Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Drag and drop the steps to configure a data loss prevention (DLP) policy in the Microsoft 365 compliance center into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Step 1: Select a DLP template or start with a custom policy. Step 2: Choose the locations (Exchange, SharePoint, OneDrive, Teams) where the policy applies. Step 3: Define the policy rules with conditions and actions.

DLP policies are created in the compliance center by selecting a template, locations, and rules.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Step 1: Select a DLP template or start with a custom policy. Step 2: Choose the locations (Exchange, SharePoint, OneDrive, Teams) where the policy applies. Step 3: Define the policy rules with conditions and actions.

    Why this is correct

    Selecting a DLP template first is correct because templates provide prebuilt rule categories (e.g., PII, financial, health) that align with common compliance regulations. After establishing the policy type, you then scope it to the appropriate locations such as Exchange, SharePoint, OneDrive, and Teams—since not every rule type is available in every location. Finally, you define or customize the specific rules (conditions and actions) based on the template and the chosen workloads, which is the logical wizard flow in Microsoft Purview.

  • ✗

    Step 1: Choose locations (Exchange, SharePoint, OneDrive, Teams). Step 2: Select a DLP template or start with a custom policy. Step 3: Define the policy rules with conditions and actions.

    Why it's wrong here

    Placing location selection before template selection is incorrect because the available conditions and actions for a DLP policy are largely determined by the template you choose. For example, a PCI-DSS template predefines rules for credit card numbers, whereas a custom policy starts with no defaults—so without a template first, you have no baseline rules to attach to the locations. Additionally, the Microsoft Purview DLP wizard enforces the template-first order, so this sequence does not reflect the actual configuration process.

  • ✗

    Step 1: Define the policy rules with conditions and actions. Step 2: Select a DLP template or start with a custom policy. Step 3: Choose locations (Exchange, SharePoint, OneDrive, Teams).

    Why it's wrong here

    Defining rules before selecting a template or locations is impractical because rules are dependent on both the template's built-in rule patterns and the specific workloads they will apply to. In the Microsoft Purview interface, you cannot even advance to the rule-definition step without first selecting a template and then choosing locations, since the UI enforces that dependency. Furthermore, some conditions (like fingerprinting for custom sensitive info) and actions (like end-user notification) are only supported in certain locations, making it technically impossible to fully define rules in isolation.

  • ✗

    Step 1: Select a DLP template or start with a custom policy. Step 2: Define the policy rules with conditions and actions. Step 3: Choose locations (Exchange, SharePoint, OneDrive, Teams).

    Why it's wrong here

    Selecting the template first but then defining rules before locations is incorrect because the location selection is a required prerequisite for the rule-definition step in the DLP policy wizard. Rules must reference the specific workloads they apply to—for instance, whether a block action is allowed in Exchange versus Teams—so without locations chosen, you cannot accurately evaluate which rule actions are valid. The wizard is explicitly designed to collect locations before rules, and this order ensures that rule conditions and actions are scoped appropriately.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.