Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

An organization uses Microsoft 365 and wants to automatically classify and protect sensitive data in SharePoint Online based on content patterns. Which Microsoft Purview solution should they implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-labeling policies

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on sensitive information types or patterns, classifying and protecting data without manual intervention. Option B (Retention policies) is incorrect because they manage data retention and deletion, not classification. Option C (DLP policies) is incorrect because they detect and prevent data loss but do not automatically classify content. Option D (Trainable classifiers) is incorrect because they use AI to identify content based on examples, not automatic pattern-based classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Auto-labeling policies

    Why this is correct

    Auto-labeling policies in Microsoft Purview scan SharePoint Online content using pattern-based rules, such as regex or sensitive information types, then apply sensitivity labels automatically. This satisfies the requirement to classify and protect data based on content patterns without manual intervention, unlike manual labelling or DLP policies that only alert or block.

  • ✗

    Retention policies

    Why it's wrong here

    Retention policies govern how long content is kept, or delete it, and never inspect content patterns or apply protection. They are tempting because they also target SharePoint Online, but they are correct when the requirement is lifecycle management, such as retaining records for seven years.

  • ✗

    Data Loss Prevention (DLP) policies

    Why it's wrong here

    DLP policies act on data already identified by sensitive information types; they do not themselves detect content patterns, and the stem asks for classification as well as protection. DLP is the right choice when detection rules exist and you must block sharing of that identified data.

  • ✗

    Trainable classifiers

    Why it's wrong here

    Trainable classifiers learn from labelled sample content, so they cannot act on pattern-based detection without a training set, and they only classify rather than enforce protection. They suit categorising unstructured content such as contracts or resumes where predefined sensitive information types cannot describe the data.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.