Describe security, compliance, privacy, and trust in Microsoft 365 →easyMultiple ChoiceObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A compliance officer needs to automatically retain all emails in Exchange Online for exactly 7 years, and then permanently delete them. Which Microsoft Purview solution should they configure?
⚠ Common exam trap
Many candidates confuse retention policies (which automate lifecycle management) with DLP policies (which prevent data leaks) or sensitivity labels (which classify data), leading them to select an option that addresses a different compliance goal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retention policy
A retention policy in Microsoft Purview is designed to retain data for a specified period and then automatically delete it. By configuring a retention policy with a retention period of 7 years and an action to permanently delete the content at the end of that period, the compliance officer can meet the requirement for Exchange Online emails. This policy applies at the mailbox level and ensures that all emails are retained for exactly 7 years before being irreversibly removed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Loss Prevention (DLP) policy
Why it's wrong here
Data Loss Prevention (DLP) policies in Microsoft Purview are reactive controls that inspect messages for sensitive information patterns (e.g., credit card numbers, PII) and enforce actions like blocking or warning users before transmission. They are not designed to manage data lifecycle; they lack any time-based retention or deletion schedule, so they cannot automatically retain emails for a compliance period. DLP might complement a retention strategy, but it does not fulfill the requirement of automatic time-based retention.
- ✓
Retention policy
Why this is correct
Retention policies in Microsoft Purview are the correct answer because they are purpose-built to automatically retain content for a specified duration and then optionally delete it, directly satisfying the compliance officer's need. You can apply a retention policy to Exchange mailboxes, and it works at the item level, ensuring every email is retained for the configured period. These policies support both adaptive and static scopes and can be set to keep items indefinitely or for a specific number of days, making them ideal for regulatory compliance.
- ✗
Sensitivity label
Why it's wrong here
Sensitivity labels are classification and protection tools that apply encryption, access restrictions, and visual markings to emails and documents, but they do not manage retention or deletion schedules. While a sensitivity label can be configured to trigger a retention label through auto-labeling, the sensitivity label itself has no built-in time-based lifecycle actions. Thus, it does not automatically retain all emails for a compliance period; that is a separate capability provided by retention labels or retention policies.
- ✗
eDiscovery case
Why it's wrong here
eDiscovery cases are used for legal investigations and allow you to search, preserve, and export content, but they are not a lifecycle management tool. When you place an eDiscovery hold on a mailbox, it preserves all content indefinitely until the hold is released, without any automatic deletion schedule. This is a temporary, case-specific preservation mechanism, not a policy for routine compliance retention, so it cannot automatically retain and then delete emails on a recurring schedule.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
Key term
Retention policy
A retention policy is a set of rules that determines how long an organization keeps its data and what happens to it when the retention period expires.
About these practice questions
This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.