Block Emails with Credit Card Numbers Using DLP Policy Tip
A compliance officer needs to block users from sharing emails that contain credit card numbers with external recipients. When a user attempts to send such an email, it should be blocked immediately, and a policy tip should notify the user. Which Microsoft Purview solution should the officer configure?
Quick Answer
The correct answer is Data Loss Prevention (DLP) policy. This Microsoft Purview solution is specifically designed to detect sensitive information types, such as credit card numbers, using predefined rule patterns that validate against the Luhn algorithm, and can enforce immediate actions like blocking the email while displaying a policy tip to the sender. On the MS-102 exam, this scenario tests your understanding of how DLP policies apply to data in transit—a common trap is confusing DLP with Microsoft Defender for Office 365 or sensitivity labels, which handle threat protection and classification, not real-time blocking with user notification. Remember that when you need to block emails with credit card numbers and show a policy tip, you are configuring a DLP rule with an action set to "Block" and a notification tip enabled. A useful memory tip: DLP = Detect, Lock, and Prompt—it finds the sensitive data, locks the send action, and prompts the user with a tip.
⚠ Common exam trap
Many exam-takers confuse the real-time blocking and notification capability of DLP with sensitivity labels (which only apply protection after classification) or communication compliance (which is a review-based solution, not a real-time enforcement mechanism).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policy.
A Data Loss Prevention (DLP) policy is the correct solution because it is specifically designed to detect sensitive information types (e.g., credit card numbers via predefined rule patterns matching the Luhn algorithm) in transit and enforce actions such as blocking the email and displaying a policy tip to the sender. This meets the compliance officer's requirement to block external sharing of credit card data immediately with user notification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP) policy.
Why this is correct
DLP policies inspect email content for sensitive data types such as credit card numbers, block transmission to external recipients, and display policy tips to the sender. This directly satisfies the requirement to stop the email immediately while notifying the user.
- ✗
Sensitivity label with encryption.
Why it's wrong here
Sensitivity labels with encryption restrict access to content but do not automatically detect credit card numbers or block external sending with a policy tip. It would be correct for manually or automatically classifying and encrypting documents, whereas this scenario needs pattern-based detection and real-time blocking.
- ✗
Microsoft Defender for Office 365 Safe Attachments policy.
Why it's wrong here
Safe Attachments detonates email attachments in a sandbox to detect malware, and cannot inspect message body content for credit card patterns or block on data classification. It would be correct for defending against malicious attachments, not for data-loss prevention with user-facing policy tips.
- ✗
Communication compliance policy.
Why it's wrong here
Communication compliance policies detect and review potentially inappropriate messages after they are sent, routing them to reviewers for investigation; they cannot block a send in real time. It is tempting because it does handle sensitive-data and policy-violation detection, but the correct solution is a DLP policy with policy tips, which intercepts the email at send time.
Go deeper
Related to this question
Learn chapter
Teams Compliance: Recording and Archiving
Key term
External sharing
External sharing is the process of granting access to an organization's internal resources, such as documents or sites, to users who are not part of the organization's own identity system.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user in your organization receives a 'Message blocked' notification when trying to send an email with a credit card number. The DLP policy is configured to block such emails. The user claims the credit card number is a valid test number used for training. What should you do to allow the email while maintaining security?
easy- ✓ A.Configure a policy tip to allow override with a business justification.
- B.Exclude the user from the DLP policy.
- C.Disable the DLP policy temporarily.
- D.Add the user to the DLP policy's super user group.
Why A: Configuring a policy tip with override allows the user to justify the override with a business justification, which is audited. This maintains security by notifying the user and recording the override for compliance. Option B (excluding the user) removes DLP protection entirely for that user, which is insecure. Option C (disabling the policy) disables protection for all users. Option D (adding to super user group) bypasses all DLP checks for the user, which is too permissive.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.