Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

An organization needs to ensure that all Microsoft 365 data is encrypted at rest and in transit. Which of the following is a built-in encryption mechanism in Microsoft 365?

⚠ Common exam trap

It's easy for candidates to confuse optional customer-managed encryption features (like CMK or OME) with the built-in, default encryption mechanisms (like BitLocker) that Microsoft automatically applies to all data at rest in its datacenters.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

BitLocker Drive Encryption

BitLocker Drive Encryption is a built-in encryption mechanism in Microsoft 365 that encrypts data at rest on physical drives within Microsoft datacenters. It uses AES 256-bit encryption to protect data stored on disk volumes, ensuring that even if physical drives are removed, the data remains unreadable. Additionally, Microsoft 365 uses TLS 1.2+ for data in transit, but BitLocker specifically addresses the 'at rest' requirement as a native, default encryption layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    BitLocker Drive Encryption

    Why this is correct

    Microsoft protects all Microsoft 365 data at rest in its datacenters with BitLocker Drive Encryption, which encrypts the entire physical drive using AES. This is a default, always-on layer applied to every disk hosting Exchange Online, SharePoint Online, and Teams content. Because it covers the full drive, it ensures that any Microsoft 365 data — regardless of workload or tenant — is encrypted at the disk level before any optional keys or services are considered.

  • ✗

    Customer-managed keys (CMK) using Azure Key Vault

    Why it's wrong here

    Customer-managed keys using Azure Key Vault are an optional, service-specific feature in Microsoft 365 for customers who need to control their own encryption keys, but they are not a built-in default for all data. Even when enabled, Customer Key only applies to selected workloads such as Exchange Online, SharePoint Online, and OneDrive, and it still depends on the underlying BitLocker encryption for the physical disk. It cannot serve as the universal assurance that every byte of Microsoft 365 data is encrypted, because it is not automatically active across the entire service.

  • ✗

    Office 365 Message Encryption

    Why it's wrong here

    Office 365 Message Encryption is a focused solution that encrypts individual email messages in transit and at rest for recipients, often using rights management to protect message content. It does not encrypt the underlying mailboxes, documents, or entire Microsoft 365 data stores, so it only covers the message body and attachments, not all data. Thus, it is a message-level control, not a platform-level encryption guarantee for all Microsoft 365 information.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection is primarily a classification and labeling service that lets organizations assign labels to documents and emails, and it can conditionally apply encryption when labels require it. The label is the core mechanism, and encryption only occurs if a label defines such protection; it does not automatically encrypt all data at rest. For a blanket requirement covering all Microsoft 365 data, AIP is a governance tool, not the foundational encryption layer that BitLocker provides.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.