Three Required Components for a DLP Policy Blocking Credit Card Numbers in Email
Your organization is implementing Microsoft Purview Data Loss Prevention (DLP). You need to ensure that sensitive data such as credit card numbers cannot be shared externally via email. Which THREE components should you configure?
⚠ Common exam trap
Many exam-takers confuse Insider Risk Management (a behavior-based tool) with DLP (a content-based policy), or think a retention policy is needed to block sharing, when in fact DLP policies alone handle detection and enforcement via SITs and rule actions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Define sensitive information types for credit card numbers
A is correct because sensitive information types (SITs) are predefined or custom patterns that detect specific data like credit card numbers (e.g., regex matching major credit card formats). Defining the SIT for credit card numbers allows the DLP policy to identify this sensitive content in emails, which is the first step before any action can be taken.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Define sensitive information types for credit card numbers
Why this is correct
Sensitive information types are the detection backbone of a Microsoft Purview DLP policy. Built-in SITs such as "Credit Card Number" use pattern matching, checksum validation, and keyword evidence to identify card data in Exchange, SharePoint, OneDrive, and Teams. Defining or fine-tuning these SITs (e.g., confidence levels or custom patterns) ensures that the DLP policy accurately detects credit card numbers before rules and actions can act on them.
- ✗
Enable Microsoft Purview Insider Risk Management
Why it's wrong here
Insider Risk Management is an independent Purview solution that identifies potential insider threats by analyzing user behavior patterns such as unusual data exfiltration, not by inspecting content for sensitive data. While it can alert on risky activities, it does not provide the content-aware scanning or sharing-blocking actions that DLP policies enforce. Enabling it would not help detect credit card numbers or block external sharing, so it is not part of DLP implementation.
- ✓
Configure DLP rule actions to block external sharing
Why this is correct
Configuring DLP rule actions is what actually enforces the policy. In Microsoft Purview, a rule can contain conditions (e.g., content contains a SIT and is shared externally) and actions such as "Block users from sharing with external users" or "Allow override with business justification." Without these actions, the policy is only audit-mode and will not prevent external sharing, so setting the desired action is an essential implementation step.
- ✗
Configure a retention policy for email
Why it's wrong here
Retention policies govern the lifecycle of email and other content by preserving or permanently deleting items after a specified period, typically for regulatory or legal requirements. They do not inspect message content for sensitive information, nor do they prevent a user from forwarding or externally sharing email. Therefore, a retention policy is unrelated to DLP's goal of blocking unauthorized sharing of credit card numbers.
- ✓
Create a DLP policy in Microsoft Purview
Why this is correct
Creating a DLP policy in Microsoft Purview is the central implementation activity because it binds the selected sensitive information types, locations (Exchange, SharePoint, OneDrive, Teams, Devices), and one or more rules into a single enforcement unit. The policy lifecycle includes defining the rules and actions, specifying the people/accounts it applies to, and choosing the mode (test vs enforce). It is the container that transforms raw detection capability into an actual data loss prevention control.
Go deeper
Related to this question
Learn chapter
Microsoft Purview Data Map
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.