Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Which TWO of the following are key capabilities of Microsoft Purview Communication Compliance? (Choose two.)

⚠ Common exam trap

MS-900 often tests whether candidates can distinguish Purview's many sub-solutions — Communication Compliance is frequently confused with Data Lifecycle Management (retention) or Insider Risk Management, so candidates must map each capability to the correct workload.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detect and respond to inappropriate messages

Option A is correct because Microsoft Purview Communication Compliance is specifically designed to detect potentially inappropriate, harassing, or offensive messages across channels like Teams, Exchange, and Viva Engage, and to let reviewers investigate and remediate them with actions such as tagging, notifying, or escalating. Option D is correct because the same solution supports regulatory compliance use cases by monitoring communications for policy violations tied to regulations (for example, FINRA, HIPAA, or insider trading), using trainable classifiers, sensitive information types, and review workflows. Option B is not a capability of Communication Compliance; multifactor authentication is enforced through Microsoft Entra ID (Conditional Access / authentication methods), not through communication monitoring policies. Option C is not part of Communication Compliance; retention labels are configured in Microsoft Purview Data Lifecycle Management / Records Management to govern how long content is kept. Option E is not a Communication Compliance feature; blocking external email forwarding is handled by Exchange Online transport rules, Defender for Office 365 anti-spam/anti-phishing policies, or DLP, not by Communication Compliance's detection-and-review model.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detect and respond to inappropriate messages

    Why this is correct

    Communication Compliance uses machine-learning classifiers and keyword policies to surface inappropriate messages such as harassment or threats, then routes them to reviewers for remediation. This satisfies the capability requirement by detecting and responding to policy-violating communications across Microsoft 365 channels.

  • ✗

    Enforce multifactor authentication

    Why it's wrong here

    Communication Compliance detects and reviews policy-violating messages across channels; it does not enforce sign-in controls. Multifactor authentication is configured through Microsoft Entra ID Conditional Access policies. Communication Compliance is correct when the requirement is detecting harassment, sensitive data or regulatory breaches in communications.

  • ✗

    Configure retention labels

    Why it's wrong here

    Retention labels belong to Microsoft Purview Data Lifecycle Management, governing how long content is kept, not Communication Compliance, which detects policy violations in messages. It is tempting because both are Purview compliance solutions, and retention labels would be the right choice when the requirement is to retain or delete content on a schedule.

  • ✓

    Monitor communications for regulatory compliance

    Why this is correct

    Communication Compliance monitors Microsoft 365 communications against regulatory and organisational policies, retaining flagged items for review and audit. This satisfies the capability requirement by providing ongoing oversight of communications for compliance obligations such as financial or industry regulations.

  • ✗

    Block external email forwarding

    Why it's wrong here

    Communication Compliance inspects and classifies message content for policy breaches; it cannot alter mail flow or stop a message being forwarded. Blocking external forwarding is configured through Exchange Online transport rules or anti-spam outbound policies. Communication Compliance fits detecting when sensitive information is shared externally.

Go deeper

Related to this question

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.