Courseiva
mediumDrag & DropObjective-mapped

MS-900 Practice Question: Drag and drop the steps to perform an eDiscovery…

Drag and drop the steps to perform an eDiscovery content search in the Microsoft 365 compliance center into the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a new content search, then specify the locations to search, then define the search query, then preview and review the results

eDiscovery content search involves creating a search, specifying locations, query, and reviewing results.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a new content search, then specify the locations to search, then define the search query, then preview and review the results

    Why this is correct

    In Microsoft Purview eDiscovery, a content search must first be created as a container object before any configuration can be applied. You then select the specific locations (Exchange mailboxes, SharePoint sites, OneDrive accounts, or Teams) to define the scope, because the search query is evaluated against exactly those chosen content sources. After the scope is set, you enter keywords or condition filters in KQL, and only then can you preview and review the results, since preview executes the query against the indexed items in the specified locations.

  • Create a new content search, then define the search query, then specify the locations to search, then preview and review the results

    Why it's wrong here

    The flaw in this sequence is that defining the search query before specifying the locations breaks the logical dependency: a query such as "subject:project AND date>=2024-01-01" has no meaning until you know which mailboxes or sites it will be run against. In the eDiscovery UI, the Conditions and Keywords section is not fully functional until at least one location is selected, because the search engine needs a defined scope to construct the query. Without locations, any query you attempt to build would have an indeterminate target, and the preview step would fail to return relevant results.

  • Specify the locations to search, then create a new content search, then define the search query, then preview and review the results

    Why it's wrong here

    You cannot specify locations to search before creating the content search itself, because the location picker (for selecting mailboxes, SharePoint, etc.) is a property of an existing, saved search object. The New Content Search command creates the search job that holds all configuration; the locations are then added to that search's settings. Attempting to pick locations first would be like choosing filters for a query that doesn't exist yet—there is no container to store or execute those location selections, so the sequence is invalid from the start.

  • Create a new content search, then specify the locations to search, then preview and review the results, then define the search query

    Why it's wrong here

    This sequence is invalid because previewing and reviewing results is an execution step that runs the current search query against the indexed content; if you have not yet defined a search query, the preview would have no criteria to evaluate, so it would either return every item from the specified locations (causing a massive, unintended export) or the UI would block the preview action entirely. The order of operations requires that the query is built and refined before any preview, because the preview pane is designed to show matches for the exact conditions you have set. Defining the query after the preview step reverses cause and effect—you cannot review results of a search that has not yet been defined.

About these practice questions

This MS-900 question is part of Courseiva's 217-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.