Microsoft 365 Fundamentals Compliance and Trust Principles Flashcards
7 cards from real MS-900 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Microsoft 365 Fundamentals Compliance and Trust Principles flashcards as text
Which Microsoft 365 feature allows organizations to place a legal hold on mailboxes to preserve email content for litigation purposes?
Answer: Litigation Hold
Litigation Hold preserves all mailbox content indefinitely so it cannot be deleted, even by the user, to satisfy legal requirements.
What is the purpose of the Microsoft Compliance Manager tool?
Answer: To assess compliance posture and provide remediation guidance
Compliance Manager provides a compliance score and step-by-step guidance to help organizations meet regulatory requirements.
Which regulation requires organizations to notify authorities within 72 hours of discovering a personal data breach?
Answer: GDPR
GDPR mandates that data breaches affecting EU residents must be reported to supervisory authorities within 72 hours of discovery.
What does the term 'data residency' mean in the context of Microsoft 365?
Answer: The geographic location where customer data is stored
Data residency refers to specifying and controlling the geographic region where Microsoft stores your organization's data at rest.
Which Microsoft 365 compliance feature automatically classifies and labels sensitive documents based on their content?
Answer: Sensitivity Labels
Sensitivity Labels in Microsoft Purview can be applied automatically or manually to classify documents and apply protection policies.
What is the primary function of Microsoft Purview Audit (formerly Office 365 Audit Log)?
Answer: Recording user and admin activities across Microsoft 365 services
Microsoft Purview Audit captures a detailed log of user and administrator activities across Microsoft 365 services for forensic and compliance investigations.
In Microsoft 365, what does 'zero-trust security' primarily assume about network traffic?
Answer: No user or device should be trusted by default, even inside the network
Zero-trust security operates on the principle of 'never trust, always verify,' requiring authentication and authorization for every request regardless of source.