Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A legal team is preparing for litigation. They need to place a hold on all content (emails, documents, Teams messages) related to a specific project across the entire organization. The hold must prevent any deletion or modification of the content. Which Microsoft Purview solution should they use?

⚠ Common exam trap

Test-takers frequently confuse retention policies (which are broad, time-based preservation rules) with legal holds (which are case-specific, litigation-driven holds that prevent any modification or deletion), leading them to incorrectly select Option D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

eDiscovery (Premium) with legal hold

EDiscovery (Premium) with legal hold is the Microsoft Purview solution specifically designed to preserve content in-place for litigation. When a legal hold is applied to a case, it prevents deletion or modification of emails, documents, and Teams messages across the entire organization by placing a hold on the underlying Exchange Online mailboxes, SharePoint sites, and OneDrive accounts. This ensures that all content related to the project is immutable for the duration of the hold, meeting the legal team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • eDiscovery (Premium) with legal hold

    Why this is correct

    eDiscovery (Premium) is the Microsoft Purview solution built for legal investigations. It allows you to create a case, search across Exchange, SharePoint, OneDrive, Teams, and other workloads, and apply a legal hold that preserves all responsive content indefinitely until the hold is released by case attorneys. A legal hold overrides user deletions, auto-purge policies, and even mailbox retention cleanup processes, ensuring data stays intact for the duration of litigation. This directly satisfies the legal team's requirement to place a hold on potentially relevant data.

  • Audit log search

    Why it's wrong here

    Audit log search in Microsoft 365 is a detective control that records user and administrator activities such as file accesses, deletions, or permission changes across services. While you can query the unified audit log to reconstruct what happened to content after a deletion or modification, the audit log itself does not prevent users from deleting or editing a document—it only records the event. Additionally, the audit log has a finite default retention period of 180 days, which is insufficient for indefinite litigation holds spanning months or years. Therefore, audit log search is useful for investigation but cannot preserve data for litigation.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention (DLP) policies are designed to identify, monitor, and protect sensitive information—such as credit card numbers, bank account details, or personally identifiable information—by applying actions like blocking external sharing, encrypting content, or showing policy tips at the moment a user attempts to share it. DLP operates in real time to prevent data exposure but does not place content on hold or create an immutable copy for legal purposes. In fact, DLP policies typically only restrict certain actions, leaving the content vulnerable to deletion by the user or another retention process. Thus, DLP is a prevention control, not a preservation mechanism, and cannot meet the litigation hold requirement.

  • Retention policy

    Why it's wrong here

    Retention policies are designed for data lifecycle management, enforcing time-based retention or deletion across an organisation for compliance or operational needs. While they prevent content deletion during their active period, they lack the specific functionality for an indefinite, litigation-driven preservation requirement where content must be held until a legal case concludes. This scenario requires a targeted, event-driven hold, which retention policies are not built to provide. They are suitable for ensuring data is kept for a set period, or automatically deleted afterwards, as part of a proactive data governance strategy.

About these practice questions

This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.