MS-900 Microsoft 365 Fundamentals Compliance and Trust Principles 5 — Questions and Answers
Question 1: What is the primary purpose of Microsoft's 'Privacy by Design' approach in Microsoft 365?
- To make privacy settings visible only to administrators
- To build privacy protections into products and services from the ground up, not as an afterthought (Correct answer)
- To charge customers for advanced privacy features
- To allow users to opt out of all data collection
Correct answer: To build privacy protections into products and services from the ground up, not as an afterthought
Privacy by Design means privacy and data protection are embedded into the design of Microsoft's systems and services from the earliest stages of development.
Question 2: Which Microsoft 365 compliance feature allows you to automatically delete content after a specified period?
- Litigation Hold
- Sensitivity Labels
- Retention Policies (Correct answer)
- Information Barriers
Correct answer: Retention Policies
Retention Policies in Microsoft Purview can be configured to either retain content for a minimum period, delete it after a maximum period, or both.
Question 3: What is the Microsoft 365 'Insider Risk Management' feature designed to detect?
- External hackers attacking the organization
- Potentially risky activities by internal users such as data theft or policy violations (Correct answer)
- Insider threats from Microsoft employees accessing customer data
- Unauthorized software installations on company devices
Correct answer: Potentially risky activities by internal users such as data theft or policy violations
Insider Risk Management uses machine learning to identify potentially risky or malicious behavior by employees or contractors within the organization.
Question 4: Which standard does Microsoft 365 use to ensure that its cloud infrastructure meets rigorous security requirements for healthcare organizations in the US?
- GDPR
- HIPAA/HITECH (Correct answer)
- SOX
- CCPA
Correct answer: HIPAA/HITECH
HIPAA/HITECH establishes requirements for protecting electronic protected health information (ePHI), and Microsoft signs Business Associate Agreements to support HIPAA compliance.
Question 5: What does Microsoft's 'Lockbox' feature (Customer Lockbox) provide to organizations?
- A secure vault for storing passwords in Microsoft 365
- Approval control over Microsoft support engineers accessing customer content during service requests (Correct answer)
- Encryption for files stored in SharePoint
- A dedicated IP address range for the tenant
Correct answer: Approval control over Microsoft support engineers accessing customer content during service requests
Customer Lockbox requires organizations to explicitly approve before Microsoft support personnel can access their content during a support request.
Question 6: Which Microsoft 365 capability allows organizations to discover and govern sensitive data stored in on-premises file shares and databases, not just in the cloud?
- Microsoft Defender for Cloud Apps
- Microsoft Purview Data Map (Correct answer)
- SharePoint Migration Tool
- Azure AD Connect
Correct answer: Microsoft Purview Data Map
Microsoft Purview Data Map scans and classifies data across on-premises, multicloud, and SaaS environments to provide a unified view of sensitive data wherever it resides.
Question 7: What is the key difference between a 'retention label' and a 'retention policy' in Microsoft Purview?
- Retention labels apply to entire sites while policies apply to individual files
- Retention labels are applied to specific items and can mark content as a record, while retention policies apply broadly to locations like all mailboxes (Correct answer)
- Retention policies are free while retention labels require an add-on license
- Retention labels only work in SharePoint while policies only work in Exchange
Correct answer: Retention labels are applied to specific items and can mark content as a record, while retention policies apply broadly to locations like all mailboxes
Retention labels are applied at the item level and can declare content as records, whereas retention policies are applied broadly across entire locations like all Exchange mailboxes or all SharePoint sites.
What is the primary purpose of Microsoft's 'Privacy by Design' approach in Microsoft 365?