MS-900 Describe Microsoft 365 apps and services Practice Question
A company needs to ensure that sensitive documents stored in SharePoint Online are automatically encrypted and cannot be shared with external users. Which Microsoft Purview feature should they use?
⚠ Common exam trap
Many exam-takers confuse DLP policies with sensitivity labels, assuming DLP can both detect and encrypt content, but DLP only monitors and blocks sharing actions—it does not apply persistent encryption to the files themselves.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels
Sensitivity labels are the correct choice because they enforce encryption and access restrictions directly on documents, including blocking external sharing. Unlike DLP policies, which detect and prevent sharing after the fact, sensitivity labels apply persistent protection that travels with the file, ensuring it remains encrypted even if downloaded or shared outside SharePoint Online.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Communication compliance
Why it's wrong here
Communication compliance is an insider risk solution in Microsoft 365 that uses machine learning to scan emails, Teams messages, and Yammer discussions for policy violations such as harassment, offensive language, or improper disclosure of sensitive data. It can alert administrators to potential leaks, but it does not classify, encrypt, or restrict access to documents stored in libraries or file shares. The feature is detective and communication-focused, not a mechanism for document-level protection. Therefore, it cannot ensure that sensitive stored documents are encrypted or access-controlled.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
Data Loss Prevention (DLP) policies inspect content in transit and at rest to detect sensitive information like credit card numbers or personally identifiable information, and can take actions such as blocking external sharing or displaying policy tips. However, DLP does not automatically apply encryption to files; its primary controls are reactive sharing restrictions, not persistent protection embedded in the document. A file that is not actively being shared remains unprotected, and DLP lacks the ability to assign downstream permissions for access. Thus, DLP is a detective and preventive control for data leakage, not a classification-and-encryption solution.
- ✗
Retention labels
Why it's wrong here
Retention labels in Microsoft 365 are designed to govern data lifecycle, allowing organizations to define how long content must be kept and whether it should be subject to disposition review or deletion. They do not apply encryption, restrict access permissions, or prevent external sharing—retention labels focus on data availability and compliance, not confidentiality. Applying a retention label to a sensitive document leaves the file's encryption and access settings unchanged. Therefore, they are unsuitable for ensuring that sensitive documents are encrypted and access-restricted.
- ✓
Sensitivity labels
Why this is correct
Sensitivity labels are the correct solution because they enable persistent protection by applying encryption, permissions, and visual markings to documents and emails, and these protections travel with the file even when it is shared externally. Labels can be assigned manually, automatically based on content matching, or through recommended patterns, and they integrate with Azure Information Protection and Rights Management to enforce read-only, edit, or no-access permissions. Once applied, the document is encrypted and access is restricted according to the label's policy, directly satisfying the requirement to secure sensitive documents. This classification-based approach differs from reactive controls like DLP or communication compliance.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.