mediummultiple choiceObjective-mapped

A compliance team needs to ensure that any email sent from the Finance department that contains a bank account number is automatically encrypted. External recipients must be able to reply securely without needing to sign up for any service. Which Microsoft Purview solution should they configure?

Question 1mediummultiple choice
Full question →

A compliance team needs to ensure that any email sent from the Finance department that contains a bank account number is automatically encrypted. External recipients must be able to reply securely without needing to sign up for any service. Which Microsoft Purview solution should they configure?

Answer choices

Why each option matters

Good practice is not just finding the correct option. The wrong answers often show the exact trap the exam wants you to fall into.

A

Distractor review

Microsoft Purview Data Loss Prevention (DLP)

DLP can detect sensitive data and apply actions like blocking or notifying, but to automatically encrypt the email, DLP uses an action that invokes Message Encryption. Message Encryption is the underlying technology that encrypts the email.

B

Best answer

Microsoft Purview Message Encryption

Message Encryption allows sending encrypted emails to any recipient and supports secure reply without separate sign-up. It can be triggered automatically by a DLP policy when sensitive data is detected.

C

Distractor review

Microsoft Purview Information Protection (sensitivity labels)

Sensitivity labels can be applied manually or automatically to emails, but they rely on the recipient's ability to read protected messages. Message Encryption is specifically designed for sending encrypted emails to external users without requiring them to have Microsoft Entra ID accounts.

D

Distractor review

Microsoft Defender for Office 365

Defender for Office 365 provides anti-phishing, anti-malware, and safe attachments, but does not directly provide email encryption capabilities.

Common exam trap

Common exam trap: answer the scenario, not the keyword

Many certification questions include familiar terms but test a specific constraint. Read the exact wording before choosing an answer that is generally true but wrong for this case.

Technical deep dive

How to think about this question

This question should be treated as a scenario, not a definition check. Identify the problem, the constraint and the best action. Then compare each option against those facts.

KKey Concepts to Remember

  • Read the scenario before looking for a memorised answer.
  • Find the constraint that changes the correct option.
  • Eliminate answers that are true in general but not in this case.
  • Use explanations to understand the rule behind the answer.

TExam Day Tips

  • Underline the problem statement mentally.
  • Watch for words such as best, first, most likely and least administrative effort.
  • Review why wrong options are wrong, not only why the correct option is correct.

Related practice questions

Related MS-900 practice-question pages

Use these pages to review the topic behind this question. This is how one missed question becomes focused revision.

More questions from this exam

Keep practising from the same exam bank, or move into a focused topic page if this question exposed a weak area.

FAQ

Questions learners often ask

What does this MS-900 question test?

Read the scenario before looking for a memorised answer.

What is the correct answer to this question?

The correct answer is: Microsoft Purview Message Encryption — Microsoft Purview Message Encryption allows organizations to send encrypted emails to any recipient. It supports 'encrypt-only' and 'forward' rights, and recipients can reply encrypted without additional accounts. DLP policies can trigger automatic encryption, but the core encryption capability is Message Encryption. Azure Information Protection is for persistent protection, but for email encryption specifically, Message Encryption is the term used in M365 compliance. Sensitivity labels can also apply encryption, but the scenario describes automatic encryption triggered by content (bank account numbers) which is best achieved by a DLP policy that applies Message Encryption. However, the most direct answer is Microsoft Purview Message Encryption because it is the feature that provides the encryption and the reply-back capability.

What should I do if I get this MS-900 question wrong?

Then try more questions from the same exam bank and focus on understanding why the wrong options are tempting.

Discussion

Loading comments…

Sign in to join the discussion.