MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
An organization wants to block sharing of documents containing credit card numbers. Which two statements are accurate about the Microsoft 365 capability involved?
⚠ Common exam trap
Many candidates confuse DLP with identity and access management (IAM) or assume DLP requires public exposure of documents, when in fact DLP is a content-aware security control that operates independently of access permissions and typically restricts sharing rather than requiring it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention policies
Data Loss Prevention (DLP) policies in Microsoft 365 are specifically designed to detect and block the sharing of sensitive information, such as credit card numbers, by scanning content for predefined or custom sensitive information types. When a match is found, DLP can enforce actions like blocking the share or sending a notification, directly addressing the organization's requirement. This capability operates across Exchange Online, SharePoint, OneDrive, and Teams, providing comprehensive protection against accidental or malicious data leaks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention policies
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) policies detect sensitive information types, such as credit card numbers, using built-in data classification patterns and then enforce actions like blocking external sharing, preventing transmission, or applying encryption across Exchange Online, SharePoint, OneDrive, and Teams. These policies can also trigger informative policy tips to users and generate audit events for compliance monitoring. This directly fulfills the requirement to block sharing of documents that contain credit card numbers.
- ✗
It replaces the need for identity and access management
Why it's wrong here
Data Loss Prevention (DLP) policies are content-based controls that inspect data for sensitive information types like credit card numbers, whereas identity and access management (IAM) governs authentication and authorization of users. DLP does not authenticate users or manage their permissions; instead, it applies protective actions such as blocking sharing or encrypting content after access has already been granted by IAM. Thus, DLP complements IAM rather than replacing it, and both are required for a complete security posture.
- ✗
It requires every document to be made public
Why it's wrong here
DLP policies do not alter the underlying permission model or visibility of documents; they operate on content in its existing location, applying actions only when sensitive data is detected. Enforcing DLP does not require changing access controls to make documents public—in fact, making them public would expand exposure and defeat the purpose of protecting credit card data. Instead, DLP can restrict sharing while leaving the original permissions unchanged for authorized internal users.
- ✓
The policy should be tested with a limited group before broad rollout
Why this is correct
Because DLP policies can inadvertently block legitimate business workflows or trigger false positives on content that resembles credit card data but is not actually sensitive, Microsoft recommends deploying them gradually. Using simulation mode or a pilot group with limited scope allows you to observe detection matches and refine conditions, exceptions, and policy tips before enterprise-wide enforcement. This reduces the risk of user disruption and ensures the policy aligns with real-world data flows.
Go deeper
Related to this question
Learn chapter
External Sharing in SharePoint and OneDrive
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.