Courseiva

MS-900 · domain

Describe security, compliance, privacy, and trust in Microsoft 365

This domain covers Microsoft 365 security, compliance, privacy, and trust concepts, including Defender, Purview, and Entra. The exam tests your ability to identify which service addresses specific risks, understand shared responsibility, and recognize compliance offerings like Service Trust Portal and audit logs, without deep configuration tasks.

207 questions36 easy124 medium47 hard

Focused practice

Practice Describe security, compliance, privacy, and trust in Microsoft 365 questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Describe security, compliance, privacy, and trust in Microsoft 365

Map each risk to the right tool: Defender for threat protection, Purview for compliance and data governance, Entra for identity. Most critical: know shared responsibility and that Microsoft secures the cloud, you secure your data.

Identify Microsoft Defender for Office 365 protections against phishing, malware, and zero-day threats.

Describe Microsoft Purview solutions for data classification, DLP, eDiscovery, and insider risk management.

Explain Microsoft Entra ID capabilities: conditional access, MFA, identity protection, and privileged identity management.

Recognize compliance offerings: Service Trust Portal, compliance manager, audit logs, and data residency options.

Watch out for

Common Describe security, compliance, privacy, and trust in Microsoft 365 exam traps

  • ▸Confusing Microsoft Defender for Office 365 with Defender for Endpoint, or assuming Defender for Identity is included in all plans.
  • ▸Mixing up Microsoft Purview compliance features like DLP and retention labels, or thinking they apply to all workloads by default.
  • ▸Believing Microsoft Entra ID Premium features like conditional access are available in free or basic Microsoft 365 plans.

Question index

All Describe security, compliance, privacy, and trust in Microsoft 365 questions (207)

Click any question to see the full explanation, or start a practice session above.

1

During a Microsoft 365 planning workshop, provide baseline anti-spam and anti-malware filtering for Exchange Online. Microsoft security, identity, or compliance capability should it use?

Medium
2

During requirements gathering, an IT manager says the organization must review employee messages for harassment or regulatory policy violations. Microsoft security, identity, or compliance capability should it use?

Medium
3

A compliance manager wants a dashboard that maps Microsoft 365 controls to regulatory standards and gives recommended improvement actions. Which portal capability should they use?

Medium
4

South Ridge School District uses Microsoft 365 Education A5. They have 10,000 students and 1,000 staff. The district wants to ensure that student data is protected and that only authorized staff can access student records. They also need to comply with FERPA (Family Educational Rights and Privacy Act). The IT team has created security groups for teachers, administrators, and support staff. They want to restrict access to a specific SharePoint site containing student records to only the teachers group. Additionally, they want to prevent teachers from sharing the site with external users. What should you configure?

Easy
5

An organization wants to ensure that only compliant devices can access Microsoft 365 resources. They use Microsoft Intune for device management. Which policy should they configure?

Medium
6

A security team wants to ensure that only devices that are compliant with company security policies (e.g., antivirus enabled, disk encrypted) can access Exchange Online and SharePoint Online. Which feature should they configure in Microsoft 365?

Medium
7

A compliance officer needs to automatically detect documents stored in SharePoint Online that contain sensitive data types (e.g., credit card numbers) and apply a sensitivity label that restricts access to only certain users. The classification should occur without user intervention and the label must be applied to the document. Which Microsoft Purview solution should be configured?

Medium
8

A security analyst receives an alert about a user who downloaded a large number of files from a SharePoint document library in a short period. The analyst needs to investigate the user's activities across Exchange, SharePoint, and Teams to determine if data exfiltration is occurring. Which Microsoft Purview solution should the analyst use to review detailed activity logs?

Medium
9

A financial services firm uses Microsoft 365 and must retain all business communications for 7 years to comply with SEC regulations. They also need to prevent users from permanently deleting emails. Which Microsoft Purview feature should they implement?

Medium
10

A tenant administrator is advising a department that wants to let users sign in once and access connected Microsoft 365 and SaaS apps. Microsoft security, identity, or compliance capability should it use?

Medium
11

During requirements gathering, an IT manager says the organization must classify files as Confidential and apply encryption to the most sensitive content. Microsoft security, identity, or compliance capability should it use?

Medium
12

Your company is subject to the General Data Protection Regulation (GDPR). Which Microsoft 365 compliance feature helps you respond to a Data Subject Request (DSR) to export a user's personal data?

Easy
13

A compliance-aware administrator is selecting the right Microsoft 365 capability to manage formal records that must be retained and disposed of according to policy. Microsoft security, identity, or compliance capability should it use?

Medium
14

A compliance officer needs to automatically encrypt any outgoing email that contains a customer's credit card number. The solution should work without requiring the sender to take any manual action. Which Microsoft Purview feature should be configured?

Medium
15

A legal team is preparing for litigation. They need to place a hold on all content (emails, documents, Teams messages) related to a specific project across the entire organization. The hold must prevent any deletion or modification of the content. Which Microsoft Purview solution should they use?

Hard
16

Your organization is migrating from on-premises Exchange to Exchange Online. You need to ensure that email communications comply with regulatory requirements for retention. Which Microsoft 365 feature should you use to define retention periods for emails?

Easy
17

A company wants to ensure that all Microsoft 365 admin actions are recorded and searchable for at least 180 days. They also need to create custom alert rules to notify the security team when critical events occur, such as a user being added to the Global Admin role. Which Microsoft Purview solution should they use?

Hard
18

A multinational corporation needs to ensure that all emails containing a customer's passport number are automatically blocked from being sent externally. Additionally, the sending user should receive a policy tip explaining the block. Which Microsoft Purview solution should be configured?

Hard
19

An administrator needs to ensure that only compliant devices can access Exchange Online. Which Microsoft Entra ID feature should they configure?

Easy
20

A compliance administrator needs to manage user sign-in risk and require MFA for risky sign-ins. Which Microsoft 365 capability is the best fit?

Medium
21

A compliance officer needs to automatically label and encrypt documents that contain personally identifiable information (PII) when they are saved in SharePoint. The labeling should happen without manual user intervention. Which Microsoft Purview feature should they configure?

Medium
22

A tenant administrator is advising a department that wants to grant temporary, approved privileged administrator access. Microsoft security, identity, or compliance capability should it use?

Medium
23

A multinational corporation must comply with GDPR. They need to ensure that personal data of EU residents is retained for a specific period and then securely deleted. Additionally, they must be able to respond to data subject access requests (DSARs) within 30 days by finding and exporting relevant data. Which two Microsoft Purview solutions should they use together? (Choose two.)

Hard
24

A security administrator needs to ensure that all users accessing Microsoft 365 resources from unmanaged devices are prompted to sign in using multi-factor authentication (MFA) and are blocked from downloading sensitive files. Which conditional access policy should be configured?

Medium
25

A department head asks which Microsoft 365 option should be used to search, review, and export content for a legal investigation. Microsoft security, identity, or compliance capability should it use?

Medium
26

Your company uses Microsoft Defender for Office 365 and wants to prevent users from clicking malicious links in email. A user reports that a known phishing link was not blocked. Which step should you take to investigate?

Medium
27

A compliance team needs to prevent employees from copying sensitive data (such as financial records or customer PII) to USB drives and other removable media from their Windows 10/11 devices. When a user attempts to copy data to an unapproved USB device, the action should be blocked and an alert should be generated. Which Microsoft Purview solution should they configure?

Medium
28

A company uses Microsoft Purview Communication Compliance to detect inappropriate messages. Which action can an administrator take after reviewing a flagged message?

Medium
29

Which TWO of the following are examples of Microsoft's commitments to data privacy as outlined in the Microsoft Privacy Statement and related agreements? (Choose two.)

Easy
30

Which THREE are core pillars of the Microsoft Trust Center?

Easy
31

Refer to the exhibit. The exhibit shows a Conditional Access policy. Which requirement does this policy enforce?

Hard
32

A system administrator at Contoso needs to ensure that all users are required to use multi-factor authentication when accessing Microsoft 365 services. Which Microsoft 365 feature should the administrator use to enforce this requirement?

Easy
33

A company needs to audit user activities in Microsoft 365 for compliance. Which tool should they use?

Easy
34

A company uses Microsoft 365 (a SaaS offering). A security incident occurs where an employee's account is compromised because the employee reused their corporate password on a personal website. According to the shared responsibility model, who is primarily responsible for this security failure?

Hard
35

A business stakeholder asks how Microsoft 365 can help them protect Windows endpoints with endpoint detection and response capabilities. Microsoft security, identity, or compliance capability should it use?

Medium
36

Your company wants to run a phishing simulation to test employee awareness. Which Microsoft 365 tool can you use to create and launch a simulated phishing campaign?

Easy
37

Which THREE of the following are security features included in Microsoft 365 Business Premium? (Choose three.)

Medium
38

A user accidentally shared a file containing credit card numbers with a partner organization. You need to prevent similar incidents and detect when such data is shared externally. What should you configure?

Medium
39

Which THREE are features of Microsoft Purview Information Protection?

Medium
40

Which TWO of the following are features of Microsoft Purview Information Protection?

Medium
41

A compliance officer wants to proactively prevent users from sending emails that contain sensitive personal data (e.g., credit card numbers) to external recipients. When a user attempts to send such an email, they should see a policy tip explaining the restriction and be blocked from sending. Which Microsoft Purview feature should be configured?

Hard
42

A company is preparing for a merger and wants to prevent communication between the Human Resources and Research departments regarding sensitive salary data during the due diligence period. They need a Microsoft Purview solution that can block all email and chat between users in these two groups, as well as prevent file sharing in Teams and SharePoint. Which solution should they configure?

Medium
43

Which TWO of the following are features of Microsoft Purview that help organizations meet compliance requirements for data lifecycle management? (Choose two.)

Medium
44

An organisation wants to identify documents containing credit card numbers and prevent users from sharing them externally from SharePoint Online and Exchange Online. Which two Microsoft Purview capabilities are most relevant? (Choose 2.)

Medium
45

A compliance administrator needs to retain mailbox content for legal investigation. Which Microsoft 365 capability is the best fit?

Medium
46

A compliance officer needs to automatically detect when an employee attempts to send an email containing a social security number (SSN) to an external recipient. The solution should block the email from being sent and notify the employee with a policy tip. Which Microsoft Purview solution should be configured?

Medium
47

A legal firm needs to send a confidential document to a client via email. The firm requires that the client cannot forward or print the email and that the email expires after seven days. Which Microsoft Purview solution should they use?

Medium
48

Which four of the following are key components of the Microsoft 365 defense-in-depth security strategy? (Choose all that apply. There are four correct answers.)

Medium
49

During a Microsoft 365 planning workshop, allow access to Exchange Online only from compliant devices. Microsoft security, identity, or compliance capability should it use?

Medium
50

A service owner is comparing Microsoft 365 capabilities and needs to prevent communication and collaboration between two business groups. Microsoft security, identity, or compliance capability should it use?

Medium
51

A security administrator needs to ensure that all guest users who access Microsoft Teams are required to accept a terms of use agreement before accessing any company resources. Which Microsoft 365 identity protection feature should they configure?

Medium
52

A department head asks which Microsoft 365 option should be used to provide a cloud identity platform for Microsoft 365 and approved SaaS applications. Microsoft security, identity, or compliance capability should it use?

Medium
53

An administrator is assigned the Global Reader role in Microsoft Entra ID as shown in the exhibit. What can this administrator do?

Hard
54

A company is deploying Microsoft 365 and needs to ensure that external sharing of sensitive documents is blocked. Which Microsoft Purview feature should they configure?

Medium
55

A user reports that they cannot access a SharePoint site that contains sensitive data. The administrator confirms the user is licensed and the site permissions are correct. What should the administrator check next?

Medium
56

A compliance administrator needs to apply encryption and usage restrictions to confidential documents. Which Microsoft 365 capability is the best fit?

Medium
57

An administrator is reviewing a request from users who need to detect risky users and suspicious sign-ins. Microsoft security, identity, or compliance capability should it use?

Medium
58

Which TWO are key capabilities of Microsoft Defender for Cloud Apps? (Choose two.)

Medium
59

A legal team needs to preserve all data belonging to a former employee who is involved in litigation. The preservation must cover Exchange Online email, SharePoint sites, Teams messages, and OneDrive files. Which Microsoft Purview solution should they use to enforce the preservation?

Hard
60

Your company is adopting Microsoft 365 Copilot and wants to ensure that data security and compliance requirements are met. Which THREE considerations should be addressed? (Choose three.)

Hard
61

A help desk lead is documenting the correct Microsoft 365 approach to allow browser access to SharePoint from unmanaged devices but restrict downloads. Microsoft security, identity, or compliance capability should it use?

Medium
62

An organization uses Microsoft Defender XDR and wants to investigate a potential ransomware attack. Which portal should the security team use to see the full attack timeline?

Medium
63

An administrator is reviewing a request from users who need to analyze attachments in a protected environment before delivery. Microsoft security, identity, or compliance capability should it use?

Medium
64

A compliance team needs to implement a Data Loss Prevention (DLP) policy to protect credit card information. What is the correct order of steps for a successful implementation?

Hard
65

A service owner is comparing Microsoft 365 capabilities and needs to make sign-in decisions based on risk, location, and device compliance. Microsoft security, identity, or compliance capability should it use?

Medium
66

Which TWO of the following are capabilities of Microsoft Priva? (Choose two.)

Hard
67

An organization uses Microsoft 365 Copilot and wants to ensure that AI-generated content is automatically labeled with a sensitivity label. What should they configure?

Hard
68

A compliance administrator needs to automatically protect sensitive data by applying a 'Confidential' label that encrypts documents and restricts access to a specific user group. The label must be applied when a document containing a credit card number is saved in SharePoint. Which Microsoft Purview feature should be configured?

Medium
69

A business stakeholder asks how Microsoft 365 can help them manage laptops and mobile devices with compliance policies and app protection. Microsoft security, identity, or compliance capability should it use?

Medium
70

A compliance administrator needs to apply encryption and usage restrictions to confidential documents. Which Microsoft 365 capability is the best fit? The design must avoid adding custom operational scripts.

Medium
71

An administrator is reviewing a request from users who need to discover cloud apps being used by employees and assess their risk. Microsoft security, identity, or compliance capability should it use?

Medium
72

Match each Microsoft 365 compliance term to its definition.

Medium
73

An organization needs to ensure that all Microsoft 365 data is encrypted at rest and in transit. Which of the following is a built-in encryption mechanism in Microsoft 365?

Easy
74

A financial services company must prevent users from accidentally sharing sensitive customer data externally. They want to block sharing of any document containing a credit card number via email or SharePoint. What combination of Microsoft 365 compliance solutions should they use?

Hard
75

A compliance team needs to ensure that any email sent from the Finance department that contains a bank account number is automatically encrypted. External recipients must be able to reply securely without needing to sign up for any service. Which Microsoft Purview solution should they configure?

Medium
76

A compliance officer at Fabrikam needs to ensure that all Microsoft 365 data is retained for exactly 7 years and then permanently deleted, regardless of user actions. Which Microsoft 365 capability should the officer use?

Medium
77

Which TWO components are part of Microsoft's Service Trust Portal?

Medium
78

A security team wants Microsoft 365 access to be allowed only when a user's device is marked compliant by management policy. Which two capabilities are normally combined? (Choose two.)

Medium
79

Your company uses Microsoft 365 and wants to ensure that when employees access Microsoft 365 from unmanaged devices, they can only view data but not download or print it. Which technology should you use?

Medium
80

During a Microsoft 365 planning workshop, let users reset forgotten passwords without calling the help desk. Microsoft security, identity, or compliance capability should it use?

Medium
81

Which TWO are features of Microsoft Entra ID? (Choose two.)

Easy
82

While preparing a Microsoft 365 adoption plan, a consultant is asked to give external partners controlled access to Teams and SharePoint resources. Microsoft security, identity, or compliance capability should it use?

Medium
83

A security administrator needs to audit all activities related to a specific user in Exchange Online, SharePoint Online, and Microsoft Entra ID for the past 90 days. They also need to export the audit log as a CSV file. Which Microsoft Purview solution provides this capability without additional licensing beyond Microsoft 365 E3?

Hard
84

Your company uses Microsoft 365 E5 and has enabled Microsoft Purview Audit (Premium). The security team needs to investigate a potential data breach by searching for all activities related to a specific user in the last 90 days. Which tool should they use?

Hard
85

A company uses Microsoft Purview to monitor for potential data security incidents. They want to automatically detect and remediate activities like downloading large amounts of data to a personal device. Which solution should they configure?

Medium
86

An administrator is reviewing a request from users who need to protect users from phishing, unsafe links, and malicious attachments. Microsoft security, identity, or compliance capability should it use?

Medium
87

You are configuring a Communication Compliance policy to detect workplace harassment. The policy currently includes conditions for sensitive information types (credit card numbers, SSN) and keywords. After deployment, the policy generates many irrelevant alerts for routine HR communications that contain the keywords but no harassment. What should you modify to improve detection accuracy?

Hard
88

A company is deploying Microsoft 365 and wants to ensure that customer financial data remains within the European Union. Which Microsoft 365 feature should the administrator configure?

Easy
89

A company wants to prevent employees from forwarding sensitive emails outside the organization. Which Microsoft Purview feature should they use?

Easy
90

A compliance administrator needs to assess compliance posture against standards and improvement actions. Which Microsoft 365 capability is the best fit? The design must avoid adding custom operational scripts.

Medium
91

Which THREE of the following are capabilities of Microsoft Entra ID that support identity security? (Choose three.)

Hard
92

A multinational company uses Microsoft 365 and wants to ensure that data stored in SharePoint Online is only accessible from specific geographic regions. The company has offices in the US, EU, and Asia. You need to implement a solution that restricts access based on the user's physical location. Which feature should you configure?

Hard
93

A service owner is comparing Microsoft 365 capabilities and needs to block emails containing credit card numbers from being sent externally. Microsoft security, identity, or compliance capability should it use?

Medium
94

An organization needs to prevent users from sharing documents that contain credit card numbers via email and Microsoft Teams. When a user attempts to share such a document, they should see a policy tip explaining the restriction. Which Microsoft Purview solution should the compliance team configure?

Hard
95

Which THREE conditions must be met for a Microsoft 365 tenant to use Customer Lockbox?

Hard
96

A healthcare provider must ensure that patient health information (PHI) is not accidentally shared outside the organization. They want to automatically detect if an email contains PHI (such as diagnosis codes) and block it from being sent externally. Additionally, the sender should receive a notification explaining the block. Which Microsoft Purview solution should be configured?

Hard
97

Contoso has a Microsoft 365 E5 tenant. The security team needs to investigate a potential insider data exfiltration incident. They must be able to review the original content of emails and documents that a specific user accessed, and preserve that content so it cannot be altered or deleted by the user during the investigation. Which Microsoft Purview capability should they use?

Medium
98

Which three of the following are core components of Microsoft’s Zero Trust security model as implemented in Microsoft 365? (Choose three.)

Medium
99

A department head asks which Microsoft 365 option should be used to review file access, sharing changes, and administrator actions during an investigation. Microsoft security, identity, or compliance capability should it use?

Medium
100

A company is expanding globally and needs to meet data residency and compliance requirements in multiple regions. Which three Microsoft 365 compliance and privacy features should they consider? (Choose three.)

Medium
101

A compliance officer needs to automatically classify and protect documents stored in SharePoint Online that contain personal data such as passport numbers. The classification should happen without user intervention and must apply encryption and access restrictions. Which Microsoft Purview solution should be configured?

Medium
102

A multinational corporation needs to restrict access to Microsoft 365 services based on user location and device state. They have offices in countries with strict data sovereignty laws. Which combination of Microsoft Entra ID features should they use to enforce these policies?

Hard
103

A company wants to ensure that sensitive documents classified as 'Confidential' are automatically encrypted and have restricted access permissions applied when they are shared via email. The protection must persist even if the email is forwarded to external parties. Which Microsoft Purview solution should be used?

Medium
104

A company is adopting Microsoft 365 and wants to ensure they can investigate security incidents across email, endpoints, and identities in a unified console. Which Microsoft 365 workload should they use?

Easy
105

A compliance officer needs to identify users who are at risk of leaking sensitive data based on their activities such as copying files to USB drives or emailing content outside the organization. The solution must also allow reviewing the activities in a case-based workflow. Which Microsoft Purview solution should they use?

Medium
106

An administrator needs to monitor and investigate potential data breaches by reviewing detailed records of file access and sharing activities across Microsoft 365. They require a centralized report showing who accessed what, from where, and any unusual patterns. Which tool should they use?

Medium
107

Which three options describe key capabilities of Microsoft Purview that help organizations manage compliance and data governance in Microsoft 365? (Choose three.)

Medium
108

An organization uses Microsoft 365 Copilot and wants to ensure that Copilot responses are based only on data the user has permission to access. Which principle does this enforce?

Medium
109

A company wants to ensure that all Microsoft 365 users authenticate using multi-factor authentication (MFA). Which Microsoft 365 security feature should they configure?

Easy
110

Fabrikam Inc. is a technology company that uses Microsoft 365 E5. They have implemented Microsoft Defender XDR to monitor for threats. The security team wants to receive alerts when a user is compromised, such as when a user's credentials are used from an unusual location. They also want to automatically block the user from signing in until the risk is mitigated. You need to configure a solution that automatically detects and responds to such identity risks. What should you configure?

Hard
111

A global financial services firm needs to protect highly confidential documents containing trade secrets. The protection must restrict access to a specific group of employees, prevent editing and printing, and remain enforced even if the document is downloaded and saved to an external device. Which Microsoft Purview solution should be used?

Hard
112

A compliance officer needs to automatically classify documents stored in SharePoint Online that contain personally identifiable information (PII) such as social security numbers. The classification must apply a sensitivity label that encrypts the document and restricts access to only employees in the Legal department. The process should run without any user interaction. Which Microsoft Purview solution should be configured?

Medium
113

A company wants to ensure that only managed and compliant devices can access corporate email in Microsoft 365. Which Microsoft Entra ID capability should they configure?

Easy
114

Your organization is deploying Microsoft 365 Copilot for sales teams. The compliance team requires that Copilot interactions with customer data in Dynamics 365 Sales be subject to retention policies. Which Microsoft Purview feature should you configure to manage this data?

Medium
115

Which TWO of the following are required to implement Microsoft Entra ID Conditional Access?

Easy
116

A legal team needs to place a hold on all data belonging to a specific user who is involved in a lawsuit. The hold must preserve Exchange Online email, SharePoint sites, and Teams chat messages. Which Microsoft Purview solution should they use?

Hard
117

An organization needs to automatically delete Microsoft Teams chat messages after 90 days to comply with a data minimization policy. Which Microsoft Purview feature should they use?

Easy
118

An organization is concerned about data leakage from sensitive emails. They want to enforce encryption on emails containing financial information automatically. Which Microsoft 365 solution should they configure?

Medium
119

A compliance officer wants to automatically encrypt outgoing emails containing credit card numbers and also prevent recipients from forwarding or copying the content. Which Microsoft Purview solution should be applied?

Hard
120

You have the above Microsoft Purview DLP policy JSON. What will this policy do?

Medium
121

A newly hired administrator at Northwind Traders needs to understand who can access customer data stored in Microsoft 365 and what Microsoft itself does with that data. Which Microsoft 365 Trust Center resource should they consult to review Microsoft's commitments about data handling, privacy, and security controls?

Easy
122

An organization must comply with GDPR and needs to respond to a data subject access request (DSAR) within 30 days. Which Microsoft Purview solution helps search for personal data across Microsoft 365?

Hard
123

A compliance administrator needs to ensure that any document containing a patient's health information (e.g., medical record number) is automatically encrypted and restricted to authorized users. The encryption should be enforced regardless of where the document is saved (SharePoint, OneDrive, or email). Which Microsoft Purview feature should they configure?

Hard
124

Your organization has a Microsoft 365 E5 subscription and wants to centrally manage security incidents across identities, endpoints, and cloud apps. Which Microsoft solution provides this capability?

Hard
125

A healthcare organization needs to automatically apply a sensitivity label to any document stored in a SharePoint document library that contains patient diagnosis codes. The label should prevent the document from being shared externally. The classification must happen after the document is saved, not during creation. Which Microsoft Purview solution should be configured?

Medium
126

A legal team at a company needs to preserve all data belonging to a user who is involved in litigation. The preservation must cover Exchange Online email, SharePoint sites, OneDrive for Business files, and Teams chat messages. They also need to be able to search the preserved content and export it. Which Microsoft Purview solution should they use?

Hard
127

Your organization uses Microsoft 365 E5 and wants to automatically classify emails containing credit card numbers as 'Sensitive' and apply encryption when sent externally. Which Microsoft Purview feature should you use?

Medium
128

Which THREE of the following are key pillars of the Microsoft Trusted Cloud? (Choose three.)

Easy
129

A Litware security team must ensure that when an employee leaves, their mailbox is preserved for five years and remains searchable by the eDiscovery team, but the mailbox must not consume an Exchange Online license. Which Microsoft 365 capability should they configure?

Hard
130

Which THREE capabilities are provided by Microsoft Purview Information Protection? (Choose three.)

Hard
131

A help desk lead is documenting the correct Microsoft 365 approach to require users to approve sign-ins with a mobile app after entering a password. Microsoft security, identity, or compliance capability should it use?

Medium
132

Match each Microsoft 365 pricing model to its description.

Medium
133

A security administrator needs to automatically restrict access to documents that contain 'PII' (personally identifiable information) so that only employees in the 'Data Privacy' security group can view them. Additionally, editing and printing of these documents must be disabled. Which combination of Microsoft Purview features should be used?

Hard
134

A security administrator needs to automatically restrict access to documents labeled as 'Highly Confidential' when accessed from devices that are not joined to the domain. The restriction should block editing and printing, and apply encryption. Which combination of Microsoft 365 solutions should the administrator use?

Hard
135

A company wants to prevent users from sharing documents that contain credit card numbers via email. When a user attempts to share such a document, they should see a policy tip explaining the restriction and the share should be blocked. Which Microsoft Purview solution should the compliance team configure?

Medium
136

An organization wants to block sharing of documents containing credit card numbers. Which two statements are accurate about the Microsoft 365 capability involved?

Medium
137

A user needs to sign in to Microsoft 365 from an untrusted device. The company requires multifactor authentication (MFA) for all external access. Which Microsoft Entra ID feature enforces this requirement?

Easy
138

Your organization is deploying Microsoft 365 for a healthcare company that must comply with HIPAA. Which Microsoft 365 compliance feature should you use to prevent sensitive patient data from being shared externally via email?

Easy
139

Which TWO of the following are key benefits of using Microsoft Purview Information Protection? (Choose two.)

Medium
140

A company needs to enforce that all documents marked as 'Confidential' are encrypted and cannot be printed. Which combination of Microsoft Purview features should they use?

Hard
141

Refer to the exhibit. The JSON shows compliance scores from Microsoft Purview Compliance Manager. Which action should the organization prioritize to improve its HIPAA compliance score?

Hard
142

You are the IT administrator for a non-profit organization that uses Microsoft 365 Business Basic. The organization has 50 volunteers who use their own personal devices to access email and SharePoint Online. The board of directors wants to ensure that if a volunteer's device is lost or stolen, the organization's data on that device can be removed remotely. They also want to ensure that volunteers use multi-factor authentication (MFA) to access corporate resources. What should you do?

Easy
143

While preparing a Microsoft 365 adoption plan, a consultant is asked to protect corporate data inside mobile apps without enrolling the whole personal device. Microsoft security, identity, or compliance capability should it use?

Medium
144

While preparing a Microsoft 365 adoption plan, a consultant is asked to identify risky user behaviour such as unusual downloads or policy violations. Microsoft security, identity, or compliance capability should it use?

Medium
145

A help desk lead is documenting the correct Microsoft 365 approach to track compliance assessments and improvement actions. Microsoft security, identity, or compliance capability should it use?

Medium
146

Which TWO of the following are examples of security defaults in Microsoft Entra ID? (Choose two.)

Easy
147

A multinational company must comply with the General Data Protection Regulation (GDPR). They need to be able to search for and delete personal data of a user upon request (right to erasure). Which Microsoft Purview solution should they use?

Hard
148

A compliance officer needs to set up a policy that automatically monitors and detects activities related to accessing sensitive data from outside the corporate network. When a user from a foreign country accesses a confidential file, the policy should trigger an alert and require additional authentication. Which combination of Microsoft 365 solutions achieves this?

Hard
149

Your organization wants to ensure that data sent to Microsoft 365 is encrypted in transit. Which protocol should you enforce for all client connections?

Easy
150

A company must comply with a regulation that requires all data stored in Microsoft 365 to remain within the European Union. Which Microsoft 365 feature should an administrator configure to enforce this geographic restriction?

Medium
151

A company wants to ensure that only IT administrators can install browser extensions in Microsoft Edge. Which Microsoft 365 security feature should be used?

Medium
152

A healthcare organization must ensure that electronic protected health information (ePHI) in Microsoft 365 is encrypted both at rest and in transit. Which Microsoft 365 feature provides encryption for data in transit?

Medium
153

A compliance officer needs to automatically retain all SharePoint documents that contain a specific project code for exactly 5 years. The retention must be applied automatically when the document is uploaded, without any user interaction. Which Microsoft Purview feature should they configure?

Medium
154

Your organization uses Microsoft 365 Copilot and wants to ensure that sensitive data is not exposed through AI-powered features. Which Microsoft Purview capability should be configured?

Easy
155

A security administrator at Contoso wants to ensure that sensitive documents in SharePoint Online are automatically encrypted and access is restricted to specific users, even if the document is shared externally. Which Microsoft 365 feature should the administrator use?

Hard
156

A legal firm needs to automatically encrypt and apply access restrictions to all documents that contain case numbers considered highly confidential. The protection must remain enforced even if the document is emailed to external parties or saved to a personal device. Which Microsoft Purview solution should be configured?

Hard
157

Which THREE of the following are valid data subject rights under GDPR? (Choose three.)

Medium
158

A healthcare organization stores patient records in SharePoint Online. They need to ensure that the data is encrypted at rest and in transit. Which statement is true regarding Microsoft 365 encryption?

Easy
159

A user reports receiving a phishing email that bypassed Exchange Online Protection (EOP). You need to investigate the threat and automate a response across email, endpoints, and identities. Which Microsoft 365 security solution should you use?

Medium
160

A business stakeholder asks how Microsoft 365 can help them allow sign-in using biometrics or FIDO2 security keys. Microsoft security, identity, or compliance capability should it use?

Medium
161

A healthcare organization must encrypt outbound email automatically when a message contains passport numbers. Which two Microsoft Purview capabilities are commonly combined? (Choose two.)

Medium
162

An organization wants to prevent employees from sharing sensitive files with external users via SharePoint Online, but they need to allow sharing with a specific external partner for a single project. What is the most efficient configuration?

Hard
163

Contoso has Microsoft 365 E3 and a hybrid identity environment with Microsoft Entra Connect. Security policy requires that when a user's on-premises Active Directory account is disabled, their Microsoft 365 access must stop within minutes without an administrator manually touching the cloud account. Which Microsoft 365 capability should you rely on to meet this requirement?

Medium
164

A security administrator needs to review all sign-in attempts and identify suspicious login patterns for the past 30 days. Which Microsoft 365 portal should they use to access this information?

Easy
165

During requirements gathering, an IT manager says the organization must make document protection persist after a file is downloaded or emailed. Microsoft security, identity, or compliance capability should it use?

Medium
166

Drag and drop the steps to configure a data loss prevention (DLP) policy in the Microsoft 365 compliance center into the correct order.

Medium
167

A global company needs to ensure that only employees in the 'HR' security group can access a specific set of HR documents stored in SharePoint. If a user outside the group attempts to view or copy the content, it must be blocked. The protection must persist even if someone downloads the files and shares them externally, or if the files are saved to a personal device. Which Microsoft Purview solution should be used?

Hard
168

A tenant administrator is advising a department that wants to automatically apply a label when sensitive customer identifiers are detected. Microsoft security, identity, or compliance capability should it use?

Medium
169

A compliance officer needs to automatically detect when employees share customers' personal data (e.g., social security numbers) via email and block such sharing. Which Microsoft Purview solution should they configure?

Medium
170

A compliance administrator needs to block sharing of documents containing credit card numbers. Which Microsoft 365 capability is the best fit?

Medium
171

A compliance-aware administrator is selecting the right Microsoft 365 capability to require MFA only for sign-ins from outside trusted locations. Microsoft security, identity, or compliance capability should it use?

Medium
172

A user reports receiving a phishing email in their Outlook inbox. The organization uses Microsoft Defender for Office 365. Which feature should the user use to report the email to the security team?

Easy
173

A compliance officer needs to ensure that any document containing passport numbers automatically gets a 'Highly Confidential' label and is encrypted when saved in SharePoint. The labeling should occur without any user interaction. Which Microsoft Purview feature should they configure?

Hard
174

Your organization is implementing Microsoft Entra ID (formerly Azure AD) for identity management. Users report that they are prompted for multifactor authentication (MFA) every time they sign in, even from trusted devices. What should you configure to reduce MFA prompts while maintaining security?

Easy
175

A law firm uses Microsoft 365 and wants to ensure that only authorized users can access client files stored in SharePoint Online. They also need to track when these files are accessed. Which combination of features should they use?

Medium
176

Your company wants to ensure that only managed and compliant devices can access Microsoft 365 resources. Which Microsoft 365 security feature enforces conditional access based on device compliance?

Easy
177

A legal team is involved in a court case and needs to identify all emails and documents related to a specific project across the entire organization. They need to place these items on hold to prevent deletion or modification. Which Microsoft Purview solution should they use?

Medium
178

A compliance administrator needs to assess compliance posture against standards and improvement actions. Which Microsoft 365 capability is the best fit?

Medium
179

A healthcare organization is using Microsoft 365 and needs to ensure that patient data (protected health information) is not accidentally shared externally. They want to classify all documents containing medical terms and apply automatic encryption when shared outside the organization. Which two Microsoft Purview features should they combine? (Select TWO)

Hard
180

A company wants to ensure that all outgoing emails containing sensitive financial data are encrypted automatically. The encryption should require the recipient to authenticate to read the message. Which Microsoft 365 solution should the administrator configure?

Easy
181

An organization wants to automatically detect when a user attempts to share a document containing a customer's credit card number via email. The system should block the sharing and display a warning to the user. Which Microsoft Purview solution should they configure?

Medium
182

Litware Inc. is a law firm that uses Microsoft 365 E5. They have a requirement to preserve all communications between attorneys and clients as legal hold for ongoing litigation. The legal team needs to identify and preserve all relevant emails and documents from specific users. The preservation should be indefinite until the hold is released. The IT team has enabled Litigation Hold for the mailboxes of the involved users. However, the legal team also needs to preserve documents in SharePoint Online and OneDrive for Business. What should you do to preserve the documents?

Medium
183

A compliance officer needs to ensure that all user activities related to sensitive data in Microsoft 365 are recorded and available for forensic investigation. They require detailed logs of who accessed specific files in SharePoint Online, including attempts to access files that were blocked by DLP policies. Which solution should they enable?

Hard
184

A compliance administrator needs to automatically detect when employees share documents containing a customer's credit card number via email and block such sharing before the email is sent. Which Microsoft Purview solution should they configure?

Medium
185

Your organization uses Microsoft 365 Business Premium. You need to protect users from phishing attacks by blocking malicious links in real-time when they click them in emails. Which feature provides this capability?

Easy
186

While preparing a Microsoft 365 adoption plan, a consultant is asked to let users report suspicious phishing messages from Outlook for investigation. Microsoft security, identity, or compliance capability should it use?

Medium
187

A security administrator at Adventure Works is reviewing how Microsoft 365 protects data at rest and in transit across Exchange Online, SharePoint Online, and Teams. Which TWO statements accurately describe Microsoft 365 encryption behavior in this environment? (Choose two.)

Medium
188

A compliance administrator needs to investigate emails that may be part of a phishing campaign. Which Microsoft 365 capability is the best fit?

Medium
189

A compliance-aware administrator is selecting the right Microsoft 365 capability to delete content automatically after a defined retention period. Microsoft security, identity, or compliance capability should it use?

Medium
190

A business stakeholder asks how Microsoft 365 can help them periodically review group memberships and application access. Microsoft security, identity, or compliance capability should it use?

Medium
191

Your company is deploying Microsoft Purview to manage data subject requests (DSRs) under GDPR. Users need to submit requests to access or delete their personal data. Which Microsoft Purview solution should you use?

Medium
192

During a Microsoft 365 planning workshop, show security recommendations and a score for Microsoft 365 posture. Microsoft security, identity, or compliance capability should it use?

Medium
193

A legal team needs to preserve all data related to a specific user involved in litigation, including Exchange emails, SharePoint documents, OneDrive files, and Teams chats. They require a hold that cannot be removed by the user and must allow for later searching and export. Which Microsoft Purview solution should they use?

Medium
194

A security administrator at Contoso wants to ensure that users can only access Microsoft 365 services from compliant devices that meet specific security requirements, such as having encryption enabled and a minimum OS version. Which Microsoft 365 feature should the administrator use?

Medium
195

A help desk lead is documenting the correct Microsoft 365 approach to preserve relevant mailboxes and SharePoint content during a legal case. Microsoft security, identity, or compliance capability should it use?

Medium
196

A compliance-aware administrator is selecting the right Microsoft 365 capability to encrypt email messages sent to internal or external recipients. Microsoft security, identity, or compliance capability should it use?

Medium
197

Which TWO of the following are key capabilities of Microsoft Purview Communication Compliance? (Choose two.)

Medium
198

A service owner is comparing Microsoft 365 capabilities and needs to detect exact customer records rather than only generic data patterns. Microsoft security, identity, or compliance capability should it use?

Medium
199

Your organization uses Microsoft Purview to manage data governance. A data owner needs to classify sensitive data across SharePoint, OneDrive, and Exchange automatically based on content patterns. Which Microsoft Purview feature should they use?

Medium
200

A compliance officer needs to automatically retain all emails in Exchange Online for exactly 7 years, and then permanently delete them. Which Microsoft Purview solution should they configure?

Easy
201

An organization uses Microsoft 365 and wants to automatically classify and protect sensitive data in SharePoint Online based on content patterns. Which Microsoft Purview solution should they implement?

Medium
202

Your organization wants to ensure that users can only access Microsoft 365 resources from compliant devices. Which security feature should you implement?

Easy
203

A compliance officer needs to ensure that all outgoing emails containing a customer's credit card number are automatically encrypted before delivery. External recipients must be able to reply with the same level of encryption without a separate signing-up process. Which Microsoft Purview solution should be configured?

Hard
204

Drag and drop the steps to deploy Microsoft 365 Apps for enterprise to a Windows device using the Microsoft 365 Apps admin center into the correct order.

Medium
205

A compliance officer needs to ensure that all emails and documents in Exchange Online and SharePoint are automatically retained for five years. After five years, the data should be automatically deleted. Which Microsoft Purview solution should they configure?

Medium
206

Your company, Contoso Ltd., has a Microsoft 365 E5 subscription with 500 users. The IT department recently discovered that some employees are sharing sensitive customer data via email with external parties. You need to implement a solution that automatically detects and prevents the sharing of credit card numbers and social security numbers in emails. The solution should notify the sender when a potential violation occurs and allow them to override the block by providing a business justification. The compliance team must be able to review these overrides. What should you configure?

Easy
207

During requirements gathering, an IT manager says the organization must discover where sensitive information is stored across Microsoft 365. Microsoft security, identity, or compliance capability should it use?

Medium

Frequently asked questions

What does the Describe security, compliance, privacy, and trust in Microsoft 365 domain cover on the MS-900 exam?
Map each risk to the right tool: Defender for threat protection, Purview for compliance and data governance, Entra for identity. Most critical: know shared responsibility and that Microsoft secures the cloud, you secure your data.
How many questions are in this domain?
This page lists all 207 Describe security, compliance, privacy, and trust in Microsoft 365 questions in the MS-900 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Describe security, compliance, privacy, and trust in Microsoft 365 questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ms-900 MS-900 describe security compliance privacy and trust in microsoft 365 Practice Questions