Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A global company needs to ensure that only employees in the 'HR' security group can access a specific set of HR documents stored in SharePoint. If a user outside the group attempts to view or copy the content, it must be blocked. The protection must persist even if someone downloads the files and shares them externally, or if the files are saved to a personal device. Which Microsoft Purview solution should be used?

⚠ Common exam trap

A common mix-up: candidates confuse DLP policies (which only monitor and block sharing at the transport layer) with sensitivity labels (which provide persistent encryption and access control that stays with the file), leading them to choose DLP when the question explicitly requires protection that persists after download or external sharing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sensitivity labels with encryption and permission settings

Sensitivity labels with encryption and permission settings are the correct solution because they allow you to apply persistent protection that travels with the file, regardless of where it is stored or shared. By configuring a sensitivity label to restrict access to only members of the 'HR' security group and enabling encryption, the protection remains intact even if the file is downloaded, saved to a personal device, or shared externally. This meets the requirement for persistent access control that blocks unauthorized viewing or copying.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP) policy

    Why it's wrong here

    DLP policies scan and govern the flow of sensitive data by applying rules that block, quarantine, or notify when data is shared—but they do not encrypt the underlying file. If a user is permitted to download or share a file, the DLP policy has no persistent effect on that file after it leaves the cloud service. Thus, once the file lands on a device or external storage, any sensitive content becomes readable by anyone without further restrictions.

  • Sensitivity labels with encryption and permission settings

    Why this is correct

    Sensitivity labels, when configured with encryption, use Azure Information Protection (AIP) to encrypt the file content and apply usage rights based on the authenticated identity. The encryption is embedded into the file itself, so the protection persists everywhere—whether the file is downloaded, attached to email, or saved to a USB drive. By setting the permission to require the HR group, only their Entra ID accounts gain the rights to decrypt and read the file, making this the only option that enforces persistent, identity-based access control.

  • Microsoft Entra ID Conditional Access

    Why it's wrong here

    Microsoft Entra ID Conditional Access is a policy layer that governs sign-in and session access to cloud applications based on conditions like device compliance, IP location, or risk signals. It operates as a gate in front of the app, but it does not alter the file itself. After a legitimate user with the necessary permissions downloads the file, Conditional Access has no further control over that file, so anyone with access to the downloaded copy can open it without any encryption or permission enforcement.

  • Microsoft Defender for Cloud Apps session policy

    Why it's wrong here

    Microsoft Defender for Cloud Apps session policies, delivered through Conditional Access App Control, monitor and control user activity within a cloud app session—for example, screening downloads or blocking printing. These restrictions are applied in real time to the browser or client session and are not written into the file. If the file is later removed from that session (e.g., downloaded and then detached externally), the session policy no longer applies, leaving the file unprotected and without any persistent rights management.

About these practice questions

One of 217 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.