MS-900 Microsoft 365 Fundamentals Compliance and Trust Principles 4 — Questions and Answers
Question 1: What is the purpose of Microsoft's 'Shared Responsibility Model' in cloud services?
- It splits the licensing cost between Microsoft and the customer
- It defines which security responsibilities belong to Microsoft versus the customer (Correct answer)
- It requires customers to share their compliance reports with Microsoft
- It allows two organizations to co-manage a single Microsoft 365 tenant
Correct answer: It defines which security responsibilities belong to Microsoft versus the customer
The Shared Responsibility Model clarifies that Microsoft secures the cloud infrastructure while customers are responsible for securing their data, identities, and configurations.
Question 2: Which Microsoft 365 tool provides a quantified score to help organizations understand and improve their security posture?
- Compliance Manager
- Microsoft Secure Score (Correct answer)
- Defender for Identity
- Attack Simulator
Correct answer: Microsoft Secure Score
Microsoft Secure Score measures an organization's security posture and provides recommendations to improve it with a numerical score.
Question 3: Under which compliance framework does Microsoft 365 Government (GCC High) primarily operate to serve US federal agencies?
- ISO 27001
- SOC 2 Type II
- FedRAMP High (Correct answer)
- PCI DSS
Correct answer: FedRAMP High
FedRAMP High authorization is required for cloud services handling US government data at the high impact level, which Microsoft 365 GCC High maintains.
Question 4: What is 'eDiscovery' used for in Microsoft 365 compliance?
- Discovering new Microsoft 365 features automatically
- Searching for and exporting content across Microsoft 365 services for legal investigations (Correct answer)
- Automatically discovering shadow IT applications
- Finding misconfigured security settings
Correct answer: Searching for and exporting content across Microsoft 365 services for legal investigations
eDiscovery in Microsoft Purview allows legal and compliance teams to search, hold, and export content from Exchange, SharePoint, Teams, and other services for legal proceedings.
Question 5: Which privacy principle ensures that Microsoft only collects personal data necessary for a specific stated purpose?
- Data minimization (Correct answer)
- Purpose limitation
- Storage limitation
- Data integrity
Correct answer: Data minimization
Data minimization is the privacy principle that personal data collected should be adequate, relevant, and limited to what is necessary for the specified purpose.
Question 6: What does the Microsoft 365 'Information Barriers' feature prevent?
- Users from sending emails outside the organization
- Communication between specific groups of users within the same organization (Correct answer)
- External guests from joining Teams meetings
- Attachments larger than a set file size from being sent
Correct answer: Communication between specific groups of users within the same organization
Information Barriers restrict communication and collaboration between defined groups within an organization, commonly used in financial institutions to prevent conflicts of interest.
Question 7: Which Microsoft 365 feature uses machine learning to automatically detect and apply sensitivity labels to documents across SharePoint sites?
- Manual sensitivity labeling
- Auto-labeling policies (Correct answer)
- Retention policies
- Azure AD Access Reviews
Correct answer: Auto-labeling policies
Auto-labeling policies in Microsoft Purview use trainable classifiers or sensitive information types to automatically apply sensitivity labels to content without user intervention.
What is the purpose of Microsoft's 'Shared Responsibility Model' in cloud services?