Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your company, Contoso Ltd., has a Microsoft 365 E5 subscription with 500 users. The IT department recently discovered that some employees are sharing sensitive customer data via email with external parties. You need to implement a solution that automatically detects and prevents the sharing of credit card numbers and social security numbers in emails. The solution should notify the sender when a potential violation occurs and allow them to override the block by providing a business justification. The compliance team must be able to review these overrides. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft Purview compliance portal.

A Microsoft Purview Data Loss Prevention (DLP) policy can detect sensitive information types such as credit card numbers and social security numbers, and can be configured to block emails containing that data, notify the sender with an option to override by providing a business justification, and allow compliance team review of overrides. Option A is incorrect because Microsoft Defender for Office 365 Safe Attachments and Safe Links protect against malicious attachments and links, not against data leakage of sensitive information. Option C is incorrect because sensitivity labels are used for classification and protection (e.g., encryption) but not for blocking emails based on content. Option D is incorrect because an Exchange mail flow rule can block emails based on patterns but lacks the built-in sensitive info types, override with justification, and compliance review capabilities that DLP provides.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Defender for Office 365 Safe Attachments and Safe Links.

    Why it's wrong here

    Safe Attachments and Safe Links inspect attachments and URLs for malware, not credit card or social security numbers in message bodies, so no data-loss block occurs. It tempts because Defender for Office 365 protects email, and would be correct for blocking phishing links and malicious attachments.

  • ✓

    Create a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft Purview compliance portal.

    Why this is correct

    Microsoft Purview DLP policies inspect email content for sensitive information types such as credit card and social security numbers, blocking transmission automatically. Policy tips notify senders of violations and permit override with a business justification, while the compliance team reviews those overrides through activity explorer and DLP reports, satisfying every stated requirement.

  • ✗

    Create a sensitivity label with auto-labeling for emails containing sensitive data.

    Why it's wrong here

    Sensitivity labels classify and protect content but cannot block email delivery or capture sender override justifications for compliance review. It tempts because labels do detect sensitive information, and would be correct for applying encryption or visual markings to documents and messages rather than enforcing email flow.

  • ✗

    Create an Exchange mail flow rule to block emails containing sensitive data and send a non-delivery report.

    Why it's wrong here

    Mail flow rules can block messages matching sensitive patterns, but they cannot prompt the sender to supply a business justification or let them override the block. It tempts because transport rules do inspect email content, and would be correct for straightforward rejection without an override workflow.

About these practice questions

Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.