Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A global financial services firm needs to protect highly confidential documents containing trade secrets. The protection must restrict access to a specific group of employees, prevent editing and printing, and remain enforced even if the document is downloaded and saved to an external device. Which Microsoft Purview solution should be used?

⚠ Common exam trap

Candidates often confuse DLP policies with sensitivity labels, thinking DLP can protect files after download, but DLP only monitors and blocks at the point of sharing, not persistently encrypting the file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sensitivity labels (Azure Information Protection)

Sensitivity labels from Azure Information Protection (AIP) allow you to classify and protect documents with persistent protection that travels with the file, even when it is downloaded to an external device. By configuring a sensitivity label with encryption, you can restrict access to a specific group of employees, disable editing and printing, and enforce these restrictions regardless of where the file is stored. This meets all the requirements of the scenario, including persistent protection after download.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sensitivity labels (Azure Information Protection)

    Why this is correct

    Sensitivity labels are correct because they use Azure Rights Management (RMS) at the Microsoft Purview Information Protection layer to encrypt documents and assign granular usage rights, such as view, edit, copy, print, and forward permissions. These rights are embedded in the file itself, so the protection persists even if the document is saved to an external drive or shared with third parties. A global financial services firm specifically needs this persistent encryption and revocable access control to protect highly sensitive data after it leaves Microsoft 365.

  • ✗

    Data Loss Prevention (DLP) policy

    Why it's wrong here

    A DLP policy detects and blocks the flow of sensitive data (e.g., credit card numbers or bank account identifiers) across email, Teams, and endpoints by matching data-loss prevention rules at the boundary. However, DLP acts only at the moment of transmission or access; once a file is downloaded or legitimately shared, the policy no longer accompanies the file and cannot enforce encryption or restrict what the recipient does with it. Even when DLP is configured to apply a label, the actual persistent protection comes from sensitivity label infrastructure, not the DLP engine itself.

  • ✗

    Information Barriers

    Why it's wrong here

    Information Barriers in Microsoft Purview restrict communication and collaboration between defined user groups, commonly used in financial services to prevent conflicts of interest or insider trading between segments such as investment banking and research. This solution only controls which users can chat, call, or collaborate with each other inside platforms like Microsoft Teams and SharePoint; it does not encrypt files or limit how a single user can open, edit, or forward a document after access is granted. Therefore, it cannot provide the content-level protection the firm requires.

  • ✗

    Advanced Audit

    Why it's wrong here

    Advanced Audit is a Microsoft Purview logging feature that captures high-value auditing events, such as document access, downloads, permission changes, and admin activities, with extended retention options. While it is useful for forensic investigation and regulatory compliance reporting, it has no enforcement capability; it cannot prevent a file from being opened, copied, printed, or forwarded by an authorized user. Because it only records activities after they occur, Advanced Audit cannot proactively protect sensitive documents from unauthorized access.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.