Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

South Ridge School District uses Microsoft 365 Education A5. They have 10,000 students and 1,000 staff. The district wants to ensure that student data is protected and that only authorized staff can access student records. They also need to comply with FERPA (Family Educational Rights and Privacy Act). The IT team has created security groups for teachers, administrators, and support staff. They want to restrict access to a specific SharePoint site containing student records to only the teachers group. Additionally, they want to prevent teachers from sharing the site with external users. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

In the SharePoint site settings, set the site permissions to 'Only members of the Teachers group can access' and set external sharing to 'Only people in your organization'.

Sharing controls in SharePoint site settings can be used to limit access to specific groups and disable external sharing. Option B (private channel) is for Teams, not SharePoint. Option C (sensitivity label) can restrict access but is not site-specific. Option D (site collection admin) does not restrict sharing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    In the SharePoint site settings, set the site permissions to 'Only members of the Teachers group can access' and set external sharing to 'Only people in your organization'.

    Why this is correct

    Setting the SharePoint site permissions to 'Only members of the Teachers group can access' directly assigns the site's visitor/member scope to that specific security group, ensuring only teachers can authenticate and open the site. In parallel, configuring external sharing to 'Only people in your organization' blocks any anonymous links or external user invitations, so students and external parties cannot be granted access regardless of how a link is shared. Together these two settings enforce both the intended user boundary and the organization-wide sharing boundary, which is exactly the requirement.

  • ✗

    Apply a sensitivity label to the site that restricts access to the teachers group.

    Why it's wrong here

    Applying a sensitivity label to the site primarily classifies the data and enforces protection policies, such as preventing external sharing or applying encryption to documents within it. However, sensitivity labels do not directly grant or restrict initial access to the SharePoint site itself for a specific Microsoft Entra ID security group. This is managed through SharePoint site permissions. Sensitivity labels would be the correct choice for classifying the sensitive student data and enforcing data protection policies, or for applying container-level policies like preventing external sharing, *after* initial site access has been configured.

  • ✗

    Add the teachers group as site collection administrators.

    Why it's wrong here

    Adding the teachers group as site collection administrators grants each teacher full control over site settings, permission inheritance, and site collection features. This action does not alter the default site permissions or external sharing configuration, so the site could remain accessible to students or external users unless someone manually changes it. Furthermore, site collection admins have elevated privileges that exceed the required 'only teachers can access' model, potentially allowing them to share the site more broadly without governance safeguards.

  • ✗

    Create a private channel in Microsoft Teams for teachers only.

    Why it's wrong here

    Creating a private channel in Microsoft Teams for teachers only establishes a restricted conversation workspace within a specific team, and the channel inherits its permissions from the team (or is scoped to named members) but does not affect the associated SharePoint site's access or sharing settings. The SharePoint site that backs the team remains governed by its own site permissions and external sharing configuration, which are independent of any channel-level privacy. Since the requirement is specifically about controlling access to the SharePoint site itself, this action is insufficient.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.