Describe security, compliance, privacy, and trust in Microsoft 365 →mediumMultiple ChoiceObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A compliance team needs to prevent employees from copying sensitive data (such as financial records or customer PII) to USB drives and other removable media from their Windows 10/11 devices. When a user attempts to copy data to an unapproved USB device, the action should be blocked and an alert should be generated. Which Microsoft Purview solution should they configure?
⚠ Common exam trap
Watch out — candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking copy to USB), but sensitivity labels alone cannot block endpoint-level copy actions without DLP device policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention (DLP) with device policies
Microsoft Purview Data Loss Prevention (DLP) with device policies is the correct solution because it is specifically designed to monitor and control actions like copying sensitive data to removable media on Windows 10/11 endpoints. DLP device policies can block the copy action to unapproved USB devices and generate alerts when a policy violation occurs, directly addressing the compliance team's requirement to prevent data exfiltration via USB drives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Data Lifecycle Management (retention policies)
Why it's wrong here
Retention policies in Microsoft Purview Data Lifecycle Management govern the duration data is kept and the deletion schedule, typically for regulatory or archival compliance. They do not inspect or intercept user actions like copying files to removable media because they operate on data at rest within the tenant rather than on endpoints. Therefore, this option fails to satisfy the real-time prevention requirement.
- ✗
Microsoft Purview Information Protection (sensitivity labels)
Why it's wrong here
Sensitivity labels from Microsoft Purview Information Protection classify and encrypt data to control access and usage rights, such as preventing forwarding in email or restricting editing in Office apps. However, they do not directly block copying an already-labeled file to a USB drive unless integrated with endpoint controls like DLP, as labels lack the ability to enforce file system-level actions. The label identifies sensitivity but cannot independently provide a hard block on device operations.
- ✓
Microsoft Purview Data Loss Prevention (DLP) with device policies
Why this is correct
Endpoint DLP policies in Microsoft Purview Data Loss Prevention are purpose-built to monitor and block risky activities on devices, including copying sensitive data to removable storage such as USB drives. By leveraging configurable sensitive information types, these policies enforce real-time restrictions, display user notifications, and trigger security alerts when violations occur, directly addressing the compliance team's objective to prevent copying.
- ✗
Microsoft Purview eDiscovery (Standard or Premium)
Why it's wrong here
eDiscovery (Standard or Premium) serves legal investigations by allowing admins to search, preserve, and export content from Exchange, SharePoint, OneDrive, and Teams to meet litigation or regulatory obligations. It does not include preventative controls or real-time monitoring of endpoint user actions; instead, it operates after content exists and is subject to review, making it irrelevant for stopping active copy attempts to removable media.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
Alert
An alert is a notification that something unusual or potentially harmful has happened in a computer system or network.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.