MS-102 Manage compliance by using Microsoft Purview Practice Question
A compliance officer wants to prevent users from sending emails that contain personally identifiable information (PII), such as social security numbers, to external recipients. If a user attempts to send such an email from Outlook, the email should be blocked and a policy tip explaining the block should be displayed. Which Microsoft Purview solution should the officer configure?
⚠ Common exam trap
Many candidates confuse sensitivity labels (which apply protection at rest) with DLP policies (which enforce actions on data in motion), leading them to choose Option B because they associate labels with 'protecting' PII, but labels do not block outbound email or trigger policy tips.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention (DLP) policy
Microsoft Purview Data Loss Prevention (DLP) policies are specifically designed to detect and block sensitive information, such as PII (e.g., social security numbers), in transit. When a DLP rule matches, it can block the email and display a policy tip in Outlook, informing the user why the message was blocked. This meets the compliance officer's requirement to prevent external sending of PII with real-time user notification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Data Loss Prevention (DLP) policy
Why this is correct
A Microsoft Purview Data Loss Prevention (DLP) policy is exactly designed for this scenario: when applied to Exchange Online, it inspects outbound messages in transit against sensitive info types (such as social security numbers or credit card numbers) and can take corrective actions like blocking the message before it leaves the organization, optionally allowing an end-user override with justification and a policy tip in Outlook. This combination of content inspection, transport-level enforcement, and real-time user notification makes it the correct choice for preventing users from sending emails with specific sensitive data.
- ✗
Microsoft Purview Information Protection sensitivity label
Why it's wrong here
Sensitivity labels are metadata-based classifiers that apply protection such as encryption, visual watermarks, and permissions to email after the user selects (or an auto-labeling rule assigns) the label; they do not perform real-time content scanning of the outgoing email against a predefined list of sensitive info types, nor can they block the send action in Outlook the way a DLP policy does. While a label can enforce encryption that makes email unreadable to unauthorized recipients, it does not prevent the sender from composing and sending the message, so it fails the 'prevent sending' requirement.
- ✗
Microsoft Purview Records Management retention label
Why it's wrong here
Retention labels focus purely on data lifecycle management: they retain content for a specified period, start a retention review, or permanently delete it based on age or events, but they never inspect email bodies or attachments for sensitive data patterns. Because they are applied asynchronously after content is saved or sent, they have no mechanism to interrupt an outbound email in transit or to display a policy tip at the moment of composition. Therefore, they are entirely unsuitable for blocking email transmission based on content.
- ✗
Microsoft Purview eDiscovery case
Why it's wrong here
eDiscovery cases are designed for litigation and investigation scenarios: they allow a legal or compliance team to place content on hold, search across mailboxes and sites, and export evidence for review, but they operate after the fact rather than in the send path. An eDiscovery hold can keep email from being permanently purged, but it does not inspect outgoing mail for sensitive data and cannot block a user from hitting 'send' in real time. Thus, it only preserves or locates data, not prevent data leaks in transit.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.