MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Which TWO of the following are examples of Microsoft's commitments to data privacy as outlined in the Microsoft Privacy Statement and related agreements? (Choose two.)
⚠ Common exam trap
Many candidates confuse Microsoft's default data usage policies with those of other cloud providers, mistakenly assuming that customer data is automatically used for AI training or advertising, when in fact Microsoft explicitly prohibits these uses by default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customers can access and export their data.
The Microsoft Privacy Statement explicitly grants customers the right to access, export, and delete their data, aligning with data portability and control principles under regulations like GDPR. This commitment ensures that customers maintain ownership and control over their data stored in Microsoft 365 services.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft uses customer data to train AI models by default.
Why it's wrong here
Microsoft does not use customer data for AI training by default. Under the Online Services Terms and the Data Protection Addendum, Microsoft's use of customer data is limited to providing the cloud services and for legitimate business operations, and AI model training is not a default permitted use. For generative AI features, Microsoft may use your prompts and outputs to improve models, but only with an opt-in process and explicit customer agreement, and commercial customers can disable telemetry or must consent separately. So this statement is false because any AI training use requires explicit contractual permission and is not automatic.
- ✗
Microsoft may share customer data with third parties for marketing purposes.
Why it's wrong here
Microsoft does not share customer data with third parties for marketing purposes without consent. The Microsoft Privacy Statement and the Online Services Terms explicitly prohibit Microsoft from using customer data for advertising or marketing, and any sharing of customer data would require a lawful basis, such as customer instructions or a data processor agreement. Microsoft's contractual commitments ensure that customer data is only used for agreed purposes, and marketing would be an incompatible use unless the customer separately opted in. Therefore, it is not something Microsoft may do as a matter of course.
- ✓
Customers can access and export their data.
Why this is correct
This is a core Microsoft privacy commitment. Under the Microsoft Privacy Statement and the Online Services Terms, customers can access, correct, export, and delete their data at any time. This right to data portability is enforced through tools like the Microsoft 365 admin center, Azure portal, and Microsoft Purview compliance portal, which provide self-service data export capabilities. This transparency and control are part of Microsoft's "customer data is your data" principle, satisfying the requirement of customer control over their data.
- ✗
Microsoft allows third parties to access customer data without consent.
Why it's wrong here
Microsoft does not allow third-party access to customer data without customer consent, except under strictly defined legal requirements. For law enforcement or government requests, Microsoft follows the Law Enforcement Requests Report and requires a valid legal order, and even then it notifies customers where legally permitted. For other third parties, access is granted only through customer instructions, such as when a customer uses partner services or grants tenant permissions via Microsoft Entra ID, which is an explicit customer consent mechanism. Thus, third-party access is never a default allowance without consent.
- ✓
Customer data is not used for advertising.
Why this is correct
Microsoft explicitly states in its Privacy Statement that customer data from enterprise cloud services is not used for advertising. Unlike consumer services, which may show ads based on user data, Microsoft's commercial cloud (including Microsoft 365, Azure, and Dynamics 365) has a contractual commitment in the Online Services Terms that prohibits using customer data for advertising or any purpose other than providing the service. This is a key differentiator that reinforces Microsoft's trust and privacy commitments, and it is a verifiable statement under audit and compliance certifications.
Go deeper
Related to this question
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.