Courseiva

Data Loss Prevention (DLP) Policies

A financial services company must prevent users from accidentally sharing sensitive customer data externally. They want to block sharing of any document containing a credit card number via email or SharePoint. What combination of Microsoft 365 compliance solutions should they use?

Quick Answer

Data Loss Prevention policies are the mechanism for this because the requirement is to block an action based on the content inside a document, not to control who can access a location. A DLP policy in Microsoft Purview scans outgoing email and SharePoint sharing activity for sensitive information types — a credit card number matched by pattern and checksum is a built-in type — and can block the action automatically once a match is found, rather than merely logging it for later review. That automatic blocking, applied consistently across both email and SharePoint from one policy, is what distinguishes DLP from sensitivity labels, which protect a file's content but do not by themselves stop a sharing action from happening. Financial services scenarios on this exam consistently pair 'prevent sharing of a specific data pattern' with DLP as the answer — recognising that phrase is the fastest way through this question type.

⚠ Common exam trap

Many exam-takers confuse sensitivity labels (which classify and protect data at rest) with DLP (which monitors and blocks data in motion), leading them to choose Option A, even though DLP is the correct solution for preventing accidental external sharing of sensitive content like credit card numbers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention (DLP) policies

Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and block the sharing of sensitive information, such as credit card numbers, across email (Exchange Online) and SharePoint. By scanning content for predefined sensitive info types (e.g., credit card numbers using regex patterns from the DLP engine), DLP can automatically block or warn users before external sharing occurs, meeting the company's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sensitivity labels and Microsoft Purview Information Protection (Microsoft Purview Information Protection)

    Why it's wrong here

    Sensitivity labels classify and protect content but do not automatically detect credit card numbers in documents; that requires a data loss prevention policy with a sensitive information type. It is tempting because labels are the right choice for user-applied classification and encryption, not pattern-based blocking.

  • ✓

    Data Loss Prevention (DLP) policies

    Why this is correct

    DLP policies inspect content in Exchange email and SharePoint, detecting credit card numbers via sensitive information types and blocking external sharing. This directly satisfies the requirement to prevent accidental external disclosure of documents containing card numbers across both channels.

  • ✗

    Microsoft Purview Compliance Manager

    Why it's wrong here

    Compliance Manager only assesses and scores compliance posture against regulations; it cannot inspect documents or block sharing. It is tempting because it is the correct choice for tracking regulatory compliance readiness, but the scenario needs data loss prevention policies with credit card sensitive information types to block email and SharePoint sharing.

  • ✗

    Exchange Online Protection (EOP) and Microsoft Defender for Microsoft 365

    Why it's wrong here

    EOP and Defender for Microsoft 365 filter mail-borne malware, phishing and spam, and scan links and attachments; they do not inspect document content for credit card numbers or block sharing in SharePoint. Data loss prevention with sensitive information types is required to detect and block that content across email and SharePoint.

Go deeper

Related to this question

About these practice questions

This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on MS-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user accidentally shared a file containing credit card numbers with a partner organization. You need to prevent similar incidents and detect when such data is shared externally. What should you configure?

medium
  • A.Azure Information Protection (AIP)
  • B.Microsoft Purview eDiscovery
  • ✓ C.Microsoft 365 Data Loss Prevention (DLP) policy
  • D.Information Rights Management (IRM)

Why C: Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify sensitive information such as credit card numbers using sensitive information types and to prevent or detect when that data is shared externally. DLP can block sharing, generate alerts, and provide policy tips to users, directly addressing both prevention and detection requirements.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.