MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which TWO of the following are capabilities of Microsoft Priva? (Choose two.)
⚠ Common exam trap
MS-900 often tests the distinction between Priva and Purview capabilities, causing candidates to select retention labels, which are a Purview feature, not Priva.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automate subject rights requests
Microsoft Priva includes Subject Rights Requests, which lets organizations automate the intake, tracking, and fulfillment of data subject requests (DSRs) under regulations like GDPR and CCPA, so option A is correct. Priva also provides Privacy Risk Management capabilities, including the ability to assess and remediate privacy risks in data transfers across tenants and regions, making option C correct. Option B is not a Priva capability; retention labels are configured through Microsoft Purview records management and data lifecycle management. Option D is incorrect because network traffic monitoring is handled by tools such as Microsoft Defender for Cloud Apps or network security solutions, not Priva. Option E is incorrect because malware detection in email attachments is performed by Microsoft Defender for Office 365, not Priva.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Automate subject rights requests
Why this is correct
Priva's Subject Rights Requests automates the entire DSR workflow—discovering personal data across Exchange, SharePoint, OneDrive, and Teams, verifying the requester's identity, applying suppression and redaction, and generating auditable completion reports. It uses AI to help classify and locate data, and its template library maps directly to GDPR and CCPA rights, reducing manual effort and legal risk.
- ✗
Configure retention labels
Why it's wrong here
Retention labels are configured in Microsoft Purview Data Lifecycle Management, where administrators define policies to keep or delete content after a specified period based on items' classification. Priva, by contrast, does not manage retention schedules or disposition; its purpose is to help organizations discover and manage personal data to meet privacy obligations, not to enforce information-governance retention rules.
- ✓
Assess privacy risks in data transfers
Why this is correct
Priva's Data Transfer Risk Assessment tracks telemetry from Microsoft 365 audit logs and signals to detect when personal data is sent to domains outside the organization's approved ecosystem, flagging locations with insufficient legal protections. It evaluates the context and volume of transfers, allowing privacy officers to rank risky sharing behaviors and take corrective actions to meet cross-border data-transfer compliance (e.g., EU Standard Contractual Clauses).
- ✗
Monitor network traffic
Why it's wrong here
Monitoring network traffic—including inspecting packet-level flow, IP addresses, ports, and bandwidth usage—is performed by network-centric security tools such as Microsoft Defender for Network (or third-party network analyzers), not by Priva. Priva operates at the data plane above the network, using metadata and classifications rather than raw traffic, so it cannot detect anomalies like exfiltration or DOS attacks.
- ✗
Detect malware in email attachments
Why it's wrong here
Malware detection in email attachments is delivered through Microsoft Defender for Office 365 and its Safe Attachments feature, which detonates files in a sandbox using threat intelligence to block malicious content before delivery. Priva is a privacy-management solution, not a security-protection engine, so it has no role in examining message payloads for viruses, ransomware, or phishing attempts.
Go deeper
Related to this question
Learn chapter
Benefits of Microsoft Cloud
Key term
Defender for Cloud Apps
Defender for Cloud Apps is a Microsoft cloud access security broker (CASB) that helps you discover, protect, and govern your cloud applications and data across multiple cloud environments.
Key term
Anti-phishing policy
An anti-phishing policy is a set of rules and technical controls that organizations use to detect, block, and respond to email or message-based attacks that trick users into revealing sensitive information.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.