Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A compliance officer needs to automatically classify and protect documents stored in SharePoint Online that contain personal data such as passport numbers. The classification should happen without user intervention and must apply encryption and access restrictions. Which Microsoft Purview solution should be configured?

⚠ Common exam trap

Many exam-takers confuse DLP policies with auto-labeling, but DLP only monitors and blocks sharing actions, while auto-labeling applies persistent protection (encryption and access restrictions) directly to the document content.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sensitivity labels with auto-labeling

Sensitivity labels with auto-labeling (Option B) are the correct solution because they can automatically classify documents based on patterns like passport numbers using trainable classifiers or exact data match (EDM), and then apply encryption and access restrictions via the label's protection settings—all without user intervention. This meets the compliance officer's requirement for automatic classification and protection of personal data in SharePoint Online.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data Loss Prevention (DLP) policy

    Why it's wrong here

    Data Loss Prevention (DLP) policies are reactive controls that inspect content in email, Teams, or SharePoint against sensitive information types and block or restrict sharing when a rule matches. They do not persistently label documents or apply encryption; DLP actions are transient and focus on preventing data exfiltration, not on classifying or protecting the content itself. While DLP can be configured to reference sensitivity labels, the policy engine is not the mechanism that assigns those labels or manages their encryption.

  • ✓

    Sensitivity labels with auto-labeling

    Why this is correct

    Auto-labeling policies in Microsoft Purview use a classification engine to scan documents and emails for sensitive data types (e.g., credit card numbers, PII) and automatically attach a sensitivity label to each item. The label itself carries protection actions such as encryption via Azure Rights Management, access restrictions, and visual markings, making it the correct tool for automatic classification and protection. Auto-labeling can run client-side in Office apps or service-side across SharePoint, OneDrive, and Exchange, ensuring persistent, metadata-based security controls are applied without user interaction.

  • ✗

    eDiscovery (Standard)

    Why it's wrong here

    eDiscovery (Standard) is a compliance workflow designed for legal and investigative processes: it provides preservation holds, content search, and export capabilities across Exchange, SharePoint, OneDrive, and Teams. It does not modify content—it neither adds labels nor encrypts files—and it cannot be scheduled to scan repositories for sensitive data and apply protections. Its purpose is to discover and produce evidence, not to implement forward-looking data governance or automatic classification.

  • ✗

    Communication Compliance

    Why it's wrong here

    Communication Compliance monitors employee communications—such as Teams messages, Yahoo mail, or LinkedIn—to detect policy violations like harassment, threats, or unauthorized sharing of confidential information. It uses machine learning and partial matching to flag messages for review, but it does not parse or classify documents at rest in SharePoint or OneDrive, nor does it apply encryption or sensitivity labels to files. It is a supervisory control for human interactions, not a data classification and protection engine for stored content.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.