Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Match each Microsoft 365 compliance term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Policy to prevent accidental sharing of sensitive information

Process to search and export content for legal cases

Rule to keep or delete content for a specified time

Tags to classify and protect data based on sensitivity

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention (DLP): Helps prevent sensitive data from being shared or exposed.

Microsoft 365 compliance features include Data Loss Prevention (prevent data leaks), eDiscovery (search and export for legal needs), Retention Policies (manage content lifecycle), and Sensitivity Labels (classify and protect). Common confusions involve mixing the definitions of these tools.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data Loss Prevention (DLP): Helps prevent sensitive data from being shared or exposed.

    Why this is correct

    Data Loss Prevention (DLP) is a proactive protection mechanism that uses content analysis to detect sensitive information—such as credit card numbers, Social Security numbers, or classified PII—and then applies automated actions like blocking sharing, encrypting messages, or showing policy tips. DLP policies operate across Exchange, SharePoint, OneDrive, Teams, and endpoints, continuously monitoring data in motion and at rest. This is distinct from eDiscovery or retention because DLP's goal is to prevent data breaches, not to find content for legal review or manage content lifecycle.

  • ✓

    eDiscovery: Used to search for and export content for legal or compliance purposes.

    Why this is correct

    eDiscovery is a reactive investigative workflow in Microsoft Purview that lets authorized users search across Exchange, SharePoint, OneDrive, and Teams for content relevant to legal requests or internal investigations. It offers capabilities such as legal holds, keyword and filter-based searches, and the export of results in a prompt and forensically sound manner. Unlike DLP, eDiscovery does not prevent data leakage; it retrieves existing content and preserves it for evidence while litigation or compliance reviews are active.

  • ✓

    Retention Policies: Rules that control how long content is kept and when it is deleted.

    Why this is correct

    Retention Policies are lifecycle governance rules that specify how long content must be kept and what action is taken when that period expires—typically a permanent deletion or a retention period extension. They apply broadly to locations like mailboxes, SharePoint sites, OneDrive accounts, and Teams channel messages, and they override user deletions until the configured period ends. Unlike Sensitivity Labels, retention policies do not classify data or encrypt it; they solely manage the timeline for which content must exist and when it can be safely removed.

  • ✓

    Sensitivity Labels: Classify and protect data based on sensitivity.

    Why this is correct

    Sensitivity Labels are classification and protection controls that attach metadata to documents and emails, enabling settings like 'Confidential' or 'Highly Restricted' along with protection actions such as encryption, watermarking, and access restrictions. These labels travel with the content across Microsoft 365 and even when files leave the organization, ensuring consistent protection. Unlike retention policies, sensitivity labels do not determine deletion or retention durations; they focus on identifying data sensitivity and safeguarding it from unauthorized access.

  • ✗

    Data Loss Prevention (DLP): Used to search for and export content for legal or compliance purposes.

    Why it's wrong here

    This statement is incorrect because the ability to search for and export content for legal or compliance purposes is the definition of eDiscovery, not Data Loss Prevention. DLP does not provide on-demand search or export capabilities; instead, it proactively scans content as it is created, shared, or transmitted, and enforces protection policies when sensitive data matches predefined rules. While both are part of Microsoft Purview, they serve fundamentally different functions: DLP prevents exposure, whereas eDiscovery supports investigations by discovering and producing content.

  • ✗

    Retention Policies: Classify and protect data based on sensitivity.

    Why it's wrong here

    This description is wrong for Retention Policies because classifying and protecting data based on sensitivity is exclusively the role of Sensitivity Labels. Retention Policies operate at the macro level, defining how long content is kept in locations like mailboxes and sites, and what deletion action should occur after that period—they do not evaluate data sensitivity or apply encryption. A retention policy might keep a document for seven years, but it will never label that document as 'Confidential' or restrict who can open it; those tasks belong to sensitivity labels.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your organization is planning to use Microsoft Purview to meet compliance requirements. Which TWO capabilities are part of Microsoft Purview? (Choose two.)

easy
  • A.Data Classification
  • B.Advanced Threat Analytics
  • ✓ C.Data Loss Prevention (DLP)
  • ✓ D.Data Lifecycle Management
  • E.Insider Risk Management

Why C: Data Loss Prevention (DLP) helps organizations detect and prevent sensitive information from being shared inappropriately, and Data Lifecycle Management manages the retention and deletion of data to comply with regulations. Both are core capabilities of Microsoft Purview. Advanced Threat Analytics is part of Microsoft Defender for Identity, not Purview. Data Classification and Insider Risk Management are also Purview capabilities, but the question requires exactly two correct answers: DLP and Data Lifecycle Management.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.