Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your organization is deploying Microsoft 365 for a healthcare company that must comply with HIPAA. Which Microsoft 365 compliance feature should you use to prevent sensitive patient data from being shared externally via email?

⚠ Common exam trap

MS-900 often tests the difference between features that protect data (DLP) and those that merely audit or encrypt after the fact, causing candidates to confuse DLP with Message Encryption or eDiscovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) is designed to identify, monitor, and automatically protect sensitive information across Microsoft 365 workloads, including Exchange Online, SharePoint, OneDrive, and Teams. DLP policies can detect sensitive data types such as HIPAA-related identifiers (e.g., U.S. Social Security numbers, medical record numbers) and enforce actions like blocking external email sharing or requiring encryption. This directly addresses the requirement to prevent sensitive patient data from being shared externally via email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Purview Message Encryption

    Why it's wrong here

    Message Encryption protects email content in transit and at rest, but it does not detect or block sharing of patient data, so it cannot prevent external disclosure. It is tempting because encryption is the right control when the requirement is confidentiality of a message already being sent.

  • ✗

    Microsoft Purview eDiscovery

    Why it's wrong here

    eDiscovery locates and preserves content for legal proceedings after the fact; it does not intercept or block outbound email containing patient data. It is tempting because eDiscovery is correct when the requirement is identifying and holding existing records for litigation or regulatory investigation.

  • ✗

    Microsoft Purview Audit

    Why it's wrong here

    Audit records activity and retains logs for investigation; it cannot block outbound email. Preventing sensitive patient data leaving via email requires Data Loss Prevention policies that inspect content and enforce blocking rules at send time. Audit would be chosen for compliance evidence and forensic review after an incident, not prevention.

  • ✓

    Microsoft Purview Data Loss Prevention (DLP)

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) enforces policies that scan email content and attachments for sensitive data types, such as medical record numbers or diagnosis codes, and automatically blocks external sharing when a HIPAA-defined information type is detected. This satisfies the stem’s requirement to prevent patient data from leaving the organisation via email, using content analysis and rule-based actions rather than relying on user permissions alone.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.