Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A company must comply with a regulation that requires all data stored in Microsoft 365 to remain within the European Union. Which Microsoft 365 feature should an administrator configure to enforce this geographic restriction?

⚠ Common exam trap

Test-takers frequently confuse Data Residency policies with Data Loss Prevention (DLP) or Information Rights Management (IRM), mistakenly thinking those features control data location rather than focusing on data protection or access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Residency policies

Data Residency policies in Microsoft 365 allow administrators to define the geographic location where data at rest is stored. By configuring a Data Residency policy for the European Union, the administrator ensures that all data remains within EU data centers, meeting regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention (DLP) policies in Microsoft Purview inspect content for sensitive data types and apply actions such as blocking sharing, encrypting, or warning users. DLP can restrict where data may be sent or shared to external domains, but it does not control the physical or geopolitical location of data at rest in Microsoft 365 datacenters. Since the regulation mandates where all data must be stored, DLP cannot satisfy that residency requirement.

  • Information Rights Management (IRM)

    Why it's wrong here

    Information Rights Management (IRM) uses Azure Rights Management to encrypt documents and emails and enforce usage restrictions like preventing printing, forwarding, or copying. These rights are embedded in the file and follow the data wherever it goes, but they do not influence which datacenter or region stores the data at rest. IRM protects against unauthorized use, not data residency, so it is not the correct tool for this regulatory constraint.

  • Data Residency policies

    Why this is correct

    Data Residency policies are designed specifically to ensure customer data is stored at rest within a defined geographic region. In Microsoft 365, administrators can leverage features like Multi-Geo in Exchange Online, SharePoint, and OneDrive to provision storage in specific datacenters, or rely on regional commitments such as the EU Data Boundary. These policies directly enforce where data resides, meeting regulatory requirements for storage location, making this the correct answer.

  • Customer Lockbox

    Why it's wrong here

    Customer Lockbox provides an approval control gate before Microsoft support or engineering can access customer content to resolve a service incident. While it strengthens data privacy and access governance, it has no bearing on the geographic location where data is stored at rest. Lockbox neither moves data nor enforces a residency boundary, so it cannot satisfy a regulation requiring data to be kept within a specific jurisdiction.

About these practice questions

One of 217 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.