Courseiva

MS-102 Manage compliance by using Microsoft Purview Practice Question

Which TWO actions can you perform using Microsoft Purview Data Loss Prevention (DLP) policies?

⚠ Common exam trap

MS-102 often tests the specific actions DLP can take versus those it cannot, such as encryption or watermarking; candidates may incorrectly assume DLP can encrypt or watermark files.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Show a policy tip to users when they attempt to share sensitive data.

Option B is correct because Microsoft Purview DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and SharePoint) when their actions match a DLP rule, warning them before they share sensitive data. Option C is correct because DLP policies can enforce blocking actions, such as preventing users from sending emails containing sensitive information like credit card or Social Security numbers, via Exchange/Outlook and other workloads. Option A is not a DLP function; retention periods are configured with retention labels and retention policies in Microsoft Purview Data Lifecycle Management (or records management), not DLP. Option D is not a DLP action; watermarks are applied through sensitivity labels with content marking (or Azure Information Protection), not DLP policies. Option E is not a DLP action; automatic encryption is achieved through sensitivity labels with encryption settings, not DLP, which focuses on detecting and restricting/blocking sharing rather than encrypting files.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set retention periods for documents containing credit card numbers.

    Why it's wrong here

    Retention periods are governed by retention labels and retention policies in Microsoft Purview Data Lifecycle Management, not by DLP rules. DLP detects sensitive content and blocks, warns, or audits sharing; it does not schedule deletion. It tempts because DLP also matches credit-card numbers via sensitive information types, the same detection engine retention uses.

  • ✓

    Show a policy tip to users when they attempt to share sensitive data.

    Why this is correct

    Policy tips deliver real-time, in-context warnings within supported apps such as Outlook, Word and Teams when a user's action matches a DLP rule condition, satisfying the requirement to notify users attempting to share sensitive data. Enforcement occurs at the point of egress, letting users justify or override before the item leaves the tenant.

  • ✓

    Block users from sharing sensitive information via email.

    Why this is correct

    Microsoft Purview DLP policies enforce protective actions when sensitive information is detected, and blocking email sharing is one such enforcement action. Exchange Online conditions within a DLP policy can prevent messages containing sensitive data from being sent, directly satisfying the requirement to stop users sharing sensitive information externally.

  • ✗

    Add a watermark to sensitive documents.

    Why it's wrong here

    Watermarking is applied by sensitivity labels configured with content marking in Microsoft Purview Information Protection, not by DLP policies. DLP rules act on sharing, copying or uploading events. It tempts because both features target the same sensitive documents, and watermarking is correct when the requirement is visible labelling of classified content.

  • ✗

    Automatically encrypt sensitive files when shared.

    Why it's wrong here

    DLP policies apply encryption through sensitivity labels and Endpoint DLP actions, but automatic encryption on sharing is enforced by label-based protection in Microsoft Purview Information Protection, not by a DLP rule itself. It tempts because DLP and labels are configured together, and encryption is the right control when the requirement is persistent file protection.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.