MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which four of the following are key components of the Microsoft 365 defense-in-depth security strategy? (Choose all that apply. There are four correct answers.)
⚠ Common exam trap
It's easy for candidates to confuse operational features like versioning or backup with core security layers, or mistakenly believe Microsoft has unrestricted access to customer data, when in fact the shared responsibility model and strict access controls are fundamental to the defense-in-depth strategy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Physical security of datacenters, including biometric access controls and 24/7 monitoring.
The Microsoft 365 defense-in-depth strategy relies on multiple layers of security controls. Physical security of datacenters (biometric access, 24/7 monitoring) is the foundational layer. User identity protection via Microsoft Entra ID MFA and Conditional Access secures the authentication layer. Data encryption at rest (BitLocker) and in transit (TLS) protects data confidentiality. Advanced Threat Protection (ATP) for email, SharePoint, and Teams defends against malware and phishing at the workload layer. These four components collectively implement a layered security model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Physical security of datacenters, including biometric access controls and 24/7 monitoring.
Why this is correct
Physical security of datacenters is a foundational defense-in-depth layer that prevents unauthorized on-site access to Microsoft 365 infrastructure. It includes biometric access controls, multi-factor authentication for technicians, 24/7 surveillance via CCTV and sensors, and a layered perimeter from fences to server cages. This matters because even the strongest logical controls lose all value if an attacker can physically tamper with or steal hardware, so continuous monitoring and strict entry controls are non-negotiable for protecting customer data at the infrastructure layer.
- ✓
User identity protection via Microsoft Entra ID Multi-Factor Authentication (MFA) and Conditional Access.
Why this is correct
User identity protection is the identity layer of defense in depth, addressing credential-based attacks. Microsoft Entra ID Multi-Factor Authentication (MFA) requires a second factor like a phone notification or biometric, making stolen passwords alone insufficient. Conditional Access evaluates real-time signals—such as user risk, device compliance, and geographic location—to allow or block access, enforcing least-privilege and zero-trust principles. Together, these controls dramatically reduce account takeover, which is a primary vector for data breaches.
- ✓
Data encryption at rest and in transit, using technologies like BitLocker and TLS.
Why this is correct
Data encryption ensures confidentiality at both at-rest and in-transit states, forming a critical data-layer control. At rest, BitLocker encrypts physical disks in datacenters, while service-side encryption protects tenant data in SharePoint, OneDrive, and Exchange; in transit, TLS secures connections between clients and Microsoft 365 services. Encryption also covers backup and replicated copies, and keys are managed via Azure Key Vault. Without encryption, sensitive data would be readable if storage media is stolen or network traffic is intercepted, so this layer is fundamental to Microsoft 365's security architecture.
- ✗
Automated rollback of all user changes to previous versions within 24 hours.
Why it's wrong here
Automated rollback of all user changes within 24 hours is not a security control and does not exist in Microsoft 365. While services retain version histories and backups (e.g., SharePoint versioning or Exchange litigation hold), those support recovery from accidental deletion or malicious modification, not proactive security. Rolling back every change indiscriminately would disrupt legitimate collaboration and business workflows, and it fails to prevent data exfiltration, malware installation, or account compromise, which are the actual goals of defense-in-depth layers.
- ✓
Advanced Threat Protection (ATP) for email, SharePoint, and Teams, including anti-malware and anti-phishing.
Why this is correct
Advanced Threat Protection (ATP), now known as Microsoft Defender for Office 365, protects content collaboration and mail flow. Safe Attachments detonates files in a sandbox to detect zero-day malware; Safe Links dynamically blocks malicious URLs at click time. Anti-phishing and anti-malware policies extend protection to SharePoint, OneDrive, and Teams, not just email. This layer addresses user risk from malicious payloads, which otherwise can bypass traditional signature-based security, making it a key component of Microsoft 365's defense-in-depth strategy.
- ✗
Unrestricted access for Microsoft engineers to all customer data for continuous security scanning.
Why it's wrong here
Unrestricted access for Microsoft engineers is the exact opposite of a security control; Microsoft operates a zero-standing-access model. Engineers receive access only through a just-in-time (JIT) process, with high-risk escalation requiring approval and auditing, and Customer Lockbox provides customer control over certain data-access requests. Unrestricted access would create insider threats and violate Microsoft 365's compliance certifications, such as ISO 27001 and SOC 2, which mandate least-privilege access and strict monitoring—so this option is not a component of defense in depth.
Go deeper
Related to this question
Learn chapter
Exchange Online Protection (EOP)
Key term
Microsoft Entra ID
Microsoft Entra ID is a cloud-based identity and access management service that lets employees sign in and access resources both inside and outside of your organization.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.