MS-102 Manage compliance by using Microsoft Purview Practice Question
Which TWO actions can you perform using Microsoft Purview Data Loss Prevention (DLP) policies?
⚠ Common exam trap
MS-102 often tests the specific actions DLP can take versus those it cannot, such as encryption or watermarking; candidates may incorrectly assume DLP can encrypt or watermark files.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Show a policy tip to users when they attempt to share sensitive data.
Option B is correct because Microsoft Purview DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and SharePoint) when their actions match a DLP rule, warning them before they share sensitive data. Option C is correct because DLP policies can enforce blocking actions, such as preventing users from sending emails containing sensitive information like credit card or Social Security numbers, via Exchange/Outlook and other workloads. Option A is not a DLP function; retention periods are configured with retention labels and retention policies in Microsoft Purview Data Lifecycle Management (or records management), not DLP. Option D is not a DLP action; watermarks are applied through sensitivity labels with content marking (or Azure Information Protection), not DLP policies. Option E is not a DLP action; automatic encryption is achieved through sensitivity labels with encryption settings, not DLP, which focuses on detecting and restricting/blocking sharing rather than encrypting files.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set retention periods for documents containing credit card numbers.
Why it's wrong here
Retention periods are governed by retention labels and retention policies in Microsoft Purview Data Lifecycle Management, not by DLP rules. DLP detects sensitive content and blocks, warns, or audits sharing; it does not schedule deletion. It tempts because DLP also matches credit-card numbers via sensitive information types, the same detection engine retention uses.
- ✓
Show a policy tip to users when they attempt to share sensitive data.
Why this is correct
Policy tips deliver real-time, in-context warnings within supported apps such as Outlook, Word and Teams when a user's action matches a DLP rule condition, satisfying the requirement to notify users attempting to share sensitive data. Enforcement occurs at the point of egress, letting users justify or override before the item leaves the tenant.
- ✓
Block users from sharing sensitive information via email.
Why this is correct
Microsoft Purview DLP policies enforce protective actions when sensitive information is detected, and blocking email sharing is one such enforcement action. Exchange Online conditions within a DLP policy can prevent messages containing sensitive data from being sent, directly satisfying the requirement to stop users sharing sensitive information externally.
- ✗
Add a watermark to sensitive documents.
Why it's wrong here
Watermarking is applied by sensitivity labels configured with content marking in Microsoft Purview Information Protection, not by DLP policies. DLP rules act on sharing, copying or uploading events. It tempts because both features target the same sensitive documents, and watermarking is correct when the requirement is visible labelling of classified content.
- ✗
Automatically encrypt sensitive files when shared.
Why it's wrong here
DLP policies apply encryption through sensitivity labels and Endpoint DLP actions, but automatic encryption on sharing is enforced by label-based protection in Microsoft Purview Information Protection, not by a DLP rule itself. It tempts because DLP and labels are configured together, and encryption is the right control when the requirement is persistent file protection.
Go deeper
Related to this question
Learn chapter
Entra ID Entitlement Management and Access Packages
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Outlook
Microsoft Outlook is an email, calendar, and contact management application that is part of the Microsoft 365 suite, used by businesses and individuals to organize communications and schedules.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.