MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Exhibit
Refer to the exhibit.
```json
{
"Policy": "Communication Compliance",
"Configuration": {
"Name": "Harassment Detection",
"Scopes": ["AllUsers"],
"Conditions": [
{
"ConditionType": "SensitiveInformationTypes",
"SensitiveInfoType": ["CreditCardNumber", "USSocialSecurityNumber"]
},
{
"ConditionType": "KeywordMatch",
"Keywords": ["harass", "bully", "intimidate"]
}
],
"Actions": ["NotifyManager", "NotifyComplianceOfficer"]
}
}
```You are configuring a Communication Compliance policy to detect workplace harassment. The policy currently includes conditions for sensitive information types (credit card numbers, SSN) and keywords. After deployment, the policy generates many irrelevant alerts for routine HR communications that contain the keywords but no harassment. What should you modify to improve detection accuracy?
⚠ Common exam trap
MS-900 often tests the difference between keyword-based detection and trainable classifiers, and candidates may incorrectly think that adding more keywords or SITs will improve accuracy, when in fact it can worsen false positives.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a trainable classifier for 'harassment' instead of keyword matching
Trainable classifiers in Microsoft Purview use machine learning to identify specific types of content based on examples, rather than relying on predefined keywords or sensitive information types. For detecting workplace harassment, a trainable classifier can be trained with actual examples of harassing language, making it far more accurate than keyword matching, which often triggers false positives in routine HR communications. This directly addresses the problem of irrelevant alerts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Expand the keyword list to include more terms
Why it's wrong here
Adding more keywords widens the match surface, so routine HR messages containing those terms trigger even more irrelevant alerts rather than fewer. It is tempting because keyword conditions are easy to edit and do catch explicit harassment phrases, and would be correct when the policy misses genuine harassment wording entirely.
- ✗
Add more sensitive information types
Why it's wrong here
Adding sensitive information types broadens matching to more data patterns such as national ID or bank numbers, which are absent from routine HR text, so irrelevant keyword-triggered alerts persist. It is tempting because SITs give high-confidence detection, and would be correct when the policy must catch leaked personal or financial data.
- ✗
Enable audit logging for all communications
Why it's wrong here
Audit logging records activity across Microsoft 365 services for investigation; it does not alter which communications the policy classifies as harassment, so alert precision is unchanged. It is tempting because logs support forensic review after an incident, and would be correct for tracing who accessed what during an investigation.
- ✓
Use a trainable classifier for 'harassment' instead of keyword matching
Why this is correct
Trainable classifiers use machine learning trained on labelled examples to recognise contextual patterns of harassment, rather than matching isolated keywords. This reduces false positives from routine HR communications that merely contain those terms, improving detection accuracy.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.