MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A law firm uses Microsoft 365 and wants to ensure that only authorized users can access client files stored in SharePoint Online. They also need to track when these files are accessed. Which combination of features should they use?
⚠ Common exam trap
MS-900 often tests the confusion between access control (Conditional Access/PIM) and data-level protection (sensitivity labels/encryption) — candidates pick Conditional Access thinking it restricts file access, but it only gates sign-in.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels with encryption and Microsoft Purview auditing.
Sensitivity labels with encryption enforce access control at the item level by encrypting SharePoint files so only authorized identities can open them, and Microsoft Purview auditing logs every access event for tracking. Together they satisfy both the access restriction and the access-tracking requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity labels with encryption and Microsoft Purview auditing.
Why this is correct
Sensitivity labels apply encryption via Azure Rights Management, allowing administrators to assign granular permissions like view-only or co-author to specific users or groups. Because the label attaches to the document, the encryption and permissions persist even if the file is copied or shared externally. Microsoft Purview auditing then captures every access attempt, including successful opens and denied tries, giving the law firm a detailed, searchable log of who did what.
- ✗
Conditional Access policies and Privileged Identity Management (PIM).
Why it's wrong here
Conditional Access works at the authentication boundary, evaluating factors such as user risk, device compliance, and trusted location to allow or block sign-in to Microsoft 365 services. It does not define what a signed-in user can do with a specific document. Privileged Identity Management (PIM) is scoped to role activation for administrators (e.g., Global Admin) and does not govern permissions on law-firm case files, so this pair addresses identity and admin access, not content-level protection.
- ✗
eDiscovery cases and Content search.
Why it's wrong here
eDiscovery cases and Content search are built for legal and compliance investigations, letting authorized admins search, preserve, and export content across mailboxes, SharePoint sites, and OneDrive. These tools operate in a read/export/exhibit capacity and do not enforce real-time restrictions; they are administrative utilities that require already-appropriate permissions to run, rather than a mechanism to prevent unauthorized users from opening a file.
- ✗
Data Loss Prevention (DLP) policies and Microsoft Defender for Cloud Apps.
Why it's wrong here
DLP policies inspect data in motion and at rest to detect and block the transmission of sensitive patterns like passport numbers or client data, but they do not apply document-level encryption or per-user ACLs. Microsoft Defender for Cloud Apps provides conditional access, session controls, and activity alerts, but its focus is post-hoc detection, cloud app governance, and threat response — it cannot retroactively encrypt a file sitting in SharePoint to limit who can view its contents.
Go deeper
Related to this question
Learn chapter
Microsoft Migration Tools: SharePoint and Exchange
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.