MS-102 Manage compliance by using Microsoft Purview Practice Question
Your company has a Microsoft 365 E5 subscription. You need to prevent users from sharing files containing credit card numbers with external users. What should you configure?
⚠ Common exam trap
MS-102 often tests the distinction between DLP (which blocks sharing based on content inspection) and sensitivity labels (which classify and protect but do not automatically block sharing based on content), so candidates who pick sensitivity labels miss the requirement for automatic blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A DLP policy that blocks sharing of content with sensitive info type.
A Data Loss Prevention (DLP) policy in Microsoft 365 can detect sensitive information types such as credit card numbers and block sharing with external users. DLP policies are designed to prevent accidental or intentional sharing of sensitive data across Exchange, SharePoint, OneDrive, and Teams, making it the correct control for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A retention policy for SharePoint sites.
Why it's wrong here
Retention policies govern how long content is kept, and deletion afterwards; they neither inspect file contents nor block sharing. They are tempting because they are configured on SharePoint sites and appear protective, yet preventing external sharing of credit card data needs a DLP policy with sensitive information types.
- ✗
An information barrier policy.
Why it's wrong here
Information barriers restrict communication and collaboration between defined user segments, not content matching; credit card numbers require a DLP policy with sensitive information types. Barriers are tempting because they also govern external sharing, but their axis is user-group separation, not data classification.
- ✗
A sensitivity label with encryption.
Why it's wrong here
Encryption protects content from unauthorised reading, but does not stop a user sharing the file externally; the recipient may still open it if granted rights. It is tempting because labels can restrict sharing, yet the requirement is detecting credit card numbers, which needs a DLP policy with sensitive information types.
- ✓
A DLP policy that blocks sharing of content with sensitive info type.
Why this is correct
A DLP policy that blocks sharing of content matching a sensitive information type directly enforces the credit card number constraint, since Microsoft Purview's built-in credit card sensitive info type detects those patterns and blocks external sharing in Microsoft 365 E5.
Go deeper
Related to this question
Learn chapter
SharePoint Search Administration
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.