MS-900 · Question #142
You are a Microsoft 365 administrator for a company. What are two ways that you can ensure data security? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one…
The correct answer is A. service-level encryption using customer-provided key D. data transfer using transport-layer security (TLS). Microsoft 365 provides multiple layers of data security, including encryption at rest using customer-managed keys and encryption in transit using TLS. Administrators can leverage these mechanisms to ensure end-to-end data protection.
Question
Options
- Aservice-level encryption using customer-provided key
- Btenant-dedicated Microsoft Azure AD encryption using customer-provided key
- Csingle-tenant infrastructure partitions for sensitive data
- Ddata transfer using transport-layer security (TLS)
How the community answered
(50 responses)- A94% (47)
- B4% (2)
- C2% (1)
Why each option
Microsoft 365 provides multiple layers of data security, including encryption at rest using customer-managed keys and encryption in transit using TLS. Administrators can leverage these mechanisms to ensure end-to-end data protection.
Service-level encryption using customer-provided keys (Customer Key in Microsoft 365) allows organizations to control and manage their own encryption keys via Azure Key Vault, providing an additional layer of protection over Microsoft's default encryption at rest and ensuring the organization retains ultimate control over their data.
Tenant-dedicated Microsoft Azure AD encryption using customer-provided keys is not a real Microsoft 365 security offering; Azure AD uses shared infrastructure and does not offer a dedicated per-tenant encryption model with customer-provided keys as described.
Microsoft 365 operates on a multi-tenant shared infrastructure model with logical isolation rather than single-tenant physical infrastructure partitions; dedicated single-tenant infrastructure partitions for sensitive data is not a standard Microsoft 365 data security feature.
Transport Layer Security (TLS) is used by Microsoft 365 to encrypt data in transit between clients and Microsoft servers, as well as between Microsoft datacenters, ensuring that data cannot be intercepted or tampered with during transmission.
Concept tested: Microsoft 365 data encryption and security options
Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/customer-key-overview
Topics
Community Discussion
No community discussion yet for this question.