MS-900 Describe Microsoft 365 apps and services Practice Question
A hospital uses Microsoft 365 E5 and needs to ensure that patient health information (PHI) is not accidentally shared externally. They want to block sharing of emails containing credit card numbers or medical record numbers. Which Microsoft Purview feature should they configure?
⚠ Common exam trap
Many candidates confuse Sensitivity Labels with DLP, not realizing that labels are for classification and protection (e.g., encryption), while DLP is the enforcement engine that scans content and blocks sharing based on those labels or built-in sensitive data types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention (DLP)
Microsoft Purview Data Loss Prevention (DLP) is the correct feature because it is specifically designed to detect and block the accidental sharing of sensitive data, such as credit card numbers and medical record numbers, via email. DLP uses deep content analysis with built-in sensitive information types (e.g., Credit Card Number, U.S. Medical Record Number) to scan emails and enforce policies that prevent external sharing. This directly addresses the hospital's requirement to protect PHI from being leaked externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Privileged Access Management
Why it's wrong here
Privileged Access Management (PAM) controls time-bound, just-in-time access to elevated administrative roles in Exchange Online, SharePoint Online, and other workloads, but it does not evaluate or restrict how end users share content. In a hospital, PAM would govern whether an IT admin can modify tenant settings or access a mailbox, yet it would not inspect an email for protected health information before it is sent to an outside party. Therefore, while useful for securing administrative permissions, it cannot enforce data-loss prevention on patient data.
- ✓
Microsoft Purview Data Loss Prevention (DLP)
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) uses configurable policies to scan messages and files for sensitive information types such as HIPAA-specific identifiers, medical record numbers, and diagnosis codes, and then automatically blocks or restricts the sharing of those items. In a healthcare tenant, a DLP policy can be applied to Exchange, SharePoint, OneDrive, Teams, and endpoints so that any attempt to email or upload PHI to an unapproved external domain triggers a block action, encryption, or a policy tip to the user. This provides the proactive, content-based control needed to prevent patient data from leaving the hospital.
- ✗
Microsoft Purview Sensitivity Labels
Why it's wrong here
Sensitivity labels are metadata and protection wrappers that mark content as, for example, Confidential-Healthcare and can apply encryption or access restrictions, but they do not continuously inspect content for sensitive patterns and block sharing on their own. A user could still send an unlabeled document containing patient names and diagnoses to an external recipient, and even a labeled document does not inherently stop the act of sharing unless a separate DLP policy or conditional access rule enforces that action. They are crucial for classification and persistent protection, yet they are not the enforcement engine that detects and intercepts an unauthorized PHI disclosure.
- ✗
Microsoft Purview Information Barriers
Why it's wrong here
Information Barriers (IB) segment users into groups and prevent those groups from finding, communicating, or collaborating with each other in Teams, OneDrive, and SharePoint, primarily to avoid conflicts of interest or inappropriate internal interactions. IB does not examine message content for sensitive data or block outbound sharing to external recipients, so it would not catch a clinician sending PHI to a personal email address. In a hospital setting, IB might separate staff in conflicting departments, but it is not designed or able to act as a data leak prevention control for patient information.
Go deeper
Related to this question
Learn chapter
Intune Device Compliance and Configuration Policies
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.