MS-102 Manage compliance by using Microsoft Purview Practice Question
A compliance officer needs to prevent external users from printing or copying content from documents stored in a SharePoint Online site. Which Microsoft Purview feature should be configured to enforce this restriction?
⚠ Common exam trap
It's easy for candidates to confuse DLP policies with content protection, assuming DLP can restrict printing or copying after access, when in fact DLP only controls data in transit or at rest and does not enforce persistent usage rights on the document itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels with encryption and usage rights
Sensitivity labels with encryption and usage rights allow administrators to apply Azure Rights Management (Azure RMS) protection to documents, which can restrict actions such as printing and copying. By configuring a sensitivity label with specific usage rights (e.g., 'View Only' or disabling 'Extract' and 'Print'), external users are prevented from printing or copying content even after the document is downloaded or accessed in SharePoint Online. This is the only Purview feature that directly enforces persistent content-level restrictions on external users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity labels with encryption and usage rights
Why this is correct
Sensitivity labels with encryption and usage rights directly enforce document-level restrictions by applying Azure Rights Management (RMS) protection. When an external user opens the document, the RMS client enforces usage rights that explicitly deny actions such as printing, copying, and editing, regardless of where the file is stored or how it is shared. These restrictions travel with the file itself, making them effective even after the file leaves your tenant, and they can be scoped to specific external users or groups.
- ✗
Data Loss Prevention (DLP) policy
Why it's wrong here
Data Loss Prevention (DLP) policies are designed to detect and prevent the unauthorized sharing of sensitive information via communication channels like email, Teams, and SharePoint. DLP operates at the network and content level, evaluating data in transit or at rest, but it cannot govern what an external user does with a file after it has been legitimately opened. Because DLP does not embed persistent permissions into the file, it cannot prevent printing, copying, or editing offline — it only stops the initial transmission of sensitive data.
- ✗
Information Barriers
Why it's wrong here
Information Barriers are an administrative configuration in Microsoft 365 that restricts communication and collaboration between specific groups or users within an organization, such as preventing two departments from interacting. They apply to conversations, meetings, and shared sites, but they do not attach any permissions or usage rights to individual documents. External users are generally outside the scope of information barrier policies, and even if barriers were applied, they would not control what an external recipient can do with a document once opened.
- ✗
Microsoft Purview Information Protection without encryption
Why it's wrong here
Applying a Microsoft Purview Information Protection label without encryption only adds metadata (like classification text or a visual marking) to the document; it does not enforce any restrictions on usage. Without Azure RMS encryption, the file remains fully accessible, and any user with access can freely print, copy, or edit the content. Encryption is the critical mechanism that binds usage rights to the file — a label alone, no matter how it is configured, cannot enforce rights like 'Do Not Print' unless it is accompanied by protected rights management.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.