MS-900 Describe Microsoft 365 apps and services Practice Question
A company uses Microsoft 365 and wants to ensure that sensitive customer data in emails and documents is automatically classified and protected based on content. Which service should they implement?
⚠ Common exam trap
Microsoft often tests the distinction between Microsoft Purview Information Protection (content classification and labeling) and Microsoft Defender for Cloud Apps (cloud app security and DLP), leading candidates to mistakenly choose Defender for Cloud Apps because they associate 'protection' with security monitoring rather than content-based classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Information Protection
Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides automated classification, labeling, and protection of sensitive data based on content inspection, such as credit card numbers or social security numbers, using trainable classifiers and sensitivity labels. This directly addresses the requirement to automatically classify and protect sensitive customer data in emails and documents within Microsoft 365.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID is fundamentally an identity and access management (IAM) service that provides authentication, single sign-on, and conditional access policies. While it can enforce access controls based on user context, it does not inspect or classify the content of files or emails. Data classification requires analyzing the actual data payload, which is outside Entra ID's scope.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based endpoint management and mobile application management (MAM) solution. It manages device compliance, configuration profiles, and app protection policies, but these controls operate at the device or app level, not on the content within files. Intune cannot identify sensitive information like credit card numbers or apply persistent labels to documents.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that focuses on threat detection, shadow IT discovery, and session controls for SaaS applications. While it can apply conditional access policies and block risky activities, its primary function is not content inspection or automatic classification based on sensitive data patterns. It lacks the native sensitivity labeling engine found in Purview Information Protection.
- ✓
Microsoft Purview Information Protection
Why this is correct
Microsoft Purview Information Protection is the correct service because it provides sensitivity labels that can be applied automatically based on sensitive info types, trainable classifiers, and machine-learning models. These labels classify data in SharePoint, OneDrive, Exchange, and endpoints, and then enforce protection actions like encryption or access restrictions. This directly addresses the requirement to ensure sensitive data is identified and protected, making it the appropriate choice.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.