Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A security administrator needs to automatically restrict access to documents that contain 'PII' (personally identifiable information) so that only employees in the 'Data Privacy' security group can view them. Additionally, editing and printing of these documents must be disabled. Which combination of Microsoft Purview features should be used?

⚠ Common exam trap

Watch out — candidates often confuse DLP policies with sensitivity labels, not realizing that DLP blocks data in motion or at rest but cannot enforce persistent document-level permissions like disabling editing or printing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sensitivity labels with auto-labeling and encryption that restricts permissions to the 'Data Privacy' group

Sensitivity labels in Microsoft Purview can be configured with auto-labeling to automatically detect and classify documents containing PII, and then apply encryption that restricts access to only the 'Data Privacy' security group. Additionally, the label can enforce usage rights such as 'View Only' to disable editing and printing, meeting all requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sensitivity labels with auto-labeling and encryption that restricts permissions to the 'Data Privacy' group

    Why this is correct

    This is the correct approach because sensitivity labels in Microsoft Purview can be configured to automatically detect sensitive data types (such as PII) during file uploads or edits, and then apply encryption that dynamically restricts access to approved members of the 'Data Privacy' group. The label's encryption settings enforce an 'only view' or 'co-author' permission level, meaning users outside the group cannot open the document even if they discover it. This combines classification with persistent access control, which directly satisfies the requirement.

  • Data Loss Prevention (DLP) policy with a block action

    Why it's wrong here

    A DLP policy with a block action stops unauthorized transmission or sharing of content—for example, emailing a document with credit card numbers outside the organization—but it does not modify existing permissions or the document's encryption state. Once a file is knowingly stored in SharePoint or OneDrive, a DLP block action does nothing to strip away access that users already have. Therefore, it prevents data exfiltration in transit but fails as a standalone mechanism for restricting access to already-stored documents containing PII.

  • Retention policy with a restrict action

    Why it's wrong here

    Retention policies are designed solely for data lifecycle management—they preserve a document for a compliance period, then delete it when the period expires; they have no 'restrict action' that can alter viewing or editing permissions. Even if a retention policy marked content as 'restricted,' it would not prevent a user with explicit SharePoint permissions from opening the file. Thus, retention cannot meet the requirement of restricting access to PII documents while keeping them accessible to only the Data Privacy group.

  • Privileged Identity Management (PIM)

    Why it's wrong here

    Privileged Identity Management (PIM) is an Azure AD feature for granting time-bound, approval-based roles to administrators (e.g., Global Administrator, Privileged Role Administrator); it does not issue or revoke permissions on individual documents. PIM controls who can manage Azure AD or Azure resources, not who can open a SharePoint file, so it cannot be used to restrict user access to documents containing PII. The scope is identity management at the directory level, not data access control at the file level.

About these practice questions

One of 217 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.