Courseiva

MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365

Your organization wants to ensure that data sent to Microsoft 365 is encrypted in transit. Which protocol should you enforce for all client connections?

⚠ Common exam trap

Watch out — candidates often confuse HTTPS (the URL scheme) with the underlying encryption protocol TLS, leading them to select HTTPS instead of TLS 1.2, even though HTTPS is merely the application-layer wrapper that relies on TLS for actual encryption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

TLS 1.2

TLS 1.2 is the correct protocol because Microsoft 365 enforces TLS 1.2 or later for all client-to-service connections to ensure data is encrypted in transit. TLS provides end-to-end encryption for HTTP-based traffic (including HTTPS) and is the standard protocol used by Microsoft 365 services like Exchange Online, SharePoint Online, and Teams. Enforcing TLS 1.2 ensures that older, less secure versions like TLS 1.0 and 1.1 are blocked, meeting the organization's encryption requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec

    Why it's wrong here

    IPsec operates at the network layer (Layer 3) and is typically employed to build encrypted VPN tunnels between sites, hosts, or subnets. It does not provide per-connection encryption for client applications talking to Microsoft 365; those clients use Transport Layer Security on each TCP connection. Selecting IPsec would be the wrong encryption mechanism for securing client-to-cloud HTTPS traffic.

  • ✓

    TLS 1.2

    Why this is correct

    TLS 1.2 is the encryption protocol Microsoft 365 requires for inbound client connections; Microsoft disabled TLS 1.0 and 1.1 for these services. It authenticates the server using digital certificates, negotiates a symmetric session key, and then encrypts the application data flowing between the client and cloud. This satisfies the confidentiality and integrity needs for data sent to Microsoft 365.

  • ✗

    HTTPS

    Why it's wrong here

    HTTPS is not a separate cryptography protocol but an application-layer scheme that indicates HTTP is being carried over TLS. When a browser connects to outlook.office365.com or a similar Microsoft 365 endpoint, the actual encryption is provided entirely by TLS, not by a distinct 'HTTPS' protocol. Choosing HTTPS would name the wrapper rather than the underlying secure transport mechanism the question is asking for.

  • ✗

    SSH

    Why it's wrong here

    SSH (Secure Shell) is designed for remote command execution, terminal sessions, and secure file transfer (e.g., SFTP or SCP), using its own protocol on TCP port 22. It relies on host public keys and a different authentication model than the TLS certificate chain used by web services. Microsoft 365 exposes REST, Outlook, and Exchange endpoints over HTTPS/TLS, so SSH has no role in securing normal client-to-service data transfer.

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.