Describe security, compliance, privacy, and trust in Microsoft 365 →hardMultiple ChoiceObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A compliance officer needs to ensure that all outgoing emails containing a customer's credit card number are automatically encrypted before delivery. External recipients must be able to reply with the same level of encryption without a separate signing-up process. Which Microsoft Purview solution should be configured?
⚠ Common exam trap
Watch out — candidates often confuse sensitivity labels (Option B) with DLP-based encryption, not realizing that sensitivity labels require explicit configuration for automatic encryption and do not inherently handle reply encryption without additional setup, whereas OME with DLP provides the seamless, policy-driven encryption and reply capability described.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Office 365 Message Encryption (OME) with a DLP policy
Office 365 Message Encryption (OME) with a Data Loss Prevention (DLP) policy is the correct solution because OME provides automatic encryption for emails based on sensitive information types (e.g., credit card numbers) detected by DLP rules. It also supports the 'encrypt-only' option, which allows external recipients to reply with the same level of encryption without requiring a separate sign-up or certificate exchange, leveraging the Microsoft 365 message encryption infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Office 365 Message Encryption (OME) with a DLP policy
Why this is correct
Office 365 Message Encryption (OME) integrated with a Data Loss Prevention (DLP) policy is the standard mechanism for automatically encrypting outgoing emails that contain sensitive data such as credit card numbers. The DLP policy scans outbound messages for specific sensitive info types and, when matched, conditionally modifies the message to apply OME encryption via Azure Rights Management. OME ensures external recipients receive an encrypted email and can authenticate via a secure web portal to read and reply, maintaining end-to-end confidentiality without requiring the recipient to have an M365 license.
- ✗
Sensitivity labels with automatic marking
Why it's wrong here
Sensitivity labels with automatic marking allow emails to be classified based on content, but the automatic marking action alone does not guarantee encryption; while a label can configure encryption through Azure RMS, this is a separate configuration from the DLP-triggered OME workflow. For the stated requirement of automatically encrypting all outbound emails containing credit card numbers, the appropriate control is a DLP policy that invokes OME, not label auto-classification, which is primarily for manual or co-authoring scenarios.
- ✗
Azure Information Protection (AIP)
Why it's wrong here
Azure Information Protection (AIP) is the legacy classification and labeling technology that underlies sensitivity labels, but it is not the operational policy engine that detects and reacts to credit card numbers in outbound mail. AIP requires a license and is now largely consolidated into Microsoft 365 sensitivity labels, and while it can encrypt files and emails via Rights Management, it does not natively scan message bodies and attachments for specific data patterns the way a DLP policy does. Thus, AIP alone is insufficient and not the recommended approach for this compliance requirement.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 provides security threat protection such as anti-phishing, anti-malware, safe links, and safe attachments, but it does not include a native mechanism to encrypt outgoing messages based on content compliance. Even though its Advanced Delivery and filtering can integrate with DLP, the actual encryption action is performed by OME, not by Defender. Therefore, enabling Defender alone does not satisfy the requirement to encrypt outgoing emails containing sensitive credit card numbers.
Go deeper
Related to this question
Learn chapter
Cloud Service Types for MS-900
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
One of 217 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.