Courseiva

MS-900 Describe Microsoft 365 apps and services Practice Question

An organization needs to enforce that all external emails are automatically encrypted before delivery to recipients. Which feature should they configure in Microsoft 365?

⚠ Common exam trap

Candidates often confuse Microsoft Purview sensitivity labels or DLP policies as the direct mechanism for automatic encryption, when in fact mail flow rules are the correct transport-level feature to enforce encryption on all external emails without relying on user action or client-side configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Exchange Online mail flow rules

Exchange Online mail flow rules (also known as transport rules) can be configured to automatically encrypt all external emails by applying Office 365 Message Encryption (OME) based on conditions such as recipient domain or sender address. This allows the organization to enforce encryption for all outbound messages without requiring user intervention, meeting the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    S/MIME

    Why it's wrong here

    S/MIME is a user-level encryption method that relies on a public/private key pair and a certificate issued for each individual mailbox. It typically must be explicitly selected by the sender or configured per-user in Outlook, and the recipient also needs the corresponding certificate and S/MIME support, making it impractical for automatically encrypting all external email at the organizational level.

  • ✗

    Microsoft Purview Data Loss Prevention

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) is designed to detect specific sensitive information patterns, such as credit card or social security numbers, and then take actions like blocking or quarantining the message. It does not apply blanket encryption to every external email; it only acts when a policy condition matching sensitive content is met, so a message with no sensitive data would be delivered unencrypted.

  • ✓

    Exchange Online mail flow rules

    Why this is correct

    Exchange Online mail flow rules (transport rules) can be configured with a condition like 'The recipient is outside the organization' and an action to apply Microsoft Purview Message Encryption, which automatically encrypts all outbound messages without requiring end-user action. This makes it the correct native mechanism for enforcing encryption on every email sent to external recipients, as it operates at the transport layer and applies uniformly.

  • ✗

    Microsoft Purview sensitivity labels

    Why it's wrong here

    Microsoft Purview sensitivity labels can encrypt messages, but they are typically applied manually by users or through automatic classification policies based on content inspection. Without a label applied to the message, no encryption occurs, and labels are not inherently designed to be applied to all external email as a transport-level rule, so they do not guarantee that every external email is encrypted.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.