Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A company uses Microsoft 365 and wants to automatically classify documents containing credit card numbers as 'Highly Confidential' and apply encryption when shared externally. Which solution should they use?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Defender for Cloud Apps (a CASB) with Purview's auto-labeling, assuming a CASB can classify and encrypt content natively, when in fact it only applies labels that are already defined and managed by Purview Information Protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection with auto-labeling

Microsoft Purview Information Protection with auto-labeling is the correct solution because it uses trainable classifiers or exact data match (EDM) to detect sensitive data types like credit card numbers, automatically apply a 'Highly Confidential' sensitivity label, and enforce encryption when the document is shared externally. This capability is built into Microsoft 365 compliance center and integrates with sensitivity labels to protect data at rest and in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is a cloud-based Enterprise Mobility Management service for managing mobile devices and apps. It enforces device compliance and app protection policies but does not inspect or classify content in Word documents or emails. Auto-labeling of sensitive data is outside Intune's purpose, making it unsuitable for this requirement.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a cloud-native SIEM/SOAR that collects security telemetry and detects threats across the enterprise. While Sentinel can ingest audit and label activity logs, its role is to analyze security events, not to scan or classify the content of individual files. It cannot natively apply sensitivity labels to documents or emails, so it is incorrect here.

  • ✓

    Microsoft Purview Information Protection with auto-labeling

    Why this is correct

    Microsoft Purview Information Protection with auto-labeling is the correct service for automatic classification. It uses sensitivity labels and service-side detection of sensitive info types to automatically apply labels to documents and emails stored in Exchange, SharePoint, and OneDrive. Administrators define policies that trigger on credit card numbers, driver's license IDs, or other data types, ensuring sensitive content is consistently protected.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps operates as a CASB, providing visibility, conditional access, and data loss prevention for cloud apps. It can control session-based activities and restrict access to risky applications, but it does not perform content-level classification of files at rest. Any labeling it supports would be through integration with Purview, making it a security gateway rather than a labeling engine.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.