MS-900 Microsoft Purview Message Encryption Practice Question
A compliance-aware administrator is selecting the right Microsoft 365 capability to encrypt email messages sent to internal or external recipients. Microsoft security, identity, or compliance capability should it use?
⚠ Common exam trap
The trap here is that candidates might confuse Microsoft Purview Message Encryption with other Microsoft 365 security features like Microsoft Defender for Office 365 or Azure Information Protection, but the question specifically asks for an email encryption capability, not a broader security or compliance tool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Message Encryption
Microsoft Purview Message Encryption (B) is the correct choice because it is the dedicated Microsoft 365 service that provides encryption for email messages sent to both internal and external recipients. It leverages Azure Rights Management (Azure RMS) to protect messages, ensuring only intended recipients can decrypt and read them, which directly meets the compliance requirement for email encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Stream
Why it's wrong here
Microsoft Stream hosts and shares internal video content; it never touches SMTP transport, so it cannot apply encryption to email sent to internal or external recipients. It is tempting because it is a Microsoft 365 service with sharing and permission controls, but it would be correct for publishing recorded meetings or training videos.
- ✓
Microsoft Purview Message Encryption
Why this is correct
Microsoft Purview Message Encryption applies encryption to email in transit, letting senders protect messages to internal or external recipients. It satisfies the compliance requirement by enforcing encryption at the message level without relying on recipient-side configuration.
- ✗
Microsoft Planner
Why it's wrong here
Microsoft Planner organises team tasks and plans; it has no mail-flow or encryption capability, so it cannot encrypt messages to internal or external recipients. It is tempting because it is a Microsoft 365 workload with assignment and access controls, but it would be correct for tracking project work, not for securing email.
- ✗
Microsoft Forms
Why it's wrong here
Microsoft Forms collects surveys and quizzes; it has no mail-flow transport rules or encryption engine, so it cannot encrypt messages to any recipient. It is tempting because it lives in Microsoft 365 and handles recipient-facing content, but it would be the right choice for gathering feedback or building a quiz, not for securing email.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.