Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

A company is preparing for a merger and wants to prevent communication between the Human Resources and Research departments regarding sensitive salary data during the due diligence period. They need a Microsoft Purview solution that can block all email and chat between users in these two groups, as well as prevent file sharing in Teams and SharePoint. Which solution should they configure?

⚠ Common exam trap

Watch out — candidates often confuse Information Barriers with DLP, assuming that blocking sensitive data patterns is equivalent to blocking all communication between groups, but DLP cannot enforce department-wide communication restrictions—it only acts on content matches.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Information Barriers

Information Barriers (IB) in Microsoft Purview are specifically designed to prevent communication and collaboration between defined user groups, such as HR and Research, by blocking email, Teams chat, and SharePoint/OneDrive file sharing. This solution enforces policies at the transport and service level, ensuring that sensitive salary data is not inadvertently shared during the merger due diligence period.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Information Barriers

    Why this is correct

    Information Barriers in Microsoft Purview are purpose-built to restrict real-time and async collaboration between defined user segments. Admins define segments based on attributes like department or organization and create policy rules that block one-way or two-way communication; the policy is enforced by the service layer itself across Exchange Online, Microsoft Teams, and file-sharing workflows. This goes far beyond individual content protection—it prohibits the relationship itself, so an attempted email or Teams chat between barred users is rejected before the message is delivered.

  • Data Loss Prevention (DLP)

    Why it's wrong here

    Data Loss Prevention (DLP) is a content-inspection engine that scans emails and files for sensitive information types such as credit card numbers, Social Security numbers, or custom data elements, and applies actions like blocking transmission or restricting external sharing. DLP policies do not maintain a graph of which employees may interact with each other; they only evaluate whether the content matches a sensitive pattern. Thus, a message between two users from conflicting groups that contains no sensitive data will pass freely, because DLP never considers the sender–recipient relationship.

  • Sensitivity Labels

    Why it's wrong here

    Sensitivity Labels apply classification and protection (e.g., encryption, watermark, or 'do not forward') to documents and emails after they are created, but they are tied to the artifact, not to user-to-user communication channels. A label can revoke permissions to a specific file, but it cannot stop two employees from exchanging text messages, chat messages, or voice calls unless those interactions involve a labeled piece of content. In short, sensitivity labels protect the data wherever it lives, not the flow of communication between people.

  • eDiscovery (Premium)

    Why it's wrong here

    eDiscovery (Premium) is a forensic and investigative workflow for legally holding, searching, reviewing, analyzing, and exporting content from Exchange, SharePoint, Teams, and other Microsoft 365 workloads. It is inherently backward-looking: it helps locate and preserve evidence that has already been created, making it useful for litigation or compliance investigations. It has no real-time policy engine that can intercept or block arbitrary communications between user groups, so it cannot act as an access control or communication barrier mechanism.

Go deeper

Related to this question

About these practice questions

Courseiva writes every MS-900 question from scratch — 217 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.