MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A service owner is comparing Microsoft 365 capabilities and needs to block emails containing credit card numbers from being sent externally. Microsoft security, identity, or compliance capability should it use?
⚠ Common exam trap
Candidates often confuse Microsoft 365 compliance tools with unrelated productivity apps, assuming any 'Microsoft' tool can handle security tasks, but only DLP is purpose-built for content-based email restrictions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) in Microsoft 365 is the correct capability because it is specifically designed to detect and protect sensitive information, such as credit card numbers, by scanning email content and attachments. DLP policies can be configured to block external transmission of emails containing sensitive data, using built-in sensitive information types like the Credit Card Number rule that matches patterns based on Luhn checksum validation. This directly addresses the service owner's requirement to prevent credit card numbers from being sent externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Planner
Why it's wrong here
Microsoft Planner is a task management application for organizing teamwork, where you assign tasks and track progress on boards. It does not perform content inspection or apply data classification policies, so it cannot detect credit card numbers, personal data, or other sensitive information. Its security model is limited to permissions for accessing plans, which does not meet the requirement to prevent unauthorized sharing of sensitive data.
- ✓
Data Loss Prevention (DLP)
Why this is correct
Data Loss Prevention (DLP) is a compliance feature in Microsoft 365 that uses predefined sensitive information types and custom rules to inspect content across Exchange, SharePoint, OneDrive, and Teams. It can automatically block sharing of files containing passport numbers, health records, or other regulated data, and can display policy tips to users before they take risky actions. DLP policies support conditions, exceptions, and actions such as blocking access, encrypting content, or sending incident reports, making it the correct capability for this security and compliance control.
- ✗
Microsoft Stream
Why it's wrong here
Microsoft Stream is a video hosting and sharing service within Microsoft 365, primarily used to store and play back recorded meetings, lectures, and presentations. While Stream applies standard permissions and access controls, it does not scan video content or associated metadata for sensitive data patterns, nor does it enforce data loss prevention policies across other workloads. Its purpose is media management, not the detection and blocking of data leakage, so it is not a valid solution for this requirement.
- ✗
Microsoft Forms
Why it's wrong here
Microsoft Forms is an application for designing surveys, quizzes, and polls, and for collecting user responses. It does not include a policy engine to analyze submitted data for sensitive information, and it lacks the ability to apply DLP actions such as blocking or warning when a user tries to share confidential data. Although Forms has some access controls, it cannot meet the stated need for a DLP control, so it is an incorrect choice.
Go deeper
Related to this question
Learn chapter
Microsoft Compliance Manager and Score
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.