MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A compliance team needs to implement a Data Loss Prevention (DLP) policy to protect credit card information. What is the correct order of steps for a successful implementation?
⚠ Common exam trap
MS-900 often tests the misconception that policy creation comes first — candidates must remember that discovery/identification of sensitive data locations is the necessary first step before scoping and deploying DLP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identify locations, Create policy, Deploy in production, Monitor alerts and refine
A successful DLP implementation starts with discovery: identifying where sensitive data such as credit card numbers actually resides across email, SharePoint, OneDrive, and endpoints. Only after locations are known can a policy be scoped correctly, deployed in production (often after a test/simulation mode), and then monitored and refined based on alerts and false positives. This order prevents blind deployment and reduces business disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create policy, Identify locations, Deploy in production, Monitor alerts and refine
Why it's wrong here
Creating the DLP policy before identifying where sensitive data lives is a classic 'form over substance' pitfall. In Microsoft Purview, DLP policies must be scoped to specific locations such as Exchange, SharePoint, OneDrive, or endpoint devices, and the rules must reference applicable sensitive information types. If you define the policy first, you risk omitting repositories that actually contain regulated data, leading to coverage gaps and false confidence. Discover first, then design the policy to match reality.
- ✓
Identify locations, Create policy, Deploy in production, Monitor alerts and refine
Why this is correct
This is the correct sequence because it mirrors a mature data governance lifecycle. Start by using Microsoft Purview's Content Explorer or data classification capabilities to map where sensitive data resides. Then create a DLP policy in test mode, targeting those locations and defining rules and actions, before deploying in production. Finally, monitor Activity Explorer and refine the policy based on real incidents—ensuring continuous alignment with evolving compliance requirements.
- ✗
Deploy in production, Monitor alerts and refine, Identify locations, Create policy
Why it's wrong here
Deploying a DLP policy in production before the policy even exists is operationally nonsensical—there is no rule set to enforce, and the deployment step would have nothing to configure on your chosen locations. Monitoring alerts at this stage would either produce nothing (if no policy is attached) or produce false signals from any default policies, giving you meaningless telemetry. Identifying locations afterward means your deployment was untargeted, and creating a policy only at the end leaves your compliance posture exposed during the entire process.
- ✗
Identify locations, Deploy in production, Create policy, Monitor alerts and refine
Why it's wrong here
While identifying locations is a good first step, jumping straight to production deployment without creating and testing the policy first is a logical impossibility. In the Microsoft 365 DLP workflow, you must author the policy, configure rules (e.g., sensitive info types, conditions, actions like block or restrict access), and run it in test mode to validate behavior before you can meaningfully deploy it. Deploying before policy creation means there is no policy to deploy, and creating the policy after deployment inverts the dependency, making the production state unmanaged and non-compliant.
Go deeper
Related to this question
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.