MS-900 Describe Microsoft 365 apps and services Practice Question
A multinational corporation uses Microsoft 365 E5. They need to enforce that all documents marked as 'Confidential' are encrypted and cannot be printed or forwarded. Which Microsoft Purview Information Protection capability should they configure?
⚠ Common exam trap
Test-takers frequently confuse DLP policies with sensitivity labels, thinking DLP can enforce encryption and restrict actions like printing, but DLP only monitors and alerts on content in transit or at rest, while sensitivity labels provide persistent, user-enforced protection at the file level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels with encryption
Sensitivity labels with encryption are the correct choice because they allow you to classify and protect documents at the file level, applying encryption that restricts actions such as printing and forwarding. This is a core capability of Microsoft Purview Information Protection, enabling persistent protection that travels with the document regardless of where it is stored or shared.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity labels with encryption
Why this is correct
Sensitivity labels with encryption are the correct choice because they apply persistent protection directly to content, enforcing encryption, and usage restrictions such as 'Do Not Forward' or 'View Only' settings. These labels work natively across Microsoft 365 apps and services, ensuring that print, copy, and edit actions are blocked based on policies defined by the organization.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
Data Loss Prevention (DLP) policies are incorrect because they focus on detecting and blocking the unintentional sharing of sensitive data via email and cloud services, but they do not enforce encryption or restrict actions like printing. DLP operates at the transport and sharing layers, scanning content for defined data types, whereas the requirement demands persistent usage rights on the documents themselves.
- ✗
Retention policies
Why it's wrong here
Retention policies are incorrect because they govern the lifecycle of content, specifically retaining or deleting data after a certain period to meet compliance or legal obligations. They do not provide encryption, nor do they control user actions such as printing or forwarding; instead, they ensure data is kept for the required duration or removed when no longer needed.
- ✗
Azure Information Protection (AIP) client
Why it's wrong here
Azure Information Protection (AIP) client is incorrect because it is a legacy, client-based labeling solution that has been superseded by native sensitivity labels in Microsoft Purview. While the AIP client could apply encryption, it required separate installation and maintenance, and modern best practice is to use built-in sensitivity labels that integrate directly with Office apps and services.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.