Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

A marketing department uses Microsoft 365 Copilot to generate content. The compliance officer is concerned about data leakage when users interact with Copilot. Which Microsoft Purview feature should the admin implement to prevent sensitive data from being used in Copilot prompts?

⚠ Common exam trap

Many exam-takers confuse sensitivity labels (which classify and protect static content) with DLP (which actively monitors and blocks data in motion), leading them to choose Option D instead of the correct preventive control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Loss Prevention (DLP) for Copilot

Microsoft Purview Data Loss Prevention (DLP) for Copilot is the correct feature because it specifically inspects and blocks sensitive data (e.g., credit card numbers, PII) from being included in Copilot prompts or generated content. DLP policies can be applied to Copilot interactions to prevent data leakage by evaluating the content in real time against sensitive information types and enforcing actions like blocking or warning the user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Microsoft Purview Data Loss Prevention (DLP) for Copilot

    Why this is correct

    Microsoft Purview DLP for Copilot inspects both the Copilot prompt and the generated response for sensitive content types, such as credit card numbers, personal data, or confidential keyword patterns, using the same policy engine as classic DLP. When a violation is detected, it can block the interaction, restrict sharing, and raise an incident in Microsoft Defender, which is why it is the control that actually prevents leakage. This is a preventive, in-line control rather than a retrospective or classification-only measure.

  • ✗

    Microsoft Purview Audit (Standard)

    Why it's wrong here

    Microsoft Purview Audit (Standard) captures an event record for actions such as prompts sent to Copilot, responses viewed, and policy matches, but it does not inspect or filter the content before that interaction is shown to the user. It gives security teams the ability to investigate leakage after the fact, which is valuable for compliance, but it cannot stop sensitive data from leaving the tenant at the time of the prompt. Therefore it is a detective control, not the correct choice for blocking a leak.

  • ✗

    Microsoft Purview Information Rights Management (IRM)

    Why it's wrong here

    Microsoft Purview Information Rights Management (IRM) protects documents and emails by encrypting them and applying usage restrictions like 'do not forward' or 'restrict edit' so that only authorized users can open or modify them. That protection is applied to files after they exist, and while it can shield an output document that Copilot generates if the file is already IRM-protected, it has no mechanism to parse a live Copilot prompt or response for sensitive data. IRM is about downstream document protection, not real-time content awareness in Copilot conversations.

  • ✗

    Microsoft Purview Sensitivity labels

    Why it's wrong here

    Sensitivity labels attach metadata to documents, emails, and other items so that tenant admins can classify data and automate protection behaviors such as encryption or headers when the item is used or shared. A label does not actively scan the text of a Copilot prompt, nor can it independently block a Copilot response that insecurely composes sensitive information, even if the underlying data was labeled. Labels are a building block for policy conditions, but without DLP's content inspection engine, they cannot enforce a block on Copilot interactions.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.