Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A healthcare organization is adopting Microsoft 365 and must meet compliance requirements: retain all communications for 7 years, prevent accidental deletion of documents, and classify sensitive data automatically. Which THREE Microsoft Purview features should the organization use?

⚠ Common exam trap

Watch out — candidates often confuse DLP policies with auto-labeling, but DLP is about preventing data loss after classification, not the classification itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-labeling

Auto-labeling (Option C) is correct because it enables the organization to automatically classify sensitive data based on content patterns (e.g., healthcare records, PII) without manual intervention. This aligns directly with the requirement to classify sensitive data automatically, using trainable classifiers or sensitive info types in Microsoft Purview.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data loss prevention (DLP) policies

    Why it's wrong here

    Data loss prevention (DLP) policies scan content for sensitive data types (e.g., patient names with medical record numbers) and enforce protective actions like blocking sharing or encrypting email, but they do not automatically assign classification labels or apply retention schedules. DLP is reactive and policy-driven, triggered at the point of data loss risk, not an ongoing records-management mechanism. Because it neither classifies documents in place nor retains them for a fixed duration, it fails to meet the twin requirements of classification and retention for healthcare communications.

  • ✗

    eDiscovery

    Why it's wrong here

    eDiscovery is a search-and-export tool that lets you query content across Exchange, SharePoint, OneDrive, and Teams to identify relevant records for legal or compliance investigations. It can place temporary holds (eDiscovery holds) on specific content, but those holds are for preserving evidence during active litigation, not for systematically enforcing a retention period across all communications. eDiscovery does not apply any automatic classification or lifecycle management; its role begins after a retention or classification need has already been defined, so it is not the correct mechanism for establishing those requirements.

  • ✓

    Auto-labeling

    Why this is correct

    Auto-labeling in Microsoft 365 automatically applies sensitivity or retention labels to content based on rules, sensitive information patterns, or machine-learning classifiers. For a healthcare organization, this ensures that communications containing protected health information (e.g., a patient ID with a diagnosis) are immediately classified as sensitive without manual user intervention. This classification is a prerequisite for enforcing downstream governance actions like encryption or access restrictions, and it directly fulfills the 'classify' part of the requirement. Auto-labeling alone does not retain content for a set period, but it is the correct mechanism for automated classification.

  • ✓

    Preservation hold lock

    Why this is correct

    A preservation hold lock is a severity-level setting on a retention policy or eDiscovery hold that makes the hold legally incontrovertible and unremovable. Once locked, even global admins cannot reduce the retention period, delete the policy, or add exclusions, which prevents accidental or malicious deletion of communication records. This is critical in healthcare to satisfy regulatory and legal obligations that demand transcripts or messages be kept for a specified time, as it ensures the retention hold is tamper-proof. While it does not itself classify content, it robustly guarantees that a retention hold remains in effect, making it a correct component of a compliant retention solution.

  • ✓

    Retention policies

    Why this is correct

    Retention policies in Microsoft Purview allow you to define rules that retain communications for a specified period, then delete or preserve them afterward. You can scope policies to entire workloads (Exchange mailboxes, Teams chat, SharePoint sites) so that all communications—emails, conversations, documents—are captured without requiring per-item user action. Unlike DLP or eDiscovery, a retention policy is a proactive, automated lifecycle control that directly enforces the 'retain for required period' part of the mandate. This is the foundational mechanism for ensuring that healthcare communication records exist for the necessary regulatory or legal duration.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.