Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A compliance team needs to implement a Data Loss Prevention (DLP) policy to protect credit card information. What is the correct order of steps for a successful implementation?

⚠ Common exam trap

MS-900 often tests the misconception that policy creation comes first — candidates must remember that discovery/identification of sensitive data locations is the necessary first step before scoping and deploying DLP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify locations, Create policy, Deploy in production, Monitor alerts and refine

A successful DLP implementation starts with discovery: identifying where sensitive data such as credit card numbers actually resides across email, SharePoint, OneDrive, and endpoints. Only after locations are known can a policy be scoped correctly, deployed in production (often after a test/simulation mode), and then monitored and refined based on alerts and false positives. This order prevents blind deployment and reduces business disruption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create policy, Identify locations, Deploy in production, Monitor alerts and refine

    Why it's wrong here

    Creating the DLP policy before identifying where sensitive data lives is a classic 'form over substance' pitfall. In Microsoft Purview, DLP policies must be scoped to specific locations such as Exchange, SharePoint, OneDrive, or endpoint devices, and the rules must reference applicable sensitive information types. If you define the policy first, you risk omitting repositories that actually contain regulated data, leading to coverage gaps and false confidence. Discover first, then design the policy to match reality.

  • ✓

    Identify locations, Create policy, Deploy in production, Monitor alerts and refine

    Why this is correct

    This is the correct sequence because it mirrors a mature data governance lifecycle. Start by using Microsoft Purview's Content Explorer or data classification capabilities to map where sensitive data resides. Then create a DLP policy in test mode, targeting those locations and defining rules and actions, before deploying in production. Finally, monitor Activity Explorer and refine the policy based on real incidents—ensuring continuous alignment with evolving compliance requirements.

  • ✗

    Deploy in production, Monitor alerts and refine, Identify locations, Create policy

    Why it's wrong here

    Deploying a DLP policy in production before the policy even exists is operationally nonsensical—there is no rule set to enforce, and the deployment step would have nothing to configure on your chosen locations. Monitoring alerts at this stage would either produce nothing (if no policy is attached) or produce false signals from any default policies, giving you meaningless telemetry. Identifying locations afterward means your deployment was untargeted, and creating a policy only at the end leaves your compliance posture exposed during the entire process.

  • ✗

    Identify locations, Deploy in production, Create policy, Monitor alerts and refine

    Why it's wrong here

    While identifying locations is a good first step, jumping straight to production deployment without creating and testing the policy first is a logical impossibility. In the Microsoft 365 DLP workflow, you must author the policy, configure rules (e.g., sensitive info types, conditions, actions like block or restrict access), and run it in test mode to validate behavior before you can meaningfully deploy it. Deploying before policy creation means there is no policy to deploy, and creating the policy after deployment inverts the dependency, making the production state unmanaged and non-compliant.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.