MS-102 Manage compliance by using Microsoft Purview Practice Question
A compliance officer needs to prevent users from sharing documents that have been labeled 'Highly Confidential' with external users. When a user attempts to share such a document externally, the action should be blocked and the user should see a policy tip. Which Microsoft Purview solution should the officer configure?
⚠ Common exam trap
Watch out — candidates often confuse sensitivity label encryption (which protects the file) with DLP (which controls the sharing action), leading them to choose encryption when the requirement explicitly involves blocking the share and showing a policy tip.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policy
A Data Loss Prevention (DLP) policy is the correct solution because it can inspect content and context (including sensitivity labels) to enforce rules that block external sharing of documents labeled 'Highly Confidential' and display a policy tip to the user. DLP policies in Microsoft Purview are specifically designed to prevent accidental or intentional data leakage by monitoring and controlling sharing actions in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP) policy
Why this is correct
A Microsoft Purview DLP policy can use sensitivity labels as conditions, and its actions can block sharing both via email (Exchange, Outlook) and external sharing in SharePoint/OneDrive. For example, when a condition like 'content contains a Confidential label' is met, the policy can block the sharing action and display a policy tip to the user before the block occurs. This directly enforces the compliance officer's requirement to prevent users from sharing content with a specific label, while the other mechanisms do not intercept the sharing action.
- ✗
Sensitivity label encryption
Why it's wrong here
Sensitivity label encryption protects content by applying Azure Rights Management usage rights (e.g., view, edit, copy, forward) to files and messages, but it does not evaluate whether a sharing action should be allowed. An encrypted file can still be attached to an email or shared via OneDrive; if the intended recipient is granted access or is inside the tenant, they can open it. Encryption is a confidentiality measure, not a sharing-permission policy, so it cannot by itself meet the 'prevent sharing' requirement.
- ✗
Retention policy
Why it's wrong here
A retention policy only governs the lifecycle of content by preserving it for a required period or permanently deleting it after that period; it executes automatically in the background. Rather than intercepting user or external sharing actions, it evaluates items based on age, creation date, or an event such as deletion. Because retention has no conditions for sensitivity labels or real-time user actions, it cannot prevent a user from sharing a document at the moment they attempt to do so.
- ✗
Records management
Why it's wrong here
Records management uses retention labels to mark an item as a record or regulatory record, which locks the content to prevent modification and deletion, but it does not disable the ability to share the file. A document that is a record can still be accessed and shared with external users, because records management does not examine sharing permissions or external recipients. To block sharing, you would still need a DLP policy that applies to the record's sensitivity label.
Go deeper
Related to this question
Learn chapter
Anti-Spam and Anti-Malware Policies
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
External sharing
External sharing is the process of granting access to an organization's internal resources, such as documents or sites, to users who are not part of the organization's own identity system.
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.