MS-102 Practice Questions: Microsoft Purview & Security Compliance Deep Dive
By GetCertPrep Editorial Team
·
18 min read
·
Certification Guides
MS-102MS-102 Purview practice questionsStudy Guide
Direct Answer
Exam Summary & High-Yield Blueprint
Master MS-102 Purview concepts with scenario-based practice questions covering data classification, sensitivity labels, retention policies, and compliance features. These deep-dive walkthroughs reflect real exam scenarios, ensuring actionable understanding. Build topical authority by analyzing solved questions and referencing essential admin center configurations for Microsoft 365 compliance.
# MS-102 Practice Questions: Microsoft Purview & Security Compliance Deep Dive
> đĄ **Direct Answer**
>
> Master MS-102 Purview concepts with scenario-based practice questions covering data classification, sensitivity labels, retention policies, and compliance features. These deep-dive walkthroughs reflect real exam scenarios, ensuring actionable understanding. Build topical authority by analyzing solved questions and referencing essential admin center configurations for Microsoft 365 compliance. Use this guide to identify your weak spots before tackling the full MS-102 certification exam.
The Microsoft 365 Certified: Administrator Expert (MS-102) exam places substantial weight on compliance and information protection. Microsoft Purview is no longer a side topic; itâs a core pillar every administrator must understand inside out. Exam candidates frequently stumble on scenario-driven questions that combine sensitivity labels, auto-labeling, retention locks, and data loss prevention (DLP) into a single business requirement.
This post is your structured deep dive. Weâll break down the most common Purview exam scenarios, walk through solved questions step by step, and map each concept back to the real admin centres youâll use daily. Whether youâre starting your prep or refining your knowledge, these MS-102 Purview practice questions will transform dry theory into actionable skills.
---
## Common Purview Exam Scenarios
Microsoft structures MS-102 compliance questions around real-world business challenges. Youâre rarely asked âWhat does this setting do?â Instead, youâre given a workplace situation and must deduce the correct combination of Purview features. Three domains dominate the exam:
| Exam Domain | Weight in MS-102 | Purview Relevance |
|-------------|------------------|-------------------|
| Manage Microsoft 365 compliance | 15â20% | Core focus: labels, policies, DLP, records management |
| Implement and manage identity and access | 25â30% | Overlap with Information Rights Management (IRM) |
| Manage security and threats | 25â30% | Insider risk, communication compliance, auditing |
| Plan and manage Microsoft 365 services | 20â25% | Archiving, retention, eDiscovery integration |
(Source: Microsoft MS-102 exam skills outline, updated for latest objectives.)
All Purview scenarios demand that you understand not only *what* a feature does but *where* to configure it and *how* different policies interact. Letâs unpack each critical area.
### Data Classification and Sensitivity Labels in Action
Sensitivity labels are the backbone of Microsoft Purview Information Protection. In the exam, youâll see scenarios like:
- **Auto-labeling emails based on content** â e.g., âAll emails containing project code âFalconâ must be automatically marked Confidential and encrypted.â
- **User-applied labels with justification prompts** â Users manually label a document; if they downgrade the classification, must they provide a business justification?
- **Label inheritance and default labels** â How do labels flow between Office apps, SharePoint, and Teams? What happens when a document containing a C3 label is shared with an external user?
Key concepts tested:
- **Label publishing vs. auto-labeling policies** â Labels must be published to users/groups; auto-labeling policies apply labels to content at rest (and in transit for specific workloads).
- **Label precedence** â Multiple conditions may match; which label wins?
- **Encryption and access permissions** â Assigning usage rights via âAssign permissions nowâ or letting users decide (Do Not Forward, Encrypt-Only).
- **Label scope** â Files, emails, meetings (Teams, Outlook), and containers (groups, sites).
**Real Exam Twist:** A common trick is asking you to apply a sensitivity label to Teams meetings that require encrypted channel messages. The correct answer often involves configuring a label with âProtect meetingsâ scope and assigning the âConfidentialâ or âHighly Confidentialâ template.
### Retention Policies and Records Management
Retention and records management questions test your ability to balance legal compliance with data lifecycle management. Youâll encounter:
- **Mixed retention requirements** â âKeep all financial records for 7 years after creation, then delete automatically, but if a legal hold is placed, override the deletion.â
- **Retention lock for immutability** â âThe legal department requires that once a retention policy is set, no oneâincluding adminsâcan modify or disable it.â The answer: a Preservation Lock.
- **Records management vs. retention labels** â When to use file plan descriptors, event-based retention, or disposition reviews.
- **Static vs. adaptive policy scopes** â Adaptive scopes evaluate query conditions dynamically (e.g., âall OneDrive sites of users in the Finance departmentâ), which appear frequently in scenario questions.
**Critical comparison:**
| Feature | Retention Labels | Sensitivity Labels |
|---------|------------------|---------------------|
| Primary purpose | Govern data lifecycle (keep/delete) | Protect data with encryption and visual markings |
| Applied to | SharePoint, OneDrive, Exchange, Teams | Files, emails, containers, meetings |
| Can trigger actions | Deletion, starting disposition review | Visual header/footer, watermark, encryption |
| End-user involvement | Often automatic or published for manual classification | Mainly user-applied, with option to auto-label |
| Immutable lock | Preservation Lock on retention label policies | No direct lock; label settings changeable by admins |
Understanding these differences saves you from losing points on MS-102 Purview practice questions that ask, âWhich label type should you use to ensure documents are retained for five years and cannot be permanently deleted by users?â
### Insider Risk and Communication Compliance
Microsoft has deepened its integration of Insider Risk Management and Communication Compliance into the Purview stack. The exam expects you to know:
- **Insider risk indicators** â Data leaks, data theft by departing users, security policy violations.
- **Policy templates** â âData leaks by departing usersâ template uses HR connector (Azure AD account deletion date) as trigger.
- **Communication compliance** â Detecting inappropriate text (harassment, threats, sharing adult content) and triggering review workflows. Scenarios may ask âWhich policy detects a specific profanity in Teams chats and requires a reviewer to take action?â
> **Exam Tip:** Insider risk often needs Microsoft 365 E5 licensing. In the MS-102, you may need to identify the minimum license requirement for a compliance feature, so keep licensing in mind.
---
## Solved Question Walkthroughs
Nothing builds confidence like tearing apart a real scenario and seeing *why* the correct answer wins. The following solved questions mirror the complexity and wording of actual MS-102 exam items. For each, weâll state the question, highlight the critical details, then walk through the solution step by step.
### Scenario 1: Auto-apply Sensitivity Labels to Emails
**Question:**
Your company requires that all emails containing the word âProject Orionâ and sent to external recipients be automatically marked with the âHighly Confidentialâ sensitivity label. Users must not be able to remove the label. You have already created and published the sensitivity label. Which three actions should you perform in Microsoft Purview?
A. Create an auto-labeling policy for Exchange email.
B. Create a DLP policy with a custom sensitive information type for âProject Orionâ.
C. Configure the labelâs encryption to assign âDo Not Forwardâ.
D. Configure the auto-labeling policy condition to use a trainable classifier.
E. Set the label priority higher than any other published label.
F. Configure the auto-labeling policy to apply the label when email matches âProject Orionâ keyword.
**Walkthrough:**
1. **Parse the requirement:**
- Trigger: emails containing âProject Orionâ AND sent to external recipients.
- Action: âHighly Confidentialâ label applied automatically, and users canât remove it.
- Existing element: label already published.
2. **Which admin tool does auto-labeling for Exchange emails?**
Auto-labeling policies are created in the **Microsoft Purview compliance portal** under **Information protection** > **Auto-labeling**. They can target Exchange emails, SharePoint, OneDrive. So option A is essential.
3. **What drives the condition?**
You can use sensitive info types, trainable classifiers, or custom keyword lists. Here, we just need a simple keyword âProject Orionâ. The *auto-labeling policy* itself supports content conditions that include keyword dictionaries. You do **not** need a separate DLP policy (B) or a trainable classifier (D). Use the built-in âContent containsâ condition with a phrase list. So the right approach is to configure the policy condition directly (F).
4. **User cannot remove the label** â this is controlled by **label priority and enforcement settings**. When you create an auto-labeling policy, it overrides any existing user-applied labels if the auto-label has higher priority. Sensitivity labels have a priority number; lower number = higher priority. So you must ensure that âHighly Confidentialâ label has a higher priority (lower number) than any label a user might apply. Thus, option E is necessary.
5. **âDo Not Forwardâ encryption** (C) is a protection setting within the label, not something that prevents label removal. It restricts what the recipient can do with the email, not the senderâs ability to strip the label. So itâs not an action required here.
**Correct answer: A, E, F**.
The admin creates an auto-labeling policy for Exchange (A), sets the label priority appropriately (E), and defines a content condition with the keyword âProject Orionâ combined with the external recipient condition (which you configure in the policyâs âChoose locationsâ and recipient filters â but the question simplifies to the keyword part). The auto-labeling engine will then stamp the label and prevent manual removal because the policy takes precedence.
> đĄ **Key Takeaway:** Auto-labeling policies donât need DLP. They directly evaluate content and apply sensitivity labels. When you see âuser cannot removeâ, think label priority and auto-labeling.
---
### Scenario 2: Configuring a Retention Lock for Legal Hold
**Question:**
A litigation hold requires that all email in a specific mailbox be preserved for 10 years from the date the item was received. Even global administrators must be unable to disable or reduce this retention period. You need to implement the solution. What should you create?
A. A retention label policy with a 10-year retention period and Preservation Lock enabled.
B. An eDiscovery case with an in-place hold for the mailbox.
C. A retention policy scoped to the mailbox with Dynamic lock.
D. A sensitivity label with encryption and retention settings.
**Walkthrough:**
- **Immutable retention** that even admins cannot override screams **Preservation Lock** (also called Retention Lock). Once a retention policy or retention label policy is locked, no one (not even global admin) can modify the retention period or delete the policy. The only way to remove it is to delete the content, but you canât shorten the retention.
- Option A mentions a retention label policy with a 10-year retention period and Preservation Lock. This is exactly what we need. The lock is applied at the policy level after all settings are confirmed.
- Option B, an eDiscovery hold, preserves content but does not necessarily prevent an admin from removing the hold. Moreover, itâs tied to a case, not a simple administrative requirement. The question wants a retention-based solution.
- Option C refers to âDynamic lockâ which isnât a feature; itâs a confused term. Retention policies can be locked, but they use Preservation Lock, not Dynamic lock.
- Option D mixes sensitivity labels with retention, but sensitivity labels cannot enforce retention periods directly; thatâs the job of retention labels/policies. Also, sensitivity labels donât offer a lock that prevents admin modification.
**Correct answer: A**. Create a retention label policy, configure a 10-year retention period (based on when received), and then apply Preservation Lock.
**Step-by-step in admin centre:**
Navigate to **Records management** > **Label policies** (or **Information governance** > **Label policies**), create or edit a policy, set retention to âKeep items for 10 years from when they were receivedâ, publish it to the mailbox location, and after publishing, use the **Preservation Lock** option (available once the policy is created). A warning message confirms immutability.
---
### Scenario 3: DLP Policy to Block Sharing of PII
**Question:**
Your organization must prevent users from sharing credit card numbers via Microsoft Teams chat and channel messages. You need to create a single DLP policy that blocks the sharing of credit card information in Teams, gives users a policy tip, and sends an alert to the compliance officer. Which components should you configure in the DLP rule?
A. Incident reports with high severity.
B. Block access and restrict content in SharePoint.
C. Block anyone from sending the message and notify the sender.
D. Include a sensitive info type for credit card number.
E. Configure an override capability for business justification.
F. Set the action to âRestrict access or encrypt the contentâ.
**Walkthrough:**
- Requirement: block sharing in Teams chat/channels. The DLP policy location must be **Teams chat and channel messages**.
- The content to detect: credit card numbers. Thatâs a built-in sensitive information type (SIT) called âCredit Card Numberâ. The DLP rule must **include** that SIT (option D).
- Blocking action in Teams DLP: You can block the message from being sent entirely, or restrict it. The exact action available for Teams is âBlock anyone from sending the message and notify the senderâ (or similar wording). Option C matches that. When this action is triggered, the user sees a policy tip and cannot send the message.
- Alerts and incident reports: To notify the compliance officer, you need to configure an **incident report** with the desired severity. So option A (incident reports with high severity) is correct.
- Option B is for SharePoint/OneDrive actions; not relevant to Teams chat.
- Option E (override) is typically for SharePoint/OneDrive/Exchange DLP where you can allow users to override with a business justification, but the question says âpreventâ so override would defeat the purpose. Not required here.
- Option F (restrict access or encrypt) is an action for files in SharePoint/OneDrive or email, not Teams messages.
**Correct answer: A, C, D**. Set the sensitive info type (credit card number), block the message and notify the sender, and send an incident report to the compliance officer.
**Admin configuration path:**
Purview compliance portal > Data loss prevention > Policies. Create a policy, select âCustomâ or âFinancialâ template. Choose location: Teams chat and channel messages. Create a rule with condition: âContent containsâ > Sensitive info types > âCredit Card Numberâ. Action: âBlock users from sending or accessingâ and set user notification. Then in the rule, turn on incident reports, select high severity, and assign the compliance officer email.
---
> **đ More Purview Questions? Take the Full MS-102 Practice Test**
> Packed with 100+ additional Purview-focused scenario questions, detailed explanations, timed simulations, and performance tracking. Donât leave compliance to chance â prepare for every twist the exam can throw at you.
> **[Start Full Test](/ms-102-full-purview-practice-test)**
---
## Related Admin Center Screenshots & Configuration
Even without live screenshots, knowing exactly where each setting lives in the Microsoft Purview compliance portal (and the associated Microsoft 365 admin centres) is crucial for the exam. The MS-102 may ask you to identify the correct blade, order of operations, or which role is required.
### Navigating Microsoft Purview Compliance Portal
The Microsoft Purview compliance portal (https://compliance.microsoft.com) groups features into logical solution areas. For MS-102 preparation, focus on these navigation paths:
- **Information protection**
- **Labels**: sensitivity labels, label publishing, auto-labeling policies.
- **Label analytics**: see how labels are being used.
- **Activity explorer**: monitor label activity across workloads.
- **Data lifecycle management**
- **Retention policies**: static policies for Exchange, SharePoint, OneDrive, Teams.
- **Retention label policies**: publish retention labels to locations.
- **Records management**: file plan, event-based retention, disposition reviews.
- **Adaptive scopes**: create dynamic policy scopes.
- **Data loss prevention**
- **Policies**: create and manage DLP policies.
- **Alerts**: view DLP alerts and manage incident reports.
- **Activity explorer**: see DLP rule matches.
- **Insider risk management**
- **Policies**: insider risk policies, indicators, priority user groups.
- **Alerts**: review and triage insider risk alerts.
- **Communication compliance**
- **Policies**: detect inappropriate messages, set up reviewers.
- **Reports**: policy matches, trends.
- **eDiscovery**
- **Standard and Premium cases**: holds, searches, exports.
- **Audit**
- **Search**: standard and premium audit log queries.
- **Audit retention policies**: manage long-term audit log retention.
Exam scenarios often describe a requirement and ask âFrom the Microsoft Purview compliance portal, which blade should you use?â Familiarity with the portalâs left navigation is key. For example, creating a retention label policy: you go to **Data lifecycle management** > **Label policies** > **Publish labels**.
### Key Screens: Label Policies, Content Explorer, Audit Logs
**Label Policies â Publish sensitivity labels:**
When configuring label publishing, the critical screen is **Policy settings** where you choose users/groups, then the **Default label** and **Mandatory labeling** options. For exam, remember:
- You can set a default sensitivity label for documents and emails.
- You can require users to provide a justification to change or remove a label.
- Policy settings apply to Office apps (Word, Excel, PowerPoint, Outlook). For SharePoint and Teams, labels are applied automatically based on the sensitivity label configuration on the container.
**Content Explorer:**
A powerful tool under **Data classification** > **Content explorer**. It shows where sensitive information types and trainable classifiers are occurring across all locations. In scenario questions, if you need to find all locations containing a specific PII type before creating a DLP policy, you use Content Explorer. It also helps answer âWhich SharePoint site has the most credit card numbers?â â you can drill down by location.
**Audit Logs:**
Found under **Audit** > **Search**. MS-102 often quizzes on what actions are audited by default and which require additional configuration (like enabling mailbox audit logging or turning on unified audit log search). Remember:
- The unified audit log is turned on by default for most tenants.
- Searching the audit log requires the **View-Only Audit Logs** or **Audit Logs** role.
- For long-term retention (>180 days), an **Audit retention policy** is needed (E5 licensing).
When troubleshooting âWhy canât I see mailbox audit events?â you need to check that mailbox audit logging is enabled (it is by default since 2019, but older mailboxes may need manual enabling via PowerShell).
**Step-by-step exam strategy:**
1. **Map the requirement to the correct portal area.** If itâs about protecting data â Information Protection; lifecycle â Data Lifecycle Management; policy violations â DLP; user behaviour â Insider Risk.
2. **Identify the exact configuration object.** Is it a label, a policy, or a rule?
3. **Consider licensing and permissions.** Purview features often require E5, Compliance Manager role group, or specific roles like Compliance Data Administrator.
4. **Walk through the portal mentally.** Every solved question can be mentally reproduced in the admin centre; this reduces exam-day guesswork.
---
> đŻ **Ready to go all-in on Purview?**
> The full MS-102 Purview practice test digs deeper with questions that combine retention, DLP, and sensitivity labels into multi-step scenarios. Experience the exam interface, track your weak areas, and get answer explanations that turn mistakes into mastery.
> **[Start Full Test](/ms-102-full-purview-practice-test)**
---
## Additional Sample Practice Questions
Test yourself with these quick-check questions. Answers and explanations follow immediately.
**Question 1:**
Your company wants to automatically apply a âConfidential â Internalâ sensitivity label to any document or email that contains the word âSalaryâ and the credit card SIT, but only if the content is stored in a SharePoint site in the HR department. What is the minimal set of components needed?
**Question 2:**
A retention label called âLegal Holdâ is published to all Exchange mailboxes. The company legal team must ensure that items labelled âLegal Holdâ are never permanently deleted before a review. Which retention label option should you configure?
### Answers & Explanations
**Answer 1:**
- An auto-labeling policy (simulation mode or enforced) that targets SharePoint sites.
- The policy condition must include a custom keyword (âSalaryâ) AND the credit card sensitive info type. You can combine multiple conditions with the âANDâ/ âORâ logic in the content conditions.
- No DLP or retention required; sensitivity auto-labeling handles it.
- Location scope: use a specific SharePoint site collection filter to limit to the HR department.
**Answer 2:**
Enable **Disposition review** on the retention label. When a retention label with âtrigger a disposition reviewâ is applied, content cannot be permanently deleted until a designated reviewer approves the deletion. Without this, items would be automatically deleted after the retention period. The exam loves to test that you understand the nuance: retention labels can delete content automatically *or* require manual review.
---
## Final Preparation Tips for MS-102 Purview Domains
- **Donât memorize the UI â understand the logic.** The exam asks âYou need to achieve X. Which three actions should you perform?â The order often mimics the configuration wizard.
- **Study the interplay between labels and policies.** A single requirement can involve sensitivity labels, auto-labeling, DLP, and retention. Know what each component brings to the solution.
- **Use the Microsoft Purview compliance portal hands-on.** A free Microsoft 365 developer tenant (E5 trial) lets you explore every feature. Practice building policies, seeing the effect, and checking the audit logs.
- **Pay attention to licensing caveats.** MS-102 often includes âWhat is the minimum license required?â For auto-labeling, records management, and insider risk, E5 is typically needed. Sensitivity labels alone are available with E3.
- **Review the domain weight breakdown** and allocate study time accordingly. Compliance is 15â20%, but itâs highly integrated with security and identity topics, so mastery here boosts your score across multiple areas.
Bottom line: Success on the MS-102 Purview section depends on your ability to translate business requirements into precise administrative actions. The scenario-based practice questions here provide a blueprint. Combine these walkthroughs with hands-on portal exploration, and youâll tackle even the trickiest compliance items with confidence.
> đ **Get the edge with targeted, exam-grade practice.**
> Donât stop here â the full MS-102 Purview practice test offers adaptive question banks, performance analytics, and explanations that bridge any knowledge gaps. Walk into the exam centre knowing youâve faced every scenario type.
> **[Start Full Test Now](/ms-102-full-purview-practice-test)**
---
## đ Recommended Study Resources & Video Tutorials
Access verified study guides, discount vouchers, and tutorial walkthroughs matching this certification:
- **[MS-102](https://getcertprep.com/ms-102-administrator-exam-prep)**:
- **[MS-102 Entra ID & Tenant Security Revision Mindmap](https://getcertprep.com/resources/ms102-mindmap.pdf)**: Visual breakdown of Conditional Access policies, PIM role activation, and Purview compliance enforcement.
- **[Microsoft Official Exam Prep Voucher - 30% Off](https://getcertprep.com/coupons/ms102-30-off)**: Limited time discount code for Microsoft 365 administrator certification exam booking. *(Use Coupon Code: `MS365SAVE30`)*
- **[AHIMA CHPS Study Guide & Privacy Practice Questions](https://getcertprep.com/resources/ahima-chps-guide.pdf)**: Comprehensive 50-page downloadable PDF covering HIPAA privacy rules, breach notification protocols, and healthcare data security controls.