MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Your organization uses Microsoft Purview to manage data governance. A data owner needs to classify sensitive data across SharePoint, OneDrive, and Exchange automatically based on content patterns. Which Microsoft Purview feature should they use?
⚠ Common exam trap
MS-900 often tests the confusion between DLP policies (which protect) and sensitivity labels (which classify and protect), causing candidates to pick DLP when the question asks for classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels with auto-labeling
Sensitivity labels with auto-labeling in Microsoft Purview are designed to automatically classify and label content based on sensitive information types (SITs) or trainable classifiers. They apply across SharePoint, OneDrive, and Exchange, matching content patterns to detect sensitive data. This is the correct feature for automatic classification based on content patterns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity labels with auto-labeling
Why this is correct
Auto-labelling sensitivity labels scan content across SharePoint, OneDrive and Exchange using pattern matching, applying classification automatically without manual intervention. This satisfies the requirement to classify sensitive data based on content patterns across all three workloads, which manual labelling cannot achieve at scale.
- ✗
eDiscovery (Premium)
Why it's wrong here
eDiscovery (Premium) identifies and collects content for legal cases, using custodians and review sets rather than persistent automatic classification. It is tempting because it searches the same workloads, but it would be correct for litigation hold and investigation workflows, not ongoing sensitivity labelling.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
DLP policies act on data already identified by sensitivity labels, enforcing rules such as blocking sharing; they do not themselves detect content patterns to classify items. It is tempting because DLP also spans SharePoint, OneDrive and Exchange, but that scenario assumes classification exists first.
- ✗
Audit (Standard)
Why it's wrong here
Audit (Standard) records user and admin activity for later investigation; it captures events about labelled items but never inspects content to assign a sensitivity label. It is tempting because it covers SharePoint, OneDrive and Exchange, yet it would be correct for compliance reporting and forensic tracing.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.