MS-900 Describe cloud concepts Practice Question
Exhibit
{
"policy": {
"description": "Data Loss Prevention policy for credit card numbers.",
"priority": 1,
"mode": "enforce",
"rules": [
{
"name": "Credit Card Rule",
"condition": {
"sensitiveInformationTypes": [
{
"id": "Credit Card Number",
"confidenceLevel": "high"
}
]
},
"action": {
"type": "blockAccess",
"blockAccessMessage": "This content contains sensitive information and cannot be shared externally."
}
}
]
}
}Refer to the exhibit. A Contoso user tries to send an email containing a credit card number to an external recipient. What will happen?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The email is blocked and the user receives a notification.
The DLP policy enforces blocking of credit card numbers. Option B is wrong because the policy is enforced, not just audit. Option C is wrong because it blocks, not removes. Option D is wrong because it blocks, not quarantines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The email is blocked and the user receives a notification.
Why this is correct
This is correct because the DLP policy is set to enforce mode with a block action. When the credit card number is detected as a sensitive info type, Outlook or Outlook on the web displays a policy tip to the sender, and the message is not delivered. The notification informs the user that the content violates policy and that the send is prevented.
- ✗
The credit card number is removed and the email is sent.
Why it's wrong here
This is incorrect because DLP policies do not support automatic removal of sensitive data from an email in transit. The only content actions available are block, block with override, or allow with audit. Removing data would require a custom action or advanced data classification not offered by a standard DLP rule. Since the exhibit shows the action set to block, no modification occurs.
- ✗
The email is sent and an alert is generated for admin.
Why it's wrong here
This is incorrect because the policy is in enforce mode, not test/audit mode. In audit mode, the email would be delivered and an admin might receive an alert for investigation. In enforce mode, delivery is prevented at the transport layer, and an alert would only be generated as a separate incident report after the block. Thus, the email is not sent when the policy is enforced.
- ✗
The email is delivered to the external recipient but placed in quarantine.
Why it's wrong here
This is incorrect because the policy action in the exhibit is to block access, which prevents the email from being delivered to the external recipient altogether. Quarantine is a separate mechanism used by anti-spam or malware filters, not by DLP policies. A blocked DLP email is held with the sender or suppressed entirely, and the sender receives a policy tip rather than the recipient receiving it in quarantine.
Go deeper
Related to this question
About these practice questions
This MS-900 question is part of Courseiva's 794-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.