Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

An organisation wants to identify documents containing credit card numbers and prevent users from sharing them externally from SharePoint Online and Exchange Online. Which two Microsoft Purview capabilities are most relevant? (Choose 2.)

⚠ Common exam trap

Test-takers frequently confuse Microsoft Purview capabilities with unrelated Microsoft 365 services like Bookings or Autopilot, failing to recognize that only sensitive information types and DLP policies directly address content inspection and sharing controls for compliance scenarios.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sensitive information types.

Sensitive information types (A) are predefined or custom patterns that detect sensitive data like credit card numbers using regex and checksum validation. Data Loss Prevention policies (B) use these sensitive information types to enforce rules that block external sharing of documents containing credit card numbers in SharePoint Online and Exchange Online. Together, they identify the sensitive content and prevent its unauthorized external distribution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sensitive information types.

    Why this is correct

    Sensitive information types are content classifiers that use built-in pattern recognition to identify data like credit card numbers, including validation via Luhn checksum and context keywords. These predefined or custom regex-based detectors can scan content in Exchange Online, SharePoint, and OneDrive, making them the direct mechanism for identifying documents containing credit card data.

  • ✓

    Data Loss Prevention policies.

    Why this is correct

    Data Loss Prevention (DLP) policies in Microsoft 365 are enforcement frameworks that apply protective actions such as blocking, warning, or encrypting content when sensitive data is detected. However, DLP itself does not identify the sensitive data; it relies on sensitive information types as conditions to trigger actions, so while DLP is related, it is the policy layer rather than the detection engine.

  • ✗

    Microsoft Bookings.

    Why it's wrong here

    Microsoft Bookings is a scheduling and appointment management application that allows organizations to manage customer bookings and staff calendars. It performs no content inspection or data classification and has no capability to scan documents or files for sensitive information, so it is entirely unrelated to identifying credit card numbers in documents.

  • ✗

    Windows Autopilot.

    Why it's wrong here

    Windows Autopilot is a device provisioning and deployment service that automates the setup and configuration of new Windows devices, including enrollment into Microsoft Endpoint Manager. It operates at the device lifecycle level and does not analyze file contents or enforce data classification, rendering it irrelevant to identifying documents containing credit card data.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.