nerdexam
Microsoft

MS-900 · Question #142

You are a Microsoft 365 administrator for a company. What are two ways that you can ensure data security? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one…

The correct answer is A. service-level encryption using customer-provided key D. data transfer using transport-layer security (TLS). Microsoft 365 provides multiple layers of data security, including encryption at rest using customer-managed keys and encryption in transit using TLS. Administrators can leverage these mechanisms to ensure end-to-end data protection.

Submitted by carter_n· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

You are a Microsoft 365 administrator for a company. What are two ways that you can ensure data security? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • Aservice-level encryption using customer-provided key
  • Btenant-dedicated Microsoft Azure AD encryption using customer-provided key
  • Csingle-tenant infrastructure partitions for sensitive data
  • Ddata transfer using transport-layer security (TLS)

How the community answered

(50 responses)
  • A
    94% (47)
  • B
    4% (2)
  • C
    2% (1)

Why each option

Microsoft 365 provides multiple layers of data security, including encryption at rest using customer-managed keys and encryption in transit using TLS. Administrators can leverage these mechanisms to ensure end-to-end data protection.

Aservice-level encryption using customer-provided keyCorrect

Service-level encryption using customer-provided keys (Customer Key in Microsoft 365) allows organizations to control and manage their own encryption keys via Azure Key Vault, providing an additional layer of protection over Microsoft's default encryption at rest and ensuring the organization retains ultimate control over their data.

Btenant-dedicated Microsoft Azure AD encryption using customer-provided key

Tenant-dedicated Microsoft Azure AD encryption using customer-provided keys is not a real Microsoft 365 security offering; Azure AD uses shared infrastructure and does not offer a dedicated per-tenant encryption model with customer-provided keys as described.

Csingle-tenant infrastructure partitions for sensitive data

Microsoft 365 operates on a multi-tenant shared infrastructure model with logical isolation rather than single-tenant physical infrastructure partitions; dedicated single-tenant infrastructure partitions for sensitive data is not a standard Microsoft 365 data security feature.

Ddata transfer using transport-layer security (TLS)Correct

Transport Layer Security (TLS) is used by Microsoft 365 to encrypt data in transit between clients and Microsoft servers, as well as between Microsoft datacenters, ensuring that data cannot be intercepted or tampered with during transmission.

Concept tested: Microsoft 365 data encryption and security options

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/customer-key-overview

Topics

#data security#service-level encryption#TLS#data transfer security

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice