nerdexam
Microsoft

MS-900 · Question #145

You are a Microsoft 365 administrator for a company. You need to ensure that company documents are marked as confidential. You must prevent employees from sharing documents with people outside the…

The correct answer is D. Create a data-loss prevention policy E. Apply sensitivity labels to documents. To mark documents as confidential and prevent sharing with external users, you can use sensitivity labels to classify and protect documents and data-loss prevention (DLP) policies to block external sharing of sensitive content.

Submitted by olafpl· Mar 5, 2026Describe security, compliance, privacy, and trust in Microsoft 365

Question

You are a Microsoft 365 administrator for a company. You need to ensure that company documents are marked as confidential. You must prevent employees from sharing documents with people outside the company. What are two possible ways to achieve the goal? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • AValidate outbound emails by using DomainKeys identified Mail (DKIM)
  • BCreate sensitive information types
  • CConfigure Secure/Multipurpose Internet Mail Extensions (S/MIME) settings for Outlook
  • DCreate a data-loss prevention policy
  • EApply sensitivity labels to documents

How the community answered

(45 responses)
  • A
    2% (1)
  • B
    11% (5)
  • C
    4% (2)
  • D
    82% (37)

Why each option

To mark documents as confidential and prevent sharing with external users, you can use sensitivity labels to classify and protect documents and data-loss prevention (DLP) policies to block external sharing of sensitive content.

AValidate outbound emails by using DomainKeys identified Mail (DKIM)

DKIM is an email authentication mechanism used to validate that outbound emails are not spoofed or tampered with; it does not classify documents or prevent external sharing.

BCreate sensitive information types

Sensitive information types define patterns for detecting sensitive data (like credit card numbers or SSNs) but by themselves do not mark documents as confidential or prevent external sharing without being used within a DLP policy.

CConfigure Secure/Multipurpose Internet Mail Extensions (S/MIME) settings for Outlook

S/MIME provides email encryption and digital signing to ensure message integrity and confidentiality in transit, but it does not label documents as confidential or prevent sharing with external parties.

DCreate a data-loss prevention policyCorrect

A data-loss prevention (DLP) policy can detect sensitive or confidential documents and enforce rules that block or restrict sharing with external recipients, directly preventing employees from sharing company documents outside the organization.

EApply sensitivity labels to documentsCorrect

Sensitivity labels allow you to classify and mark documents as confidential, and they can enforce protection settings such as encryption and access restrictions that prevent external users from accessing the labeled content.

Concept tested: Microsoft 365 data protection with DLP and sensitivity labels

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/sensitivity-labels?view=o365-worldwide

Topics

#data loss prevention#sensitivity labels#information protection#document sharing

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice