MS-900 Describe Microsoft 365 apps and services Practice Question
A financial services company uses Microsoft 365 E5 and wants to implement a data loss prevention (DLP) policy that blocks users from sharing credit card numbers via email and Teams messages. The compliance team also wants to generate reports on policy violations. They are considering using Microsoft Purview. Which approach should they take to meet these requirements with minimum administrative overhead?
⚠ Common exam trap
MS-900 often tests the misconception that DLP must be configured separately per workload (Exchange vs Teams), when Microsoft Purview provides a single unified policy engine across Microsoft 365 workloads.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a unified DLP policy in the Microsoft Purview compliance portal that covers Exchange and Teams.
A unified DLP policy in Microsoft Purview covers Exchange Online, Teams, SharePoint, and OneDrive from a single policy definition, so credit card numbers (a built-in sensitive information type) can be blocked across both email and Teams chat with one configuration. This minimizes administrative overhead because there is no need to duplicate rules across separate admin centers, and violation reports are consolidated in the Purview compliance portal.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create separate DLP policies in Exchange admin center and Teams admin center.
Why it's wrong here
Separate policies in each admin centre duplicate rule definitions and reporting, so credit card detection must be maintained twice and violations reviewed in two portals. A single Microsoft Purview DLP policy covers Exchange, Teams and other workloads with unified reporting, meeting the minimum-overhead requirement.
- ✓
Create a unified DLP policy in the Microsoft Purview compliance portal that covers Exchange and Teams.
Why this is correct
A single unified DLP policy in Microsoft Purview applies across Exchange and Teams, blocking credit card numbers in both and generating violation reports. This meets both requirements with minimum administrative overhead, avoiding separate per-workload policies.
- ✗
Use Microsoft Sentinel to create analytics rules that detect sharing of credit card numbers.
Why it's wrong here
Sentinel analytics rules detect and alert on events after they occur; they cannot block a user from sending credit card numbers in email or Teams. Sentinel is correct for SIEM correlation and incident investigation across log sources, not for inline prevention or Purview DLP violation reporting.
- ✗
Use Microsoft Defender for Cloud Apps to create session policies for email and Teams.
Why it's wrong here
Session policies in Defender for Cloud Apps govern access to cloud apps via Conditional Access App Control, requiring traffic proxying and per-app configuration; they do not natively evaluate credit card numbers in Exchange and Teams messages nor produce Purview DLP violation reports. It suits controlling unsanctioned SaaS usage, not in-tenant DLP enforcement.
Go deeper
Related to this question
Learn chapter
SharePoint Online and OneDrive
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.