Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A global organization uses Microsoft 365 E5 and needs to securely share sensitive documents with external partners. The compliance officer requires that external users can view but not edit, print, or forward the documents, and access must expire after 30 days. Which combination of services should the admin use?

⚠ Common exam trap

Many candidates confuse external sharing controls (like B2B or guest access) with document-level protection, assuming that any external sharing mechanism can enforce granular usage restrictions, but only sensitivity labels with Azure RMS can apply 'View Only' and expiration at the file level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection with sensitivity labels and SharePoint Online

Microsoft Purview Information Protection with sensitivity labels can enforce 'View Only' permissions that prevent editing, printing, and forwarding, while SharePoint Online allows setting an expiration date for external access via sharing links. Together, they meet the compliance officer's requirements for granular document-level restrictions and time-bound access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SharePoint Online External Sharing and Microsoft Entra B2B

    Why it's wrong here

    SharePoint Online External Sharing alone controls whether external users can be invited to access a site, and Microsoft Entra B2B supplies the guest identity and authentication lifecycle, but neither mechanism applies or enforces document-level restrictions such as view-only, watermarking, or copy/print blocking. While external sharing can be scoped to specific sites or folders, it does not natively enforce expiration or read-only permissions on the content itself, so a guest with edit permissions could download, print, or forward the document. The combination therefore addresses who can access the site, not how the document may be used after access is granted.

  • ✓

    Microsoft Purview Information Protection with sensitivity labels and SharePoint Online

    Why this is correct

    Microsoft Purview Information Protection with sensitivity labels provides the actual protection layer: labels can be configured to apply encryption, set permissions such as View-only, disable printing and copying, and attach expiration dates to the document itself. SharePoint Online then hosts the protected file and enforces these label-based restrictions when the document is opened through Office apps or the web, including for external guests. This combination directly satisfies the requirement to allow viewing only, prevent downloads/prints/forwards, and enforce an automatic access expiration, making it the correct solution.

  • ✗

    Microsoft Entra B2B collaboration with Conditional Access

    Why it's wrong here

    Microsoft Entra B2B collaboration with Conditional Access governs the guest user's ability to sign in to Microsoft Entra ID and controls access based on conditions like device compliance, location, or risk during authentication. However, once the guest is authenticated, Conditional Access does not evaluate or enforce permissions on specific documents; it does not know whether a user should be allowed to print, copy, or download a particular file. Even with a compliant device and successful sign-in, the guest could still perform any action the underlying SharePoint/OneDrive permission grants, so this option fails to provide document-level usage restrictions or expiration.

  • ✗

    Microsoft Teams with guest access and sharing permissions

    Why it's wrong here

    Microsoft Teams with guest access allows external users to be added to teams and channels, and sharing permissions at the team level control what guests can see or interact with in the team workspace. However, Teams guest access relies on SharePoint Online and OneDrive for file storage, and it does not add an independent document-level protection mechanism. A guest with access to a channel can open files and, depending on the underlying SharePoint permission, can download, print, or forward them; Teams has no built-in way to make a document view-only or automatically expire access to the file itself.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.