Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

An organization uses Microsoft 365 Copilot and wants to ensure that Copilot responses are based only on data the user has permission to access. Which principle does this enforce?

⚠ Common exam trap

MS-900 often tests the distinction between security principles — candidates may pick Zero Trust because it sounds more comprehensive, but the specific enforcement of user permissions is least privilege.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Least privilege

Microsoft 365 Copilot respects the permissions of the signed-in user, meaning it only surfaces data the user already has access to. This enforces the principle of least privilege by ensuring users cannot use Copilot to access information beyond their authorized scope. It does not grant new access; it inherits existing access controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Defense in depth

    Why it's wrong here

    Defense in depth layers independent controls so one failure does not expose the whole estate; it does not determine per-user content filtering in Copilot responses. It is tempting because layered security sounds relevant to data protection, so it would be correct if the question described overlapping network, endpoint and identity controls rather than Copilot respecting existing Microsoft 365 permissions.

  • ✗

    Segregation of duties

    Why it's wrong here

    Segregation of duties prevents one person holding conflicting responsibilities, such as both creating and approving payments; it does not govern which documents a search returns. It is tempting because both concepts involve restricting access, so it would be correct if the scenario described splitting approval authority across roles rather than Copilot surfacing only content the signed-in user may already open.

  • ✗

    Zero Trust

    Why it's wrong here

    Zero Trust concerns verifying explicitly and assuming breach across network, identity and device signals; it does not describe permission-trimmed content retrieval. It is tempting because Copilot honours existing Microsoft 365 permissions, which resembles least-privilege access, so it would be correct if the question asked about conditional access or continuous verification rather than permission inheritance in search results.

  • ✓

    Least privilege

    Why this is correct

    Least privilege ensures Copilot responses surface only content the signed-in user already has permission to access, because Copilot inherits the user's existing Microsoft 365 permissions. This satisfies the constraint that responses must respect each user's access rights.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.