Courseiva
Manage compliance by using Microsoft PurviewhardMultiple ChoiceObjective-mapped

MS-102 Manage compliance by using Microsoft Purview Practice Question

A compliance officer needs to ensure that all emails containing sensitive information (e.g., passport numbers) are automatically encrypted when sent to external recipients. The encryption should be enforced without requiring users to manually select an option. Which Microsoft Purview feature should they configure?

⚠ Common exam trap

Test-takers frequently confuse sensitivity labels with auto-labeling as the solution for automatic encryption, but auto-labeling only applies labels based on conditions and does not enforce encryption unless the label itself is configured for encryption and the DLP policy triggers the action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Loss Prevention (DLP) policy with encryption action

A Data Loss Prevention (DLP) policy with encryption action is correct because it automatically detects sensitive information (e.g., passport numbers) using sensitive info types and enforces encryption via Microsoft Purview Message Encryption (OME) as a rule action. This ensures that when an email containing such data is sent to an external recipient, the email is automatically encrypted without requiring user intervention, meeting the compliance officer's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP) policy with encryption action

    Why this is correct

    Data Loss Prevention (DLP) policies in Microsoft Purview can directly apply an encryption action to outgoing email by leveraging Azure Rights Management. When a DLP policy detects a sensitive information type (e.g., credit card numbers or personally identifiable information) in the message body or attachments, it automatically wraps the message with the 'Encrypt' action, enforcing transport-level protection without user intervention. This policy-based approach is purpose-built for compliance scenarios where data exfiltration must be prevented at the email boundary.

  • Sensitivity labels with auto-labeling

    Why it's wrong here

    Sensitivity labels with auto-labeling can encrypt messages only if the assigned label itself is configured with Rights Management protection, and the auto-labeling policy is scoped to Exchange in transit. However, auto-labeling is primarily designed to classify and protect documents and emails at rest, and for outgoing email it requires additional configuration, such as enabling an in-transit label policy and ensuring label inheritance is correctly applied. DLP inherently couples content detection with an immediate encryption action, making it more reliable for 'ensure all emails containing sensitive data' rather than relying on label classification.

  • Message Encryption (OME) policies

    Why it's wrong here

    Office 365 Message Encryption (OME) is a feature of Exchange Online that provides encryption capabilities, but it is not a content-aware policy engine. To automatically encrypt emails based on sensitive data, OME must be triggered by an Exchange mail flow rule or a DLP policy; OME itself does not scan messages for data loss prevention. Additionally, OME is not presented as a Microsoft Purview compliance policy type, so it would be an awkward fit for a compliance officer using the Purview portal for centralized enforcement.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance is a Microsoft Purview solution designed for monitoring and reviewing communications for policy violations, such as harassment, threats, or inappropriate sharing. It identifies potentially non-compliant messages and routes them for administrative review and investigation, but it does not include any enforcement actions like encrypting outgoing email. Therefore, while it can detect sensitive data being shared, it cannot automatically protect that data in transit, making it unsuitable for the stated requirement.

About these practice questions

This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.