MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A global financial services firm needs to protect highly confidential documents containing trade secrets. The protection must restrict access to a specific group of employees, prevent editing and printing, and remain enforced even if the document is downloaded and saved to an external device. Which Microsoft Purview solution should be used?
⚠ Common exam trap
Candidates often confuse DLP policies with sensitivity labels, thinking DLP can protect files after download, but DLP only monitors and blocks at the point of sharing, not persistently encrypting the file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels (Azure Information Protection)
Sensitivity labels from Azure Information Protection (AIP) allow you to classify and protect documents with persistent protection that travels with the file, even when it is downloaded to an external device. By configuring a sensitivity label with encryption, you can restrict access to a specific group of employees, disable editing and printing, and enforce these restrictions regardless of where the file is stored. This meets all the requirements of the scenario, including persistent protection after download.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity labels (Azure Information Protection)
Why this is correct
Sensitivity labels are correct because they use Azure Rights Management (RMS) at the Microsoft Purview Information Protection layer to encrypt documents and assign granular usage rights, such as view, edit, copy, print, and forward permissions. These rights are embedded in the file itself, so the protection persists even if the document is saved to an external drive or shared with third parties. A global financial services firm specifically needs this persistent encryption and revocable access control to protect highly sensitive data after it leaves Microsoft 365.
- ✗
Data Loss Prevention (DLP) policy
Why it's wrong here
A DLP policy detects and blocks the flow of sensitive data (e.g., credit card numbers or bank account identifiers) across email, Teams, and endpoints by matching data-loss prevention rules at the boundary. However, DLP acts only at the moment of transmission or access; once a file is downloaded or legitimately shared, the policy no longer accompanies the file and cannot enforce encryption or restrict what the recipient does with it. Even when DLP is configured to apply a label, the actual persistent protection comes from sensitivity label infrastructure, not the DLP engine itself.
- ✗
Information Barriers
Why it's wrong here
Information Barriers in Microsoft Purview restrict communication and collaboration between defined user groups, commonly used in financial services to prevent conflicts of interest or insider trading between segments such as investment banking and research. This solution only controls which users can chat, call, or collaborate with each other inside platforms like Microsoft Teams and SharePoint; it does not encrypt files or limit how a single user can open, edit, or forward a document after access is granted. Therefore, it cannot provide the content-level protection the firm requires.
- ✗
Advanced Audit
Why it's wrong here
Advanced Audit is a Microsoft Purview logging feature that captures high-value auditing events, such as document access, downloads, permission changes, and admin activities, with extended retention options. While it is useful for forensic investigation and regulatory compliance reporting, it has no enforcement capability; it cannot prevent a file from being opened, copied, printed, or forwarded by an authorized user. Because it only records activities after they occur, Advanced Audit cannot proactively protect sensitive documents from unauthorized access.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID (Azure AD) in M365
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
Key term
Sensitivity label
A sensitivity label is a metadata tag applied to digital content that classifies the content's level of confidentiality and governs how it can be shared, protected, and accessed.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.