Courseiva
Manage compliance by using Microsoft PurviewmediumMultiple ChoiceObjective-mapped

MS-102 Manage compliance by using Microsoft Purview Practice Question

A compliance officer needs to prevent users from sending emails that contain sensitive information, such as social security numbers, to external recipients. If a user attempts to send such an email, the action should be blocked and a policy tip should be displayed to the user. Which Microsoft Purview solution should the officer configure?

⚠ Common exam trap

Candidates often confuse sensitivity labels (which protect data at rest) with DLP (which protects data in motion), leading them to choose Option B because they think encryption prevents sending, but encryption does not block the email or show a policy tip at the point of sending.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Loss Prevention (DLP) policy

A Data Loss Prevention (DLP) policy in Microsoft Purview is designed to inspect email content for sensitive information (e.g., social security numbers) and can block the message while displaying a policy tip to the user. This matches the requirement exactly, as DLP policies enforce actions on data in transit (email) with user notifications.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP) policy

    Why this is correct

    A DLP policy in Microsoft Purview integrates with Exchange Online to inspect email content in transit and at the client. It uses sensitive information types (e.g., U.S. Social Security Number) as conditions and can apply an action to 'Block the message' from being sent, optionally allowing the sender to override with a business justification. At the same time, policy tips are displayed in Outlook, Outlook on the web, and Mail for iOS/Android during composition, providing real-time guidance before the message leaves the client. This is the only option that actually prevents the email from being sent and educates the sender.

  • sensitivity label with encryption

    Why it's wrong here

    A sensitivity label with encryption applies persistent rights management to content—such as view-only, edit, or no-forward—but it functions after the message is composed and delivered. Encryption and usage restrictions do not stop the send action in Outlook, nor do they scan the message body for sensitive data and issue a blocking condition. While a label may be mandatory or recommended, it does not provide a transport-level gate that prevents the email from being transmitted, so it fails to meet the compliance requirement.

  • Information Rights Management (IRM)

    Why it's wrong here

    Information Rights Management (IRM) in Exchange Online protects message content by applying usage restrictions that prohibit forwarding, printing, or copying, but it is not a sending gate. IRM works by encrypting the message and assigning rights to recipients after the send action is initiated; it does not evaluate the content for patterns like national ID numbers and cannot trigger an 'unable to send' denial. Additionally, IRM does not generate policy tips during composition because it is not rule-based content inspection, making it unsuitable for preventing an email from being sent.

  • retention label with deletion

    Why it's wrong here

    Retention labels are designed for information governance through retention and deletion actions—they can mark content as a record or permanently delete it after a specified period, but they have no ability to block outbound email at send time. A retention label does not inspect the message body for sensitive data or enforce transport rules, so it cannot intercept a violation during composition. Even a label configured for deletion only acts after the item is stored according to a lifecycle, not to prevent transmission of confidential information.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.