Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Exhibit

Refer to the exhibit.

```json
{
  "Policy": "Communication Compliance",
  "Configuration": {
    "Name": "Harassment Detection",
    "Scopes": ["AllUsers"],
    "Conditions": [
      {
        "ConditionType": "SensitiveInformationTypes",
        "SensitiveInfoType": ["CreditCardNumber", "USSocialSecurityNumber"]
      },
      {
        "ConditionType": "KeywordMatch",
        "Keywords": ["harass", "bully", "intimidate"]
      }
    ],
    "Actions": ["NotifyManager", "NotifyComplianceOfficer"]
  }
}
```

You are configuring a Communication Compliance policy to detect workplace harassment. The policy currently includes conditions for sensitive information types (credit card numbers, SSN) and keywords. After deployment, the policy generates many irrelevant alerts for routine HR communications that contain the keywords but no harassment. What should you modify to improve detection accuracy?

⚠ Common exam trap

MS-900 often tests the difference between keyword-based detection and trainable classifiers, and candidates may incorrectly think that adding more keywords or SITs will improve accuracy, when in fact it can worsen false positives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a trainable classifier for 'harassment' instead of keyword matching

Trainable classifiers in Microsoft Purview use machine learning to identify specific types of content based on examples, rather than relying on predefined keywords or sensitive information types. For detecting workplace harassment, a trainable classifier can be trained with actual examples of harassing language, making it far more accurate than keyword matching, which often triggers false positives in routine HR communications. This directly addresses the problem of irrelevant alerts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Expand the keyword list to include more terms

    Why it's wrong here

    Adding more keywords widens the match surface, so routine HR messages containing those terms trigger even more irrelevant alerts rather than fewer. It is tempting because keyword conditions are easy to edit and do catch explicit harassment phrases, and would be correct when the policy misses genuine harassment wording entirely.

  • ✗

    Add more sensitive information types

    Why it's wrong here

    Adding sensitive information types broadens matching to more data patterns such as national ID or bank numbers, which are absent from routine HR text, so irrelevant keyword-triggered alerts persist. It is tempting because SITs give high-confidence detection, and would be correct when the policy must catch leaked personal or financial data.

  • ✗

    Enable audit logging for all communications

    Why it's wrong here

    Audit logging records activity across Microsoft 365 services for investigation; it does not alter which communications the policy classifies as harassment, so alert precision is unchanged. It is tempting because logs support forensic review after an incident, and would be correct for tracing who accessed what during an investigation.

  • ✓

    Use a trainable classifier for 'harassment' instead of keyword matching

    Why this is correct

    Trainable classifiers use machine learning trained on labelled examples to recognise contextual patterns of harassment, rather than matching isolated keywords. This reduces false positives from routine HR communications that merely contain those terms, improving detection accuracy.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.