MS-102 Manage compliance by using Microsoft Purview Practice Question
Your organization needs to ensure that all emails containing credit card numbers are automatically encrypted before being sent to external recipients. Which Microsoft Purview solution should you configure?
⚠ Common exam trap
MS-102 often tests the distinction between DLP and sensitivity labels; candidates pick sensitivity labels because they also encrypt, but DLP is the correct tool for automatic, content-based encryption of emails containing specific sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a DLP policy that uses the 'Encrypt email messages' action.
A Microsoft Purview DLP policy can detect sensitive information types like credit card numbers (via the Credit Card Number SIT) and apply the 'Encrypt email messages' action, which uses Office 365 Message Encryption (OME) to encrypt the email before it leaves the organization. This directly satisfies the requirement to automatically encrypt emails containing credit card numbers sent to external recipients. DLP policies are evaluated at send time and can enforce encryption without user intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a DLP policy that uses the 'Encrypt email messages' action.
Why this is correct
DLP policies in Microsoft Purview can be configured with the action 'Encrypt email messages' to automatically apply IRM (Azure RMS) protection to any outbound email that matches a sensitive info type condition. This action uses the built-in encryption template and does not require a separate label to be defined. When an email triggers a DLP rule, the message is encrypted in transit and at rest, enforcing access controls before delivery.
- ✗
Create a sensitivity label that applies encryption and auto-labeling.
Why it's wrong here
Auto-labeling with a sensitivity label that applies encryption can be used, but it depends on a separate auto-labeling policy to assign the label, and the label must be individually configured with encryption settings. While auto-labeling can inspect content for sensitive info types, it introduces an extra layer of label management and policy publication that a DLP policy does not require. For a direct, content-based encryption requirement, the DLP 'Encrypt email messages' action is the more immediate and standard control in Exchange Online.
- ✗
Set up a retention policy with encryption.
Why it's wrong here
Retention policies are designed to preserve, hold, or permanently delete emails based on age or other conditions; they have no capability to encrypt message content. Encryption is an information protection control, not a records management control. Applying a retention policy to an email does not alter its format or enforce rights management, so the messages would remain unencrypted and readable by any recipient.
- ✗
Implement a Communication Compliance policy.
Why it's wrong here
Communication Compliance policies are used to detect and analyze communications that may violate organizational standards, such as harassment, bullying, or regulatory compliance scenarios. They apply classifiers and trainable models to flag messages, but they cannot apply encryption or rights management protection. While they can generate alerts and hold messages for review, they do not have an action to encrypt the content.
Go deeper
Related to this question
Learn chapter
Microsoft Purview Data Map
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This MS-102 question is part of Courseiva's 712-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.