MS-900 Microsoft 365 Fundamentals Compliance and Trust Principles 3 — Questions and Answers
Question 1: Which Microsoft 365 feature helps prevent accidental sharing of sensitive information like credit card numbers via email?
- Advanced Threat Protection
- Data Loss Prevention (DLP) (Correct answer)
- Microsoft Defender for Endpoint
- Azure Information Protection scanner
Correct answer: Data Loss Prevention (DLP)
Data Loss Prevention policies detect sensitive information types and block or warn users before they share that content externally.
Question 2: What is the Microsoft Service Trust Portal primarily used for?
- Managing user licenses and subscriptions
- Accessing compliance documentation, audit reports, and security assessments for Microsoft services (Correct answer)
- Configuring multi-factor authentication
- Monitoring email delivery status
Correct answer: Accessing compliance documentation, audit reports, and security assessments for Microsoft services
The Service Trust Portal provides access to Microsoft's compliance reports, certifications, and trust documentation for services like Azure and Microsoft 365.
Question 3: Which type of encryption does Microsoft 365 use to protect data while it travels between the user's device and Microsoft datacenters?
- Encryption at rest
- Encryption in transit (Correct answer)
- Client-side encryption
- Homomorphic encryption
Correct answer: Encryption in transit
Encryption in transit uses TLS (Transport Layer Security) to protect data as it moves between users and Microsoft's servers.
Question 4: What is the role of a 'Data Subject Request' (DSR) under GDPR?
- A request by an employee for more storage quota
- A request by an individual to access, correct, or delete their personal data (Correct answer)
- A government request for user data
- A request to back up sensitive information
Correct answer: A request by an individual to access, correct, or delete their personal data
Under GDPR, a Data Subject Request allows individuals to exercise their rights over their personal data, including access, rectification, and erasure.
Question 5: Which Microsoft 365 compliance solution enables organizations to manage the lifecycle of their records and meet regulatory retention obligations?
- Microsoft Purview Records Management (Correct answer)
- SharePoint Versioning
- OneDrive Recycle Bin
- Exchange Online Archiving
Correct answer: Microsoft Purview Records Management
Microsoft Purview Records Management helps organizations classify content as records, apply retention schedules, and automate disposition reviews.
Question 6: What does 'customer-managed keys' (CMK) allow organizations to do in Microsoft 365?
- Reset user passwords without admin privileges
- Control their own encryption keys rather than relying solely on Microsoft-managed keys (Correct answer)
- Manage API keys for third-party integrations
- Grant external users access to internal documents
Correct answer: Control their own encryption keys rather than relying solely on Microsoft-managed keys
Customer-managed keys allow organizations to use their own encryption keys stored in Azure Key Vault, giving them greater control over data access.
Question 7: Which feature in Microsoft 365 allows administrators to restrict what data can leave the organization through email, Teams, and SharePoint simultaneously?
- Conditional Access Policies
- Unified DLP policies in Microsoft Purview (Correct answer)
- Azure AD Identity Protection
- Microsoft Secure Score
Correct answer: Unified DLP policies in Microsoft Purview
Unified DLP policies in Microsoft Purview can be applied across multiple Microsoft 365 services including Exchange, SharePoint, Teams, and OneDrive from a single policy.
Which Microsoft 365 feature helps prevent accidental sharing of sensitive information like credit card numbers via email?