Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your organization uses Microsoft 365 E5 and wants to automatically classify emails containing credit card numbers as 'Sensitive' and apply encryption when sent externally. Which Microsoft Purview feature should you use?

⚠ Common exam trap

It's easy for candidates to confuse Microsoft Purview Information Protection (the umbrella suite) with the specific DLP feature, or they incorrectly assume sensitivity labels can automatically detect and encrypt based on content patterns without a DLP policy to trigger the label application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) is the correct feature because it is specifically designed to detect sensitive data types—such as credit card numbers—via built-in sensitive info types (e.g., Credit Card Number) and automatically enforce protective actions like blocking or encrypting emails when sent externally. Unlike sensitivity labels, DLP policies can inspect content in transit (Exchange Online) and apply encryption through transport rules or Office 365 Message Encryption (OME) without requiring user-applied labels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sensitivity labels

    Why it's wrong here

    Sensitivity labels in Microsoft Purview define classification and protection settings such as marking and encryption, but they do not by themselves scan outbound email as it is being sent. To automatically detect sensitive information like PII and apply encryption to external email, you must configure a DLP policy that uses conditions to apply the label or encryption action. Simply publishing a sensitivity label allows users to scope content, yet the orchestration of automated encryption at the transport layer is a DLP function. Thus, labels are a prerequisite, not the implementer of the automatic rule.

  • ✗

    Retention policies

    Why it's wrong here

    Retention policies under Microsoft Purview govern how long content must be kept or when it must be deleted, such as preserving email mailboxes for litigation or compliance. They do not inspect email content or apply encryption, and they have no rule engine for detecting sensitive data like credit card numbers or IDs. Retention settings act on the lifecycle of items, not on their classification or transport-time protection. Therefore, they cannot automate the encryption of external emails based on data patterns.

  • ✓

    Microsoft Purview Data Loss Prevention (DLP)

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) policies are the correct mechanism because they combine sensitive info type detection with rule actions. In an Exchange Online DLP policy, you create conditions that look for credit cards, PII, or custom patterns, and then set the action to 'Encrypt email messages' (using Azure Rights Management) when the condition matches. This operates at send time and can apply encryption dynamically to outbound messages, which is exactly what the organization wants to do. Additionally, DLP can optionally apply a sensitivity label for consistent protection across clients.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection is an umbrella suite that encompasses sensitivity labels, Azure Rights Management, and client-side classification, but it does not have its own policy engine for inspecting emails in transit. The specific feature that applies automatic encryption to outbound email based on data patterns is DLP inside the same Purview portal, not Information Protection as a standalone construct. Using a label manually or automatically in Outlook does not replace the need for a DLP rule to invoke encryption on external messages. Thus, while Information Protection provides the labeling pieces, the automation action is delivered by DLP.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.