MS-900 Describe Microsoft 365 apps and services Practice Question
A company uses Microsoft 365 E5 and wants to implement a zero-trust security model. They need to ensure that all external file sharing requires multi-factor authentication (MFA) and that sensitive documents are automatically labeled. Which combination of services should they use?
⚠ Common exam trap
Watch out — candidates often confuse Microsoft Defender for Cloud Apps (a CASB) with Entra Conditional Access for MFA enforcement, or assume Purview Data Lifecycle Management handles labeling instead of Information Protection, leading them to select options that address only one requirement or use the wrong service for the task.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra Conditional Access and Microsoft Purview Information Protection
Microsoft Entra Conditional Access can enforce MFA for external file sharing by requiring MFA as a condition for accessing SharePoint/OneDrive resources. Microsoft Purview Information Protection provides automatic sensitivity labeling for documents based on content or context, ensuring sensitive data is labeled without manual intervention. Together, these services directly address the zero-trust requirements of MFA for external sharing and automatic document labeling.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Defender XDR and Microsoft Purview Audit
Why it's wrong here
Microsoft Defender XDR focuses on detecting and responding to threats across endpoints, email, and identities, while Microsoft Purview Audit logs user and admin activities but does not apply sensitivity labels or enforce access policies. Together they provide visibility and post-incident forensics, yet they lack the conditional access engine needed to require MFA and the classification engine needed to automatically label files based on content. Thus, this combination would not meet the stated goal of enforcing MFA and auto-labeling sensitive content.
- ✗
Microsoft Intune and Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Intune is a unified endpoint management solution that controls device compliance and app protection, and Microsoft Defender for Cloud Apps acts as a Cloud Access Security Broker (CASB) that discovers shadow IT and applies session policies to cloud apps. Neither service natively enforces MFA at the authentication layer, and Defender for Cloud Apps, despite its data classification capabilities, relies on labels from other services rather than auto-labeling sensitive content itself. This pairing addresses device posture and cloud app governance but misses the core identity-level MFA enforcement and native labeling required by the scenario.
- ✗
Microsoft Defender for Cloud Apps and Microsoft Purview Data Lifecycle Management
Why it's wrong here
Microsoft Defender for Cloud Apps can enforce conditional access app control policies and block risky actions, but it does not automatically apply sensitivity labels; it typically consumes labels already present in Microsoft 365. Microsoft Purview Data Lifecycle Management focuses on retention, deletion, and disposition of content, not on classifying or labeling files at creation or edit time. Therefore, this combination is insufficient because it lacks the actual auto-labeling service (Microsoft Purview Information Protection) and the identity-based MFA enforcement that would come from Microsoft Entra Conditional Access.
- ✓
Microsoft Entra Conditional Access and Microsoft Purview Information Protection
Why this is correct
Microsoft Entra Conditional Access provides identity-driven policy enforcement, such as requiring MFA during sign-in based on user, location, device, or risk signals, which directly satisfies the MFA requirement. Microsoft Purview Information Protection automatically classifies emails and documents by applying sensitivity labels based on content detection and user-defined policies, thereby meeting the auto-labeling requirement. Together these two services form the correct combination: one governs access at the authentication boundary, the other governs data classification and protection at the content level.
Go deeper
Related to this question
Learn chapter
Microsoft Entra External Identities (B2B)
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
Key term
MFA
Multi-Factor Authentication (MFA) is a security method that requires a user to verify their identity using two or more different types of evidence, such as a password plus a code from a phone, before they can access an account or system.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.