MS-900 Describe Microsoft 365 apps and services Practice Question
A large enterprise needs to enforce that all documents containing financial data are automatically classified and encrypted when shared externally. Which combination of Microsoft 365 services should be used?
⚠ Common exam trap
Watch out — candidates often confuse security monitoring tools (Sentinel, Defender XDR) with data classification and encryption tools, or they mistakenly think device management (Intune) or identity (Entra ID) can enforce content-level encryption on documents shared externally.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Information Protection and Microsoft Defender for Cloud Apps
Microsoft Purview Information Protection provides the classification and labeling capabilities to automatically identify documents containing financial data, while Microsoft Defender for Cloud Apps enables policy-based encryption and protection controls when those documents are shared externally. Together, they enforce data loss prevention (DLP) by applying sensitivity labels that trigger encryption upon external sharing, meeting the enterprise requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Forms and Microsoft Stream
Why it's wrong here
Microsoft Forms is for building surveys and quizzes, while Microsoft Stream hosts videos. Neither service has native data-classification, sensitivity-labeling, or document-encryption capabilities, so they cannot apply protection controls to Word, Excel, or PDF files. Their role is content creation and collaboration, not policy enforcement or information governance, which makes them irrelevant for this requirement.
- ✗
Microsoft Sentinel and Microsoft Defender XDR
Why it's wrong here
Microsoft Sentinel is a cloud-native SIEM, and Microsoft Defender XDR provides extended detection and response across the estate. These tools focus on detecting and responding to security incidents after they occur, not on classifying or encrypting documents at rest or in use. They can alert on suspicious access to files, but they do not natively attach retention, sensitivity, or encryption policies to document content, so they fall short of enforcing document protection.
- ✓
Microsoft Purview Information Protection and Microsoft Defender for Cloud Apps
Why this is correct
Microsoft Purview Information Protection provides sensitivity labels that can classify and, when configured, encrypt documents using rights-management templates, while Microsoft Defender for Cloud Apps acts as a cloud access security broker to enforce policies on those labels—such as blocking download or applying visual markings. Together, they create a complete control plane that can conditionally require a label, apply automatic classification, and govern sharing behavior for documents in SharePoint, OneDrive, or third-party cloud apps. This directly enforces the enterprise requirement to protect all documents containing sensitive data.
- ✗
Microsoft Intune and Microsoft Entra ID
Why it's wrong here
Microsoft Intune is a modern device-management solution, and Microsoft Entra ID is an identity and access-management service that controls sign-in and conditional access. While they restrict which users and devices can access documents, they operate at the authentication and device-compliance layer, not at the file-content layer. They cannot inspect a document’s classification level, apply an encryption label, or enforce a specific sensitivity mark on the document itself—so they lack the data-centric protection the requirement demands.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Endpoint in M365
Key term
Defender for Cloud
Microsoft Defender for Cloud is a cloud security posture management (CSPM) and cloud workload protection platform (CWPP) that provides unified security management and threat protection across hybrid and multi-cloud environments.
Key term
Microsoft Defender
Microsoft Defender is a suite of security products that protects devices, data, and identities from cyber threats like malware, phishing, and unauthorized access.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.