Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A healthcare organization uses Microsoft 365 E5 and must comply with HIPAA. They need to ensure that all emails containing protected health information (PHI) are encrypted both in transit and at rest. They also need to prevent users from accidentally sending PHI to external recipients. What should they implement?

⚠ Common exam trap

Test-takers frequently confuse DLP with encryption, thinking that encryption alone prevents accidental sharing, or they mistake security features like MFA or Safe Attachments for data protection controls that address content-based compliance requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement Microsoft Purview Message Encryption and create DLP policies to detect and block PHI sent externally.

Microsoft Purview Message Encryption (MPME) provides the necessary encryption for PHI in transit and at rest by using Azure Rights Management (RMS) to protect emails. Data Loss Prevention (DLP) policies in Microsoft Purview can be configured to detect patterns like social security numbers or medical record numbers and automatically block or warn users before sending such emails externally, preventing accidental PHI exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Entra ID Conditional Access to require MFA for all email access.

    Why it's wrong here

    Requiring MFA via Microsoft Entra ID Conditional Access verifies the identity of users accessing email, but it does not encrypt message content or protect PHI while in transit or at rest. MFA only prevents unauthorized account access, not accidental or malicious external sharing of sensitive data, and it lacks the content inspection capabilities needed to identify PHI. Therefore, while MFA is a foundational security control, it does not satisfy HIPAA's encryption and data-loss-prevention requirements for email.

  • ✓

    Implement Microsoft Purview Message Encryption and create DLP policies to detect and block PHI sent externally.

    Why this is correct

    Implementing Microsoft Purview Message Encryption (OME) encrypts email messages and attachments, ensuring protected health information (PHI) is unreadable to unauthorized recipients, while DLP policies detect sensitive patterns such as medical record numbers or diagnosis codes and automatically block or warn before such content is sent externally. Together, these controls enforce both confidentiality and controlled sharing, which are core HIPAA safeguards. Unlike other options, this combination directly addresses the specific requirement to secure PHI in email.

  • ✗

    Configure Microsoft Defender for Office 365 Safe Attachments and Safe Links policies.

    Why it's wrong here

    Configuring Microsoft Defender for Office 365 Safe Attachments and Safe Links protects users from malware and malicious URLs by scanning attachments and links in real time, but it does not examine email content for PHI, nor does it encrypt messages or monitor data exfiltration. These policies focus on threat prevention, not information protection, and would not prevent an employee from accidentally sending unencrypted PHI to an external party. Thus, while valuable for email security, they fail to meet the stated compliance objective.

  • ✗

    Deploy Microsoft Purview Compliance Manager to assess compliance with HIPAA.

    Why it's wrong here

    Deploying Microsoft Purview Compliance Manager helps assess your organization's compliance posture against HIPAA by providing a score, controls mapping, and recommendations, but it is a governance and risk assessment tool rather than an enforcement mechanism. It does not apply encryption to outbound email, does not detect or block PHI in messages, and does not alter the behavior of email transport. Therefore, Compliance Manager can demonstrate readiness but cannot actually prevent PHI from being shared insecurely.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.