Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your organization uses Microsoft 365 Copilot and wants to ensure that sensitive data is not exposed through AI-powered features. Which Microsoft Purview capability should be configured?

⚠ Common exam trap

MS-900 often tests the misconception that Defender for Cloud Apps or Conditional Access governs Copilot data — the correct Purview workload for AI data governance is DLP scoped to Microsoft 365 Copilot.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Loss Prevention policies for Copilot

Microsoft Purview Data Loss Prevention (DLP) policies can be scoped specifically to Microsoft 365 Copilot, allowing organizations to detect and prevent sensitive data from being processed or surfaced by Copilot. This is the direct Purview control for governing data exposure through AI-powered features. Configuring a DLP policy with Copilot as the workload ensures that prompts and responses involving sensitive content are blocked or warned.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune app protection policies

    Why it's wrong here

    Intune app protection policies restrict copy, paste and save actions within managed mobile apps on enrolled or personal devices. They cannot inspect Copilot's grounding data or label-based content, which is what prevents sensitive data surfacing in AI responses. App protection would be correct for securing corporate data on BYOD phones.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps governs sanctioned SaaS usage and detects anomalous cloud activity, but it does not apply sensitivity labels or DLP policy tips to Copilot prompts and responses. It is tempting because it protects cloud apps, and it would be the right choice for discovering shadow IT or controlling session access to third-party SaaS.

  • ✓

    Microsoft Purview Data Loss Prevention policies for Copilot

    Why this is correct

    DLP policies for Copilot inspect prompts and responses in Microsoft 365 Copilot, blocking or auditing sensitive content as it is processed. This directly satisfies the requirement to prevent exposure of sensitive data through AI features, unlike sensitivity labels or retention policies, which classify or retain rather than block.

  • ✗

    Microsoft Entra Conditional Access

    Why it's wrong here

    Conditional Access controls sign-in risk and identity-based access to resources; it cannot detect or restrict sensitive content in Copilot prompts and responses. It is tempting because it governs access, but it would be correct for enforcing MFA or blocking risky sign-ins, not data loss prevention.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.