MS-102 Manage compliance by using Microsoft Purview Practice Question
Your organization uses Microsoft Purview to enforce data loss prevention (DLP) policies. Users report that a DLP policy blocks legitimate sharing of a document containing sensitive financial data. You need to allow the sharing while still protecting the data. What should you do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a policy tip to allow override with a business justification.
Configuring a policy tip to allow override with a business justification enables users to legitimately share the document while still being audited. Policy tips notify users when their action violates a DLP policy and allow them to override with a justification, which is logged for review. Option A is wrong because disabling the policy removes protection entirely. Option B is wrong because adding a user to a super user group bypasses all DLP checks, which is not appropriate. Option C is wrong because excluding the document type could weaken protection for all similar documents.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the DLP policy and create a new one with broader conditions.
Why it's wrong here
Disabling the policy removes all protection for sensitive financial data, and broader conditions would widen blocking rather than permit this sharing. Recreating policies is tempting when conditions are misconfigured, but the scenario requires an exception or override path that preserves enforcement for other documents and users.
- ✗
Add the user to the DLP policy's super user group.
Why it's wrong here
Super user group membership bypasses DLP policy enforcement entirely for that user, so the financial data would no longer be protected during sharing. It is tempting because super users are intended for troubleshooting false positives, but that removes all policy controls rather than permitting this specific legitimate sharing while retaining protection.
- ✗
Modify the DLP policy to exclude the specific document type.
Why it's wrong here
Excluding the document type stops the policy detecting that sensitive financial data at all, leaving it unprotected wherever it travels. Exclusions suit file types that never contain regulated data, but here the content is genuinely sensitive, so the correct approach permits this sharing while retaining detection and protection.
- ✓
Configure a policy tip to allow override with a business justification.
Why this is correct
Policy tips with override let users supply a business justification to bypass the block, satisfying the need to permit legitimate sharing while retaining protection. The override is logged and auditable, so sensitive financial data remains governed rather than simply unblocked.
Go deeper
Related to this question
Learn chapter
Communication Compliance Policies
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.