Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

An organization wants to block sharing of documents containing credit card numbers. Which two statements are accurate about the Microsoft 365 capability involved?

⚠ Common exam trap

Many candidates confuse DLP with identity and access management (IAM) or assume DLP requires public exposure of documents, when in fact DLP is a content-aware security control that operates independently of access permissions and typically restricts sharing rather than requiring it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention policies

Data Loss Prevention (DLP) policies in Microsoft 365 are specifically designed to detect and block the sharing of sensitive information, such as credit card numbers, by scanning content for predefined or custom sensitive information types. When a match is found, DLP can enforce actions like blocking the share or sending a notification, directly addressing the organization's requirement. This capability operates across Exchange Online, SharePoint, OneDrive, and Teams, providing comprehensive protection against accidental or malicious data leaks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data Loss Prevention policies

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) policies detect sensitive information types, such as credit card numbers, using built-in data classification patterns and then enforce actions like blocking external sharing, preventing transmission, or applying encryption across Exchange Online, SharePoint, OneDrive, and Teams. These policies can also trigger informative policy tips to users and generate audit events for compliance monitoring. This directly fulfills the requirement to block sharing of documents that contain credit card numbers.

  • ✗

    It replaces the need for identity and access management

    Why it's wrong here

    Data Loss Prevention (DLP) policies are content-based controls that inspect data for sensitive information types like credit card numbers, whereas identity and access management (IAM) governs authentication and authorization of users. DLP does not authenticate users or manage their permissions; instead, it applies protective actions such as blocking sharing or encrypting content after access has already been granted by IAM. Thus, DLP complements IAM rather than replacing it, and both are required for a complete security posture.

  • ✗

    It requires every document to be made public

    Why it's wrong here

    DLP policies do not alter the underlying permission model or visibility of documents; they operate on content in its existing location, applying actions only when sensitive data is detected. Enforcing DLP does not require changing access controls to make documents public—in fact, making them public would expand exposure and defeat the purpose of protecting credit card data. Instead, DLP can restrict sharing while leaving the original permissions unchanged for authorized internal users.

  • ✓

    The policy should be tested with a limited group before broad rollout

    Why this is correct

    Because DLP policies can inadvertently block legitimate business workflows or trigger false positives on content that resembles credit card data but is not actually sensitive, Microsoft recommends deploying them gradually. Using simulation mode or a pilot group with limited scope allows you to observe detection matches and refine conditions, exceptions, and policy tips before enterprise-wide enforcement. This reduces the risk of user disruption and ensures the policy aligns with real-world data flows.

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.