Microsoft 365 Copilot AB-900 Purview Data Classification And Retention Practice Test

 

Skills 2.1 • 20 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on purview data classification and retention through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

During a tenant cleanup at Fourth Coffee, the compliance administrator must understand what type of data is present before applying protection and governance controls. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  2. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: C

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

B: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 2

Alpine Ski House is preparing a Copilot adoption project. The team needs to apply a lifecycle rule that controls how long Microsoft 365 content is retained. What should the IT administrator choose? The solution should preserve least privilege and existing governance where possible.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Run the appropriate Data access governance report from the SharePoint admin center
  3. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted

Correct answer: E

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

B: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

C: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

E: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 3

A support case at Contoso says administrators must identify and categorize sensitive or regulated information across Microsoft 365 data. Which option is the best fit? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  3. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use Microsoft Purview Communication Compliance to review policy violations in supported communications

Correct answer: A

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

B: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

C: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

E: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 4

Litware is documenting its administrative model. Which choice most accurately describes the capability needed to prevent premature deletion of governed content? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted

Correct answer: E

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

C: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

E: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 5

The Microsoft 365 administrator at Trey Research is asked to use Purview classification insights to locate sensitive information types and labels. What is the most appropriate next step? The team will validate the result immediately after the change.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  5. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents

Correct answer: D

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

B: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

D: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

E: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 6

Consolidated Messenger has validated the surrounding services. The remaining requirement is to keep records for a required period and then dispose of them according to policy. Which choice is correct? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  2. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  5. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria

Correct answer: C

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

B: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

D: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

E: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 7

An administrator reviewing production readiness check for Woodgrove Bank must understand what type of data is present before applying protection and governance controls. Which Microsoft 365 control or object should be used? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  4. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  5. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access

Correct answer: B

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

C: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

D: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

E: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 8

Wide World Importers is documenting its administrative model. Which choice most accurately describes the capability needed to apply a lifecycle rule that controls how long Microsoft 365 content is retained? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: A

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 9

The IT team at Southridge Video wants to identify and categorize sensitive or regulated information across Microsoft 365 data. Which Microsoft 365 capability should it use? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  3. Run the appropriate Data access governance report from the SharePoint admin center
  4. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  5. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data

Correct answer: E

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

B: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

C: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

D: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

E: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 10

While handling a agent governance review, the IT administrator needs to prevent premature deletion of governed content. Which answer most directly addresses the stated need? The team needs a direct administrative answer, not a broad redesign.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data

Correct answer: D

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

C: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

E: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 11

During a data protection review at Wingtip Toys, the identity administrator must use Purview classification insights to locate sensitive information types and labels. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator wants an action that is easy to audit later.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot

Correct answer: B

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

C: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

E: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 12

VanArsdel is documenting its administrative model. Which choice most accurately describes the capability needed to keep records for a required period and then dispose of them according to policy? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  2. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  3. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access

Correct answer: B

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

B: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

C: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

E: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 13

A support case at Bellows College says administrators must understand what type of data is present before applying protection and governance controls. Which option is the best fit? The team wants the smallest change that directly addresses the requirement.

  1. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  2. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  3. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data

Correct answer: E

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

B: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

C: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

E: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 14

For a governance workshop at Tailspin Toys, which Microsoft 365 approach correctly addresses the need to apply a lifecycle rule that controls how long Microsoft 365 content is retained? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  3. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  4. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  5. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks

Correct answer: B

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

B: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

C: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

D: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

E: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 15

The service desk lead at Coho Winery is asked to identify and categorize sensitive or regulated information across Microsoft 365 data. What is the most appropriate next step? The team will validate the result immediately after the change.

  1. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  2. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: B

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

B: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify and categorize sensitive or regulated information across Microsoft 365 data.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 16

Humongous Insurance is documenting its administrative model. Which choice most accurately describes the capability needed to prevent premature deletion of governed content? No unrelated tenant settings should be changed.

  1. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  2. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  3. Run the appropriate Data access governance report from the SharePoint admin center
  4. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  5. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted

Correct answer: E

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

B: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

C: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

D: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to prevent premature deletion of governed content.

E: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 17

An administrator reviewing Copilot adoption project for Adventure Works must use Purview classification insights to locate sensitive information types and labels. Which Microsoft 365 control or object should be used? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  4. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  5. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access

Correct answer: D

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

C: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

D: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

E: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use Purview classification insights to locate sensitive information types and labels.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 18

A design review at Blue Yonder Airlines identifies one specific goal: keep records for a required period and then dispose of them according to policy. Which option best matches that goal? The choice should follow normal Microsoft 365 administrative practice.

  1. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  5. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action

Correct answer: C

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

D: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

E: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to keep records for a required period and then dispose of them according to policy.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Question 19

The IT team at Relecloud wants to understand what type of data is present before applying protection and governance controls. Which Microsoft 365 capability should it use? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  3. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  4. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  5. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions

Correct answer: A

Why: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This directly addresses the stated requirement.

B: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

C: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

D: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

E: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to understand what type of data is present before applying protection and governance controls.

Learning point: Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data. Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted.

Question 20

Lamna Healthcare is documenting its administrative model. Which choice most accurately describes the capability needed to apply a lifecycle rule that controls how long Microsoft 365 content is retained? The team needs a direct administrative answer, not a broad redesign.

  1. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: D

Why: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

Option review:

A: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

C: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This directly addresses the stated requirement.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to apply a lifecycle rule that controls how long Microsoft 365 content is retained.

Learning point: Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted. Retention controls preserve or delete content according to lifecycle and regulatory requirements.

Popular posts

img