Describe security, compliance, privacy, and trust in Microsoft 365 →hardMultiple SelectObjective-mapped
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A multinational corporation must comply with GDPR. They need to ensure that personal data of EU residents is retained for a specific period and then securely deleted. Additionally, they must be able to respond to data subject access requests (DSARs) within 30 days by finding and exporting relevant data. Which two Microsoft Purview solutions should they use together? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse Data Lifecycle Management (via sensitivity labels) with retention policies, not realizing that sensitivity labels handle classification and protection, not automated time-based retention and deletion, while retention policies are the correct tool for that purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Retention policies
Retention policies (A) are correct because they allow organizations to define rules that retain personal data for a specific period and then automatically delete it, meeting GDPR retention and secure deletion requirements. eDiscovery (Premium) (C) is correct because it enables searching, collecting, and exporting data from various Microsoft 365 workloads to fulfill data subject access requests (DSARs) within the 30-day regulatory timeframe.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Retention policies
Why this is correct
Retention policies in Microsoft Purview are the primary mechanism for automatically enforcing GDPR's storage-limitation obligations. They can be configured to retain personal data for a defined period and then permanently delete it, operating consistently across Exchange, SharePoint, OneDrive, and Teams. By allowing you to set precise retention and deletion rules based on content age or sensitive data types, they directly satisfy data-minimization and erasure requirements without manual intervention. This makes them the correct answer for meeting GDPR retention and deletion obligations.
- ✗
Data Lifecycle Management (via sensitivity labels)
Why it's wrong here
Data Lifecycle Management is a feature of Microsoft Purview that uses retention labels and auto-labeling policies to classify and manage data, but it is not a complete substitute for retention policies. While sensitivity labels can trigger retention actions, they also apply encryption, access control, and visual markings — none of which directly enforce automated deletion. Configuring Data Lifecycle Management requires per-label policies and does not provide the same breadth of automatic, workload-wide retention and deletion as retention policies. Therefore, while it assists in lifecycle management, it is not the primary solution required for GDPR compliance.
- ✓
eDiscovery (Premium)
Why this is correct
eDiscovery (Premium) is the correct tool for fulfilling data subject access requests (DSARs) under GDPR Article 15 because it allows you to search, preserve, and export personal data from multiple Microsoft 365 workloads. It supports full-text search, advanced indexing, and legal hold capabilities, enabling you to locate all relevant data about an individual and produce it within the GDPR's one-month timeframe. Unlike retention policies, it does not enforce automated deletion but rather provides the discovery and export functionality necessary to respond to access requests. This is essential for GDPR compliance, making eDiscovery (Premium) correct in its role.
- ✗
Audit (Standard)
Why it's wrong here
Audit (Standard) in Microsoft Purview records user and admin activity, such as document view, edit, and send events, but it only captures metadata about 'who did what, when, and where.' It does not allow searching the actual content of personal data, nor does it provide the ability to export that content to fulfill a DSAR. While audit logs are useful for demonstrating compliance and investigating security events, they cannot meet GDPR obligations for data access or deletion. Thus, relying on Audit (Standard) alone would fail to address GDPR requirements, making it incorrect for this purpose.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
About these practice questions
This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.