
Configure Data Location settings in the Microsoft 365 admin center.
Why this is correct
Data Location settings are found in the Microsoft 365 admin center under Org settings, and they allow administrators to view and, with Multi-Geo, assign the geographic region where customer data at rest is stored for workloads like Exchange Online and SharePoint. Configuring these settings directly enforces data residency at rest by controlling the tenant's committed data location for core services. This is the only option that addresses storage location itself.
- ✗
Set up Conditional Access policies in Microsoft Entra ID.
Why it's wrong here
Conditional Access in Microsoft Entra ID is a policy engine that evaluates user, device, location, and risk signals during authentication to allow or block access to apps. It doesn't control infrastructure placement or the physical location of stored content, and even users with valid access tokens are still using data that may reside outside a required region. Thus it affects who can reach data, not where the data is kept.
- ✗
Implement Data Loss Prevention (DLP) policies.
Why it's wrong here
Data Loss Prevention policies in Microsoft Purview inspect content in motion and at rest for sensitive information types, and can block sharing, encrypt, or quarantine items to prevent leakage. They have no capability to move, create, or configure storage locations in a different geographic region. A DLP violation may stop sensitive data from leaving, but it cannot retroactively fix a tenant whose data is already stored in a non-compliant location.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Compliance
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Microsoft 365 admin center
The Microsoft 365 admin center is a web-based portal where IT administrators manage users, subscriptions, security, and settings for an organization's Microsoft 365 services.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.