Microsoft 365 Copilot AB-900 Microsoft Purview Capabilities Information Protection Practice Test

 

Skills 2.1 • 30 original questions

This Microsoft AB-900 Microsoft 365 Copilot and Agent Administration Fundamentals practice test focuses on microsoft purview capabilities information protection and sensitivity labels through original scenario-based questions aligned to the Skills measured as of July 22, 2026. Use the full ExamSnap AB-900 collection for broader practice across all current skill areas. For broader exam preparation, review the Microsoft AB-900 Exam Dumps page.

Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.

Question 1

While handling a service desk escalation, the security administrator needs to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks. Which answer most directly addresses the stated need? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  2. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  3. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  4. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  5. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access

Correct answer: B

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

B: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

C: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

D: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

E: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 2

During a production readiness check at Proseware, the service desk lead must mark confidential content so users and services can enforce appropriate handling. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  4. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  5. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access

Correct answer: B

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

C: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

D: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

E: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 3

Lucerne Publishing is preparing a security review. The team needs to select the appropriate Purview capability for a data-protection or governance requirement. What should the Copilot administrator choose? The team needs a direct administrative answer, not a broad redesign.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  4. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: E

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

C: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

D: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 4

Which statement best explains how Microsoft 365 should address this requirement at City Power & Light: classify content and apply protection or handling expectations according to sensitivity? The administrator wants an action that is easy to audit later.

  1. Run the appropriate Data access governance report from the SharePoint admin center
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents

Correct answer: D

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

C: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

E: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 5

For a agent governance review at Northwind Traders, which Microsoft 365 approach correctly addresses the need to identify whether a requirement belongs to Purview rather than Entra or Teams? The solution should preserve least privilege and existing governance where possible.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  4. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: E

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

C: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

D: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 6

The identity administrator at Fourth Coffee is asked to use a label to express data sensitivity consistently across supported Microsoft 365 locations. What is the most appropriate next step? The team wants the smallest change that directly addresses the requirement.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  5. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears

Correct answer: A

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

B: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

D: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

E: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 7

Alpine Ski House has validated the surrounding services. The remaining requirement is to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks. Which choice is correct? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: D

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

D: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 8

Which statement best explains how Microsoft 365 should address this requirement at Contoso: mark confidential content so users and services can enforce appropriate handling? The team will validate the result immediately after the change.

  1. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  2. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  3. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  4. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  5. Run the appropriate Data access governance report from the SharePoint admin center

Correct answer: C

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

B: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

C: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

D: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

E: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 9

A design review at Litware identifies one specific goal: select the appropriate Purview capability for a data-protection or governance requirement. Which option best matches that goal? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  2. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  5. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action

Correct answer: C

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

B: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

D: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

E: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 10

The IT team at Trey Research wants to classify content and apply protection or handling expectations according to sensitivity. Which Microsoft 365 capability should it use? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  2. Run the appropriate Data access governance report from the SharePoint admin center
  3. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  4. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: E

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

B: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

C: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

D: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 11

While handling a tenant cleanup, the Copilot administrator needs to identify whether a requirement belongs to Purview rather than Entra or Teams. Which answer most directly addresses the stated need? The choice should follow normal Microsoft 365 administrative practice.

  1. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  2. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions

Correct answer: A

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

B: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

E: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 12

Which statement best explains how Microsoft 365 should address this requirement at Woodgrove Bank: use a label to express data sensitivity consistently across supported Microsoft 365 locations? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  2. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  3. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  4. Run the appropriate Data access governance report from the SharePoint admin center
  5. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears

Correct answer: B

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

B: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

C: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

D: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

E: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 13

Wide World Importers is preparing a identity hardening effort. The team needs to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks. What should the IT administrator choose? The team needs a direct administrative answer, not a broad redesign.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  3. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  4. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  5. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content

Correct answer: D

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

B: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

C: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

D: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

E: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 14

A support case at Southridge Video says administrators must mark confidential content so users and services can enforce appropriate handling. Which option is the best fit? The administrator wants an action that is easy to audit later.

  1. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions
  2. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  3. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: C

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

B: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

C: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 15

For a oversharing investigation at Fabrikam, which Microsoft 365 approach correctly addresses the need to select the appropriate Purview capability for a data-protection or governance requirement? The solution should preserve least privilege and existing governance where possible.

  1. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  2. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: B

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

B: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

D: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 16

Which statement best explains how Microsoft 365 should address this requirement at Wingtip Toys: classify content and apply protection or handling expectations according to sensitivity? The team wants the smallest change that directly addresses the requirement.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  3. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity
  4. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  5. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks

Correct answer: A

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

B: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

C: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

D: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

E: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 17

VanArsdel has validated the surrounding services. The remaining requirement is to identify whether a requirement belongs to Purview rather than Entra or Teams. Which choice is correct? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  2. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  3. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use Microsoft Purview Insider Risk Management to identify and investigate potentially risky user activity

Correct answer: B

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

B: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

C: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

E: Insider Risk Management correlates configured indicators and user activity to surface potential insider-risk cases for review. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 18

An administrator reviewing security review for Bellows College must use a label to express data sensitivity consistently across supported Microsoft 365 locations. Which Microsoft 365 control or object should be used? The team will validate the result immediately after the change.

  1. Run the appropriate Data access governance report from the SharePoint admin center
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: E

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

D: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 19

A design review at Tailspin Toys identifies one specific goal: choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks. Which option best matches that goal? No unrelated tenant settings should be changed.

  1. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  2. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  3. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  4. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: E

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

B: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

C: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

D: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 20

Which statement best explains how Microsoft 365 should address this requirement at Coho Winery: mark confidential content so users and services can enforce appropriate handling? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot

Correct answer: D

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

C: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

E: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 21

While handling a data protection review, the IT administrator needs to select the appropriate Purview capability for a data-protection or governance requirement. Which answer most directly addresses the stated need? The choice should follow normal Microsoft 365 administrative practice.

  1. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks
  2. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  3. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement

Correct answer: E

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

B: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

C: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

E: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 22

During a admin-center audit at Adventure Works, the identity administrator must classify content and apply protection or handling expectations according to sensitivity. Which Microsoft 365 action or concept most directly satisfies the requirement? The administrator must choose the Microsoft 365 feature that matches the stated goal.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  3. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Use Microsoft Purview Communication Compliance to review policy violations in supported communications

Correct answer: C

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

B: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

C: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

E: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 23

Blue Yonder Airlines is preparing a licensing change. The team needs to identify whether a requirement belongs to Purview rather than Entra or Teams. What should the SharePoint administrator choose? The team needs a direct administrative answer, not a broad redesign.

  1. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  2. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Run the appropriate Data access governance report from the SharePoint admin center
  5. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria

Correct answer: C

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

B: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

D: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

E: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 24

Which statement best explains how Microsoft 365 should address this requirement at Relecloud: use a label to express data sensitivity consistently across supported Microsoft 365 locations? The administrator wants an action that is easy to audit later.

  1. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  2. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content
  3. Use Microsoft Purview retention policies or retention labels to govern how long content is retained and when it can be deleted
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users

Correct answer: D

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

B: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

C: Retention controls preserve or delete content according to lifecycle and regulatory requirements. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

E: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 25

For a pilot rollout at Lamna Healthcare, which Microsoft 365 approach correctly addresses the need to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks? The solution should preserve least privilege and existing governance where possible.

  1. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  2. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Rely on the user existing Microsoft 365 permissions and access controls because Copilot grounds work responses only in content the user is authorized to access
  5. Use Microsoft Purview Activity explorer to review recorded user activities involving sensitive or governed content

Correct answer: C

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

B: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

D: Copilot respects the underlying Microsoft 365 permissions and does not create new access rights to protected content. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

E: Activity explorer provides visibility into supported activities across data protection and governance workloads. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to choose the Microsoft platform family used for information protection, DLP, insider-risk, communication-compliance, AI data-security posture, and data-lifecycle tasks.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 26

The service desk lead at Proseware is asked to mark confidential content so users and services can enforce appropriate handling. What is the most appropriate next step? The team wants the smallest change that directly addresses the requirement.

  1. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  2. Use Microsoft Purview Data Explorer to investigate sensitive information and where it appears
  3. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  4. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  5. Use Microsoft Purview Data Security Posture Management for AI to discover AI activity and manage AI-related data security risks

Correct answer: A

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

B: Data Explorer provides visibility into classified and sensitive information so administrators can understand exposure and plan protection. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

C: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

D: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

E: DSPM for AI provides visibility and controls focused on AI use, sensitive-data interactions, and related security posture. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to mark confidential content so users and services can enforce appropriate handling.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 27

Lucerne Publishing has validated the surrounding services. The remaining requirement is to select the appropriate Purview capability for a data-protection or governance requirement. Which choice is correct? The decision must address the stated requirement rather than a different Microsoft 365 control.

  1. Apply responsible AI principles and appropriate human review to the design and use of Copilot and agents
  2. Run the appropriate Data access governance report from the SharePoint admin center
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access
  5. Use Microsoft Purview Communication Compliance to review policy violations in supported communications

Correct answer: C

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: Responsible AI requires governance and oversight around fairness, reliability and safety, privacy and security, inclusiveness, transparency, and accountability. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

B: SharePoint Data access governance reports provide snapshot and activity views for permissions, sharing links, sensitivity labels, and broad-sharing patterns. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

D: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

E: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to select the appropriate Purview capability for a data-protection or governance requirement.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 28

Which statement best explains how Microsoft 365 should address this requirement at City Power & Light: classify content and apply protection or handling expectations according to sensitivity? The team will validate the result immediately after the change.

  1. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  2. Use Content search in Microsoft Purview eDiscovery to locate files and emails that match the search criteria
  3. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  4. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  5. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection

Correct answer: E

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

B: Content search is designed to search supported Microsoft 365 content for investigation and eDiscovery purposes. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

C: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

D: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to classify content and apply protection or handling expectations according to sensitivity.

E: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Question 29

A design review at Northwind Traders identifies one specific goal: identify whether a requirement belongs to Purview rather than Entra or Teams. Which option best matches that goal? No unrelated tenant settings should be changed.

  1. Use Microsoft Purview DLP and review the generated alert, policy match, activity, user, and content details before taking the appropriate remediation action
  2. Use SharePoint Advanced Management Restricted Access Control to limit site access to the approved group or users
  3. Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement
  4. Use the underlying Microsoft 365 permissions together with Microsoft Purview and Microsoft Defender controls to protect data used by Copilot
  5. Use Microsoft Graph-grounded Microsoft 365 context so Copilot can retrieve relevant work data that the user is permitted to access

Correct answer: C

Why: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

Option review:

A: DLP detects configured policy matches and can generate alerts with context that administrators use to investigate and respond to potential data loss. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

B: Restricted Access Control adds a site-level access restriction that can prevent broader access even when other permissions or links exist. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

C: Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities. This directly addresses the stated requirement.

D: Copilot operates within existing Microsoft 365 security and compliance boundaries, so permission hygiene and protection policies remain fundamental. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

E: Microsoft Graph provides signals and relationships across Microsoft 365 that can ground Copilot responses in authorized work context. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to identify whether a requirement belongs to Purview rather than Entra or Teams.

Learning point: Use the Microsoft Purview capability that corresponds to the data protection, compliance, risk, or lifecycle requirement. Microsoft Purview brings together information protection, DLP, risk, compliance, AI data security posture, and lifecycle governance capabilities.

Question 30

The IT team at Fourth Coffee wants to use a label to express data sensitivity consistently across supported Microsoft 365 locations. Which Microsoft 365 capability should it use? The environment uses current Microsoft 365 services and the July 2026 AB-900 scope.

  1. Use SharePoint data access governance and related sharing or permissions reports to identify overshared sites and content
  2. Use Microsoft Purview Communication Compliance to review policy violations in supported communications
  3. Use Microsoft Purview data classification capabilities to identify and understand sensitive information across supported data
  4. Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection
  5. Use Microsoft Purview Compliance Manager to assess compliance posture and review recommended improvement actions

Correct answer: D

Why: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

Option review:

A: Data access governance reports reveal broad permissions and sharing activity so administrators can focus remediation on the highest-risk sites. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

B: Communication Compliance detects content that matches configured communication policies and provides a workflow for review and remediation. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

C: Data classification provides visibility into sensitive information types, labels, and related data so protection and governance can be targeted. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

D: Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported. This directly addresses the stated requirement.

E: Compliance Manager helps organizations assess compliance against standards and provides improvement actions and scoring. This can be appropriate in another Microsoft 365 scenario, but it does not directly satisfy the requirement to use a label to express data sensitivity consistently across supported Microsoft 365 locations.

Learning point: Apply a Microsoft Purview sensitivity label appropriate to the information sensitivity and required protection. Sensitivity labels classify content and can drive protections and handling controls such as markings, encryption, and container settings where supported.

Popular posts

img