MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Your company, Contoso Ltd., has a Microsoft 365 E5 subscription with 500 users. The IT department recently discovered that some employees are sharing sensitive customer data via email with external parties. You need to implement a solution that automatically detects and prevents the sharing of credit card numbers and social security numbers in emails. The solution should notify the sender when a potential violation occurs and allow them to override the block by providing a business justification. The compliance team must be able to review these overrides. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft Purview compliance portal.
A Microsoft Purview Data Loss Prevention (DLP) policy can detect sensitive information types such as credit card numbers and social security numbers, and can be configured to block emails containing that data, notify the sender with an option to override by providing a business justification, and allow compliance team review of overrides. Option A is incorrect because Microsoft Defender for Office 365 Safe Attachments and Safe Links protect against malicious attachments and links, not against data leakage of sensitive information. Option C is incorrect because sensitivity labels are used for classification and protection (e.g., encryption) but not for blocking emails based on content. Option D is incorrect because an Exchange mail flow rule can block emails based on patterns but lacks the built-in sensitive info types, override with justification, and compliance review capabilities that DLP provides.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Microsoft Defender for Office 365 Safe Attachments and Safe Links.
Why it's wrong here
Safe Attachments and Safe Links inspect attachments and URLs for malware, not credit card or social security numbers in message bodies, so no data-loss block occurs. It tempts because Defender for Office 365 protects email, and would be correct for blocking phishing links and malicious attachments.
- ✓
Create a Microsoft Purview Data Loss Prevention (DLP) policy in the Microsoft Purview compliance portal.
Why this is correct
Microsoft Purview DLP policies inspect email content for sensitive information types such as credit card and social security numbers, blocking transmission automatically. Policy tips notify senders of violations and permit override with a business justification, while the compliance team reviews those overrides through activity explorer and DLP reports, satisfying every stated requirement.
- ✗
Create a sensitivity label with auto-labeling for emails containing sensitive data.
Why it's wrong here
Sensitivity labels classify and protect content but cannot block email delivery or capture sender override justifications for compliance review. It tempts because labels do detect sensitive information, and would be correct for applying encryption or visual markings to documents and messages rather than enforcing email flow.
- ✗
Create an Exchange mail flow rule to block emails containing sensitive data and send a non-delivery report.
Why it's wrong here
Mail flow rules can block messages matching sensitive patterns, but they cannot prompt the sender to supply a business justification or let them override the block. It tempts because transport rules do inspect email content, and would be correct for straightforward rejection without an override workflow.
Go deeper
Related to this question
Learn chapter
Data Governance and Retention
Key term
Safe Links
Safe Links is a Microsoft Defender for Office 365 feature that scans URLs in emails and documents in real time to protect users from malicious websites.
Key term
Office 365
Office 365 is a cloud-based subscription service from Microsoft that provides access to productivity applications like Word, Excel, and Outlook, along with other cloud services, for a monthly or annual fee.
About these practice questions
Courseiva writes every MS-900 question from scratch — 794 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.