MS-102 Manage compliance by using Microsoft Purview Practice Question
A compliance officer needs to prevent users from copying sensitive data (e.g., credit card numbers) from a finance application into personal email or documents. The solution must inspect the content in real-time and block the action if sensitive data is detected. Which Microsoft Purview feature should the officer configure?
⚠ Common exam trap
It's easy for candidates to confuse sensitivity labels (which protect data at rest) with DLP policies (which enforce real-time action blocking), leading them to select sensitivity labels because they think labeling alone prevents copying, but labels do not block user actions in real-time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policies
Microsoft Purview Data Loss Prevention (DLP) policies are designed to inspect content in real-time as users attempt to copy, paste, or share sensitive data (e.g., credit card numbers) from applications like finance apps into personal email or documents. DLP uses deep content analysis via sensitive information types and policy tips to block the action before the data leaves the controlled environment, meeting the compliance officer's requirement for real-time blocking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP) policies
Why this is correct
DLP policies are the correct choice because they perform real-time content inspection on endpoints and cloud apps, matching against sensitive information types (e.g., credit card numbers, PII) and then enforcing protective actions. A DLP policy can specifically block copy, paste, print, or transfer of that data to unauthorized destinations, and it can also trigger user notifications or incident reports. This is the only option that directly intercepts and prevents user copying actions at the point of resource access.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels are designed to classify and optionally protect content with encryption, rights management, and visual markings, but they do not natively detect or block real-time copying actions. While an encrypted file may prevent opening by unauthorized users, any user who has legitimate access (or is granted rights) can still copy the content displayed to them, for example, by retyping or taking a screenshot. Labels alone cannot inspect data in transit or on the clipboard to enforce a block on copy operations.
- ✗
Retention labels
Why it's wrong here
Retention labels are lifecycle management tools that control how long content is kept and what happens when it expires, such as deletion or preservation toward a compliance requirement. They operate on a schedule and apply to items at rest, but they have no mechanism to intercept or block user-initiated actions like copying, pasting, or moving data. Their purpose is disposition, not real-time content control.
- ✗
eDiscovery
Why it's wrong here
eDiscovery (purview eDiscovery) is designed for forensic search, hold, export, and review of content for legal or investigative purposes. It can preserve content in place via legal hold and search across repositories, but it does not monitor or block live user actions such as copying data. Any blockage of user behavior is outside eDiscovery's functional scope; it works on content that already exists, not on user interactions as they happen.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MS-102 question is part of Courseiva's 241-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.