Describe security, compliance, privacy, and trust in Microsoft 365 →hardMultiple ChoiceObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A global company needs to ensure that only employees in the 'HR' security group can access a specific set of HR documents stored in SharePoint. If a user outside the group attempts to view or copy the content, it must be blocked. The protection must persist even if someone downloads the files and shares them externally, or if the files are saved to a personal device. Which Microsoft Purview solution should be used?
⚠ Common exam trap
A common mix-up: candidates confuse DLP policies (which only monitor and block sharing at the transport layer) with sensitivity labels (which provide persistent encryption and access control that stays with the file), leading them to choose DLP when the question explicitly requires protection that persists after download or external sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels with encryption and permission settings
Sensitivity labels with encryption and permission settings are the correct solution because they allow you to apply persistent protection that travels with the file, regardless of where it is stored or shared. By configuring a sensitivity label to restrict access to only members of the 'HR' security group and enabling encryption, the protection remains intact even if the file is downloaded, saved to a personal device, or shared externally. This meets the requirement for persistent access control that blocks unauthorized viewing or copying.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Loss Prevention (DLP) policy
Why it's wrong here
DLP policies scan and govern the flow of sensitive data by applying rules that block, quarantine, or notify when data is shared—but they do not encrypt the underlying file. If a user is permitted to download or share a file, the DLP policy has no persistent effect on that file after it leaves the cloud service. Thus, once the file lands on a device or external storage, any sensitive content becomes readable by anyone without further restrictions.
- ✓
Sensitivity labels with encryption and permission settings
Why this is correct
Sensitivity labels, when configured with encryption, use Azure Information Protection (AIP) to encrypt the file content and apply usage rights based on the authenticated identity. The encryption is embedded into the file itself, so the protection persists everywhere—whether the file is downloaded, attached to email, or saved to a USB drive. By setting the permission to require the HR group, only their Entra ID accounts gain the rights to decrypt and read the file, making this the only option that enforces persistent, identity-based access control.
- ✗
Microsoft Entra ID Conditional Access
Why it's wrong here
Microsoft Entra ID Conditional Access is a policy layer that governs sign-in and session access to cloud applications based on conditions like device compliance, IP location, or risk signals. It operates as a gate in front of the app, but it does not alter the file itself. After a legitimate user with the necessary permissions downloads the file, Conditional Access has no further control over that file, so anyone with access to the downloaded copy can open it without any encryption or permission enforcement.
- ✗
Microsoft Defender for Cloud Apps session policy
Why it's wrong here
Microsoft Defender for Cloud Apps session policies, delivered through Conditional Access App Control, monitor and control user activity within a cloud app session—for example, screening downloads or blocking printing. These restrictions are applied in real time to the browser or client session and are not written into the file. If the file is later removed from that session (e.g., downloaded and then detached externally), the session policy no longer applies, leaving the file unprotected and without any persistent rights management.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
One of 217 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.