Courseiva
Manage compliance by using Microsoft PurviewhardMultiple ChoiceObjective-mapped

MS-102 Manage compliance by using Microsoft Purview Practice Question

A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?

⚠ Common exam trap

It's easy for candidates to confuse DLP policies with content protection, assuming DLP can restrict printing or copying after access, when in fact DLP only controls data in transit or at rest and does not enforce persistent usage rights on the document itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sensitivity labels with encryption and usage rights

Sensitivity labels with encryption and usage rights allow administrators to apply Azure Rights Management (Azure RMS) protection to documents, which can restrict actions such as printing and copying. By configuring a sensitivity label with specific usage rights (e.g., 'View Only' or disabling 'Extract' and 'Print'), external users are prevented from printing or copying content even after the document is downloaded or accessed in SharePoint Online. This is the only Purview feature that directly enforces persistent content-level restrictions on external users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sensitivity labels with encryption and usage rights

    Why this is correct

    Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.

  • Data Loss Prevention (DLP) policy

    Why it's wrong here

    Data Loss Prevention (DLP) policies are designed to detect and prevent the unauthorized sharing of sensitive information via communication channels like email, Teams, and SharePoint. DLP operates at the network and content level, evaluating data in transit or at rest, but it cannot govern what an external user does with a file after it has been legitimately opened. Because DLP does not embed persistent permissions into the file, it cannot prevent printing, copying, or editing offline — it only stops the initial transmission of sensitive data.

  • Information Barriers

    Why it's wrong here

    Information Barriers are an administrative configuration in Microsoft 365 that restricts communication and collaboration between specific groups or users within an organization, such as preventing two departments from interacting. They apply to conversations, meetings, and shared sites, but they do not attach any permissions or usage rights to individual documents. External users are generally outside the scope of information barrier policies, and even if barriers were applied, they would not control what an external recipient can do with a document once opened.

  • Microsoft Purview Information Protection without encryption

    Why it's wrong here

    Applying a Microsoft Purview Information Protection label without encryption only adds metadata (like classification text or a visual marking) to the document; it does not enforce any restrictions on usage. Without Azure RMS encryption, the file remains fully accessible, and any user with access can freely print, copy, or edit the content. Encryption is the critical mechanism that binds usage rights to the file — a label alone, no matter how it is configured, cannot enforce rights like 'Do Not Print' unless it is accompanied by protected rights management.

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.