Drag or tap steps into the slots.
MS-900 Practice Question: Describe security, compliance, privacy, and trust in Microsoft 365
Drag and drop the steps to configure a data loss prevention (DLP) policy in the Microsoft 365 compliance center into the correct order.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Step 1: Select a DLP template or start with a custom policy. Step 2: Choose the locations (Exchange, SharePoint, OneDrive, Teams) where the policy applies. Step 3: Define the policy rules with conditions and actions.
DLP policies are created in the compliance center by selecting a template, locations, and rules.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Step 1: Select a DLP template or start with a custom policy. Step 2: Choose the locations (Exchange, SharePoint, OneDrive, Teams) where the policy applies. Step 3: Define the policy rules with conditions and actions.
Why this is correct
Selecting a DLP template first is correct because templates provide prebuilt rule categories (e.g., PII, financial, health) that align with common compliance regulations. After establishing the policy type, you then scope it to the appropriate locations such as Exchange, SharePoint, OneDrive, and Teams—since not every rule type is available in every location. Finally, you define or customize the specific rules (conditions and actions) based on the template and the chosen workloads, which is the logical wizard flow in Microsoft Purview.
- ✗
Step 1: Choose locations (Exchange, SharePoint, OneDrive, Teams). Step 2: Select a DLP template or start with a custom policy. Step 3: Define the policy rules with conditions and actions.
Why it's wrong here
Placing location selection before template selection is incorrect because the available conditions and actions for a DLP policy are largely determined by the template you choose. For example, a PCI-DSS template predefines rules for credit card numbers, whereas a custom policy starts with no defaults—so without a template first, you have no baseline rules to attach to the locations. Additionally, the Microsoft Purview DLP wizard enforces the template-first order, so this sequence does not reflect the actual configuration process.
- ✗
Step 1: Define the policy rules with conditions and actions. Step 2: Select a DLP template or start with a custom policy. Step 3: Choose locations (Exchange, SharePoint, OneDrive, Teams).
Why it's wrong here
Defining rules before selecting a template or locations is impractical because rules are dependent on both the template's built-in rule patterns and the specific workloads they will apply to. In the Microsoft Purview interface, you cannot even advance to the rule-definition step without first selecting a template and then choosing locations, since the UI enforces that dependency. Furthermore, some conditions (like fingerprinting for custom sensitive info) and actions (like end-user notification) are only supported in certain locations, making it technically impossible to fully define rules in isolation.
- ✗
Step 1: Select a DLP template or start with a custom policy. Step 2: Define the policy rules with conditions and actions. Step 3: Choose locations (Exchange, SharePoint, OneDrive, Teams).
Why it's wrong here
Selecting the template first but then defining rules before locations is incorrect because the location selection is a required prerequisite for the rule-definition step in the DLP policy wizard. Rules must reference the specific workloads they apply to—for instance, whether a block action is allowed in Exchange versus Teams—so without locations chosen, you cannot accurately evaluate which rule actions are valid. The wizard is explicitly designed to collect locations before rules, and this order ensures that rule conditions and actions are scoped appropriately.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Compliance
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.