MS-900 Describe Microsoft 365 apps and services Practice Question
An organization wants to use Microsoft 365 to automatically classify and protect sensitive data in emails and documents. Which service should they use?
⚠ Common exam trap
Test-takers frequently confuse Microsoft Defender for Office 365 (which protects against threats) with Purview Information Protection (which classifies and protects data), leading them to select Option C because they associate 'protect' with security rather than data governance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Information Protection
Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides data classification, labeling, and protection capabilities directly within Microsoft 365. It uses sensitivity labels to automatically classify emails and documents based on conditions like content patterns or custom keywords, and then applies encryption, rights management, or visual markings (e.g., headers/footers) to protect sensitive data both at rest and in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Information Protection
Why this is correct
Microsoft Purview Information Protection automatically classifies and protects sensitive data by applying sensitivity labels based on sensitive info types, trainable classifiers, and machine-learning models. It can trigger encryption or access restrictions immediately when content is created or edited, making it the direct answer for automatic data-level protection.
- ✗
Microsoft Intune
Why it's wrong here
Microsoft Intune is a cloud-based service for managing user devices and applications, enforcing device compliance, and applying mobile app management policies like PINs and data transfer restrictions. However, it inspects device and app configuration, not file content, so it cannot automatically classify or label sensitive information like credit card numbers or personal data.
- ✗
Microsoft Defender for Office 365
Why it's wrong here
Microsoft Defender for Office 365 protects against email-borne threats such as phishing, ransomware, malware, and malicious links using Safe Links, Safe Attachments, and anti-phishing policies. It is a reactive threat-defense system that blocks malicious content before it reaches the mailbox, but it does not assign persistent sensitivity labels or perform continuous data classification within documents.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID, formerly Azure Active Directory, is an identity and access management service that authenticates users, enforces conditional access, and manages permissions via role-based access control and multi-factor authentication. It verifies who can sign in and what resources they can access, but it does not inspect the content of files or emails to determine data sensitivity.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.