Describe security, compliance, privacy, and trust in Microsoft 365 →hardMultiple ChoiceObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A legal team needs to preserve all data belonging to a former employee who is involved in litigation. The preservation must cover Exchange Online email, SharePoint sites, Teams messages, and OneDrive files. Which Microsoft Purview solution should they use to enforce the preservation?
⚠ Common exam trap
It's easy for candidates to confuse a retention policy (which is automated and rule-based) with a legal hold (which is manual, case-specific, and preserves data for litigation), leading them to choose Data Lifecycle Management instead of eDiscovery.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
eDiscovery (Standard) case hold
eDiscovery (Standard) case hold is the correct solution because it allows legal teams to place a legal hold on all data sources associated with a specific user, including Exchange Online mailboxes, SharePoint sites, OneDrive accounts, and Teams messages. This preserves the data in its current state, preventing modification or deletion, which is essential for litigation. Unlike other options, eDiscovery holds are designed specifically for legal preservation scenarios and can target multiple workloads simultaneously.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
eDiscovery (Standard) case hold
Why this is correct
eDiscovery (Standard) case hold creates a preservation hold within a Microsoft Purview eDiscovery case. It lets the legal team target a former employee's Exchange Online mailbox, OneDrive for Business, SharePoint sites, and Teams content, and all items in those locations are held in place, including metadata and versions. Because the hold is Custodian-based and applies organization-wide to the employee's data, it satisfies the requirement to preserve all data for legal proceedings.
- ✗
Data Lifecycle Management retention policy
Why it's wrong here
Data Lifecycle Management retention policies enforce retention and deletion rules at a large scale, such as applying a single policy to all Exchange mailboxes or all SharePoint sites. They are not designed for targeted, custodian-specific legal holds, and a policy cannot be scoped to one user's data across multiple services without a complex custom scope that would still apply the same rules to other users. Furthermore, these policies are designed to automate disposition schedules, not to freeze data for litigation.
- ✗
Sensitivity label with retention marking
Why it's wrong here
Sensitivity labels with retention markings use classification-based criteria that require each item to be labeled, either manually or via an automatic rule that scans content. It is not a blanket hold on all data belonging to a former employee because it cannot retroactively tag existing items in every location, and it does not integrate with eDiscovery cases or legal holds. A retention label preserves labeled content indefinitely, but unlabeled content remains unprotected from deletion.
- ✗
Audit log search
Why it's wrong here
Audit log search in Microsoft Purview provides a record of user and administrator activities across Microsoft 365, including who accessed an item, when, and what action was performed. It does not store the content of emails, documents, or Teams messages, nor does it prevent content from being permanently deleted. Therefore, running an audit search would help after the fact to track what may have been lost, but it cannot preserve the data itself to meet a legal preservation obligation.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 217 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.