MS-102 Manage compliance by using Microsoft Purview Practice Question
Exhibit
Refer to the exhibit.
Get-DlpComplianceRule -Identity "Block PII" | Format-List
Name : Block PII
Policy : DLP Policy 1
Conditions : @{SensitiveInformation=System.Object[]; MinCount=1}
Actions : {BlockAccess, NotifyUser}
Mode : Enable
Priority : 2
Get-DlpComplianceRule -Identity "Block Credit Cards" | Format-List
Name : Block Credit Cards
Policy : DLP Policy 2
Conditions : @{SensitiveInformation=System.Object[]; MinCount=1}
Actions : {BlockAccess, NotifyUser}
Mode : Enable
Priority : 1Refer to the exhibit. You have two DLP compliance rules as shown. A user sends an email containing both PII and credit card numbers. Which rule will be applied?
⚠ Common exam trap
The trap is assuming DLP rules conflict or that only the first matching rule applies — the exam tests whether you know that all matching rules are evaluated and the most restrictive action is enforced.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Both rules will be evaluated, and the most restrictive action will be applied.
When multiple DLP rules match the same email, Microsoft Purview evaluates all matching rules and applies the most restrictive action among them. In this case, both the PII rule and the Credit Cards rule match, so the action with the highest restriction (e.g., Block over Notify) is enforced. This ensures that sensitive data is protected even when multiple policies overlap.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Block PII rule only
Why it's wrong here
The 'Block PII rule only' option is incorrect because DLP does not stop evaluating after the first matching rule. The content contains both personal data (PII) and credit card numbers, so each rule independently matches the respective sensitive info type. Since both rules match, the action is not limited to the PII rule; the Credit Cards rule also contributes to the final decision.
- ✗
Block Credit Cards rule only
Why it's wrong here
The 'Block Credit Cards rule only' option is similarly wrong because it presumes the PII rule does not match. In a DLP policy, every rule is evaluated against the content separately, and if the data contains both PII and credit card numbers, both rules trigger. The resulting action is a composite of all matched rules, not a single rule chosen by the system.
- ✗
Neither rule will apply because they conflict.
Why it's wrong here
The 'Neither rule will apply because they conflict' option misinterprets how DLP handles multiple matches. DLP rules do not conflict or mutually exclude one another; they are evaluated concurrently, and matched rules are aggregated. Rather than canceling out, the rules together produce the most restrictive enforced action, so both still apply.
- ✓
Both rules will be evaluated, and the most restrictive action will be applied.
Why this is correct
This is correct because Microsoft 365 DLP evaluates all rules in a policy against the content and then applies the most restrictive action among those that match. Since both the Block PII rule and the Block Credit Cards rule include a Block action, the block is enforced for any matching content. This design ensures that layered protections do not weaken each other and that the highest severity action always wins.
Go deeper
Related to this question
Learn chapter
Data Loss Prevention Policies
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.