Drag or tap steps into the slots.
MS-102 Manage compliance by using Microsoft Purview Practice Question
Drag and drop the steps to configure Data Loss Prevention (DLP) policies in Microsoft Purview in the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Create DLP policy, Define conditions and actions, Test the policy, Deploy the policy
DLP policies are created in Purview, conditions and actions defined, and then deployed after testing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create DLP policy, Define conditions and actions, Test the policy, Deploy the policy
Why this is correct
In Microsoft Purview, creating the DLP policy first establishes the policy container and its scope—such as Exchange, SharePoint, OneDrive, and endpoints. You then define conditions, like sensitive info types or labels, and actions, such as restricting access or showing policy tips. Testing the policy in simulation mode validates detection accuracy and user impact before full enforcement. Deploying in the final step turns on enforcement, often after reviewing test results and adjusting rules to minimize false positives.
- ✗
Define conditions and actions, Create DLP policy, Test the policy, Deploy the policy
Why it's wrong here
You cannot define conditions and actions before the DLP policy exists because in Microsoft Purview, conditions and actions are properties of a policy object, not standalone entities. Attempting to configure them first is impossible in the compliance portal UI; the policy creation wizard must first capture the policy name, locations, and scope. Only after this container is created can you add rules with conditions and actions. This order also ensures that any test or deployment activity has a defined policy to which it can refer.
- ✗
Create DLP policy, Define conditions and actions, Deploy the policy, Test the policy
Why it's wrong here
Deploying the DLP policy before testing risks making changes to production without evidence that detection rules are accurate. Unlike test mode, a fully deployed policy enforces actions such as blocking or encrypting content, which can disrupt legitimate business workflows if the policy has false positives. Microsoft Purview provides a test mode that generates reports on matches without applying remediation, letting you validate the policy and adjust thresholds. Only after validating test results should you set the policy to enforcement mode, making deploy-before-test an unsafe shortcut.
- ✗
Create DLP policy, Test the policy, Define conditions and actions, Deploy the policy
Why it's wrong here
Testing a DLP policy before defining its conditions and actions yields no meaningful results because there is no detection logic to evaluate. In Microsoft Purview, test mode measures how well rules and conditions match content; with no rules configured, all test reports would be empty or non-informative. Additionally, the policy's scope and locations are not yet finalized, so tests would not reflect the actual environment. Therefore, conditions and actions must be configured first to provide content for the test phase.
Go deeper
Related to this question
About these practice questions
Courseiva writes every MS-102 question from scratch — 712 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.