MS-900 Describe Microsoft 365 apps and services Practice Question
Exhibit
Refer to the exhibit.
```json
{
"version": "1.0",
"rules": [
{
"name": "Block sensitive data sharing",
"condition": {
"sensitiveInformationTypes": [
{
"id": "Credit Card Number",
"confidenceLevel": "high"
}
]
},
"actions": {
"blockAccess": true,
"notifyUser": true
}
}
]
}
```Refer to the exhibit. An admin creates a Microsoft Purview Data Loss Prevention (DLP) policy rule as shown. When will the rule block access?
⚠ Common exam trap
It's easy for candidates to assume the rule blocks access whenever a sensitive information type is detected, overlooking the specific confidence level requirement, or they might think the rule is not applied to any location without verifying the exhibit's location configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When a credit card number is detected with high confidence
The rule is configured with a condition that triggers when a credit card number is detected with a confidence level of 'high'. The action 'Block access' is set to execute when this condition is met. Therefore, the rule blocks access specifically when a credit card number is detected with high confidence, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
When a credit card number is detected with high confidence
Why this is correct
The rule's condition evaluates the content of the inspected document and requires the Credit Card Number sensitive information type (SIT) to be matched at the High confidence level. Content that is merely similar to a card number or detected at low or medium confidence will not satisfy this threshold. Because the exhibit shows this exact condition, a high-confidence credit card number match is the only outcome that would trigger the configured DLP action.
- ✗
When the document is shared externally
Why it's wrong here
Sharing the document externally is an activity-level event, but a content-based DLP rule condition does not automatically fire based on that event. Unless the policy explicitly includes the "Content is shared externally" condition, which is not shown in this rule, external sharing alone does not create a match. A document can be shared externally while containing no credit card number, leaving this rule inactive even though the sharing action occurred.
- ✗
When any sensitive information type is detected
Why it's wrong here
The rule does not say "any sensitive information type" — it is scoped specifically to the Credit Card Number SIT at high confidence. In Microsoft Purview DLP, administrators can combine multiple SITs using operators such as "Any of" or "All of," but the exhibit does not use that configuration. If the document contained a U.S. Social Security number or other sensitive info type, this rule would ignore it because the condition is restricted to credit card numbers.
- ✗
Never, because the rule is not applied to any location
Why it's wrong here
The exhibit shows only the rule's condition editor, not the overall policy configuration; in Purview DLP, location scopes such as Exchange, SharePoint, OneDrive, and Teams are assigned at the policy level, not inside the rule definition. Therefore, the absence of a location list in the rule view cannot prove that the policy is unapplied. A DLP policy is expected to have locations selected, and the default setup typically applies to common workloads, so concluding "never" from this screenshot is incorrect.
Go deeper
Related to this question
About these practice questions
One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.