MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
Refer to the exhibit.
```json
{
"displayName": "Contoso AI Policy",
"description": "Policy to restrict Copilot data access",
"mode": "advanced",
"rules": [
{
"type": "sensitiveInformation",
"sensitiveInformationType": "CreditCardNumber",
"confidenceLevel": "high",
"action": "blockAccess"
}
]
}
```Refer to the exhibit. You are configuring a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft 365 compliance portal. The policy is intended to block access to files containing credit card numbers when accessed from outside the organization. However, users report that the policy is not blocking access. What is the most likely reason?
⚠ Common exam trap
Many exam-takers confuse policy mode with other settings like confidence level or location assignment, or assume 'advanced' is a valid mode similar to other Microsoft 365 features (e.g., advanced audit), when in fact DLP only supports 'enforce' and 'test' modes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy mode is set to 'advanced' which is not a valid mode; it should be 'enforce' or 'test'.
The policy mode 'advanced' is not a valid mode in Microsoft Purview DLP. The valid modes are 'enforce' (to actively block actions) and 'test' (to simulate policy effects without blocking). Setting the mode to an invalid value like 'advanced' would prevent the policy from enforcing any restrictions, explaining why access is not being blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy is not assigned to any locations.
Why it's wrong here
In Microsoft Purview DLP, location selection is a prerequisite — a policy with no assigned locations cannot be triggered. However, the exhibit does not support that conclusion; locations are usually configured as part of the policy wizard and are separate from the rule's mode setting. The visible problem is the invalid policy mode, not a missing location assignment.
- ✓
The policy mode is set to 'advanced' which is not a valid mode; it should be 'enforce' or 'test'.
Why this is correct
The mode column displays 'advanced', which is not a valid Microsoft Purview DLP policy mode. Valid modes are 'Enforce' and 'Test'; when a policy is in Enforce mode it applies protective actions, while Test mode lets you observe matches without blocking. An unhandled value such as 'advanced' means the policy is not validly configured and will not enforce, so this is the actual cause.
- ✗
The confidence level is set to 'high' which is too restrictive.
Why it's wrong here
A confidence level of 'high' for CreditCardNumber is not too restrictive; DLP's high confidence requires stronger evidence, but credit card numbers already require Luhn checksum validation in the sensitive info type. High confidence is the recommended setting for PCI-DSS-like data because it reduces false positives without missing legitimate card patterns. Therefore, this option does not identify the true misconfiguration.
- ✗
The sensitive information type is incorrect.
Why it's wrong here
CreditCardNumber is a built-in, Microsoft-maintained sensitive information type; it uses a regex and the Luhn algorithm to identify valid credit card numbers. Selecting it is appropriate for the intention of restricting credit card leakage. Thus, the sensitive information type itself is not a problem; the cause is the invalid policy mode.
Go deeper
Related to this question
Learn chapter
Entra ID Access Reviews
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.