MS-102 Manage compliance by using Microsoft Purview Practice Question
An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to create a policy that blocks users from pasting credit card numbers into web forms in Microsoft Edge. Which type of DLP policy should they configure?
⚠ Common exam trap
Watch out — candidates often assume all DLP policies are cloud-based and overlook that only Endpoint DLP can enforce restrictions on local user actions like pasting into web forms, confusing it with Exchange or SharePoint DLP which only inspect data at rest or in transit within Microsoft 365 services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Endpoint DLP
Endpoint DLP is correct because it monitors and controls activities on Windows 10/11 and macOS endpoints, including the ability to block pasting sensitive data like credit card numbers into web forms in Microsoft Edge. This policy extends DLP protection to unmanaged browsers and specific user actions, such as paste, clipboard, and print, which are not covered by cloud-based DLP policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Endpoint DLP
Why this is correct
Endpoint DLP is the correct selection because it monitors Windows and macOS devices and can inspect user activities such as copying sensitive content to the clipboard. When a user attempts to paste that data into a web form, Endpoint DLP in Microsoft Edge or another supported Chromium-based browser can evaluate the policy condition and block the paste action. The capability relies on the Microsoft Purview endpoint agent being onboarded on the device, and it is the only option that controls clipboard operations at the endpoint itself.
- ✗
Exchange DLP
Why it's wrong here
Exchange DLP policies are designed for messages in transit and mailboxes, using transport rules to scan email headers, body, and attachments. They can enforce actions like encrypting, quarantining, or blocking emails, but they have no mechanism to intercept or block a user's local clipboard paste into a web browser form. Since the issue occurs on the endpoint rather than in email flow, Exchange DLP is inapplicable and therefore incorrect.
- ✗
SharePoint DLP
Why it's wrong here
SharePoint DLP applies to files and documents stored in SharePoint Online and OneDrive for Business, governing external sharing, permissions, and file-level protection. It can analyze document content and prevent unsafe sharing, but it does not observe the user's device activity or local clipboard operations. Opening a document in SharePoint does not expose clipboard or browser form events, so this policy location cannot block a paste into a web form and is incorrect.
- ✗
Teams DLP
Why it's wrong here
Teams DLP policies protect messages and files shared within Microsoft Teams chat, channels, and meetings, detecting sensitive data in conversation content and applying restrictions such as blocking or allowing message delivery. These policies operate on data within Teams and do not integrate with endpoint clipboard or browser form functionality. A paste action into an external web form is entirely outside the scope of Teams DLP, which makes this option incorrect.
Go deeper
Related to this question
Learn chapter
SharePoint External Sharing and Guest Policies
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.