MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
A user accidentally shared a file containing credit card numbers with a partner organization. You need to prevent similar incidents and detect when such data is shared externally. What should you configure?
⚠ Common exam trap
MS-900 often tests the confusion between DLP (content-based prevention/detection) and AIP/IRM (classification and encryption), leading candidates to pick AIP when the requirement is to detect and block sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft 365 Data Loss Prevention (DLP) policy
Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify sensitive information such as credit card numbers using sensitive information types and to prevent or detect when that data is shared externally. DLP can block sharing, generate alerts, and provide policy tips to users, directly addressing both prevention and detection requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Information Protection (AIP)
Why it's wrong here
Azure Information Protection labels and encrypts content, yet detection of credit card numbers shared externally requires Microsoft Purview Data Loss Prevention policies with alerts. AIP would be correct for persistent classification and protection of files, not for monitoring outbound sharing.
- ✗
Microsoft Purview eDiscovery
Why it's wrong here
eDiscovery searches and preserves content for legal cases; it does not block sharing or raise real-time alerts when card numbers leave the tenant. It is correct for litigation holds and investigations. Preventing and detecting external sharing of sensitive data needs Microsoft Purview DLP.
- ✓
Microsoft 365 Data Loss Prevention (DLP) policy
Why this is correct
Microsoft 365 DLP policies inspect content for sensitive information types such as credit card numbers, then block or warn on external sharing in SharePoint, OneDrive, and Teams. This directly satisfies the stem's requirement to both prevent accidental sharing and detect external disclosure of that data.
- ✗
Information Rights Management (IRM)
Why it's wrong here
IRM restricts actions on files but does not detect or block sharing proactively.
Go deeper
Related to this question
Learn chapter
Microsoft Purview Information Protection
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.