MS-900 Security, Compliance, & Privacy in Microsoft 3 — Questions and Answers
Question 1: In the shared responsibility model for Microsoft 365 SaaS, who is responsible for managing user identities and access?
- Microsoft alone
- The customer organization (Correct answer)
- A third-party auditor
- Both Microsoft and the customer equally for every task
Correct answer: The customer organization
In the SaaS shared responsibility model, customers are responsible for managing their own user identities, access control, and data classification.
Question 2: Which Azure Active Directory feature allows administrators to require users to verify their identity through an additional method beyond just a password?
- Single Sign-On (SSO)
- Multi-Factor Authentication (MFA) (Correct answer)
- Privileged Identity Management
- Password Hash Sync
Correct answer: Multi-Factor Authentication (MFA)
Multi-Factor Authentication requires users to provide two or more verification factors, significantly reducing the risk of compromised credentials.
Question 3: What is the function of Microsoft Purview Information Protection's sensitivity labels?
- They scan emails for phishing links
- They classify and protect documents and emails based on their content sensitivity (Correct answer)
- They block external sharing of all files
- They encrypt only files stored in OneDrive
Correct answer: They classify and protect documents and emails based on their content sensitivity
Sensitivity labels classify content (like Confidential or Public) and can automatically apply protections such as encryption, watermarks, and access restrictions.
Question 4: Which Microsoft 365 tool allows organizations to legally hold mailbox content and prevent its deletion during litigation or investigation?
- Retention labels
- Litigation Hold (Correct answer)
- Content Search
- Audit Log
Correct answer: Litigation Hold
Litigation Hold preserves all mailbox content, preventing users from permanently deleting items for the duration of a legal matter.
Question 5: What is the role of Microsoft Entra ID (formerly Azure Active Directory) in Microsoft 365 security?
- It provides antivirus protection for endpoints
- It manages identities, authentication, and access control for Microsoft 365 services (Correct answer)
- It encrypts data in transit between services
- It scans files for sensitive information
Correct answer: It manages identities, authentication, and access control for Microsoft 365 services
Microsoft Entra ID is the identity and access management foundation for Microsoft 365, handling authentication, authorization, and user lifecycle management.
Question 6: An organization needs to ensure emails containing credit card numbers are never sent outside the company. Which Microsoft 365 solution addresses this?
- Microsoft Defender for Identity
- Data Loss Prevention (DLP) policy with sensitive info types (Correct answer)
- Azure Information Protection scanner
- Microsoft Secure Score
Correct answer: Data Loss Prevention (DLP) policy with sensitive info types
DLP policies use built-in sensitive information types like credit card numbers to detect and block external transmission of sensitive data.
Question 7: Which compliance standard does Microsoft 365 help organizations meet by providing tools for managing data subject requests (DSRs)?
- ISO 27001
- GDPR (General Data Protection Regulation) (Correct answer)
- SOC 2 Type II
- PCI DSS
Correct answer: GDPR (General Data Protection Regulation)
GDPR requires organizations to respond to data subject requests (like access or deletion requests), and Microsoft 365 provides built-in tools to locate and manage personal data.
In the shared responsibility model for Microsoft 365 SaaS, who is responsible for managing user identities and access?