Design solutions that align with security best practices and priorities →easyMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company is adopting Microsoft Purview for data security. They need to prevent users from sharing sensitive data like credit card numbers via email. Which feature should you configure?
⚠ Common exam trap
A common mix-up: candidates confuse Sensitivity labels as a direct replacement for DLP, but labels are for classification and protection (e.g., encryption), not for real-time content inspection and blocking of specific data patterns like credit card numbers in email.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policy
Data Loss Prevention (DLP) policies in Microsoft Purview are specifically designed to detect and prevent the accidental or intentional sharing of sensitive information, such as credit card numbers, through email and other channels. By configuring a DLP policy with a rule that scans for credit card number patterns (using predefined or custom sensitive info types), the system can block, quarantine, or notify users when such data is sent via Exchange Online. This directly addresses the requirement to prevent sharing sensitive data via email.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit log search
Why it's wrong here
Audit log search in Microsoft Purview is inherently a forensic, after-the-fact tool: it records events such as file access, modifications, and sharing into a searchable log, but it has no inline enforcement capability to block or intercept a sharing action before it happens. Even if a policy automatically alerts on certain events, the data has already been exposed, and remediation is manual and reactive. Thus, while it helps with investigation and compliance reporting, it cannot satisfy a requirement to prevent sensitive data from being shared in the first place.
- ✓
Data Loss Prevention (DLP) policy
Why this is correct
Data Loss Prevention (DLP) policies in Microsoft Purview are the correct inline control to block sharing of sensitive information. They use built-in sensitive info types (e.g., credit card numbers, personally identifiable information) and trainable classifiers to evaluate content in real time, then enforce actions such as 'Block' with the option to allow overrides for Exchange, SharePoint, OneDrive, and endpoints. By applying conditions like 'sharing with people outside the organization,' DLP can prevent the sharing action before any data leaves the tenant, making it the only option here that directly provides ex-ante prevention rather than detection or classification.
- ✗
Insider Risk Management policy
Why it's wrong here
Insider Risk Management in Microsoft Purview is a detection and investigation solution that uses behavioral signals—such as unusual file downloads or exfiltration patterns—to identify potentially malicious or accidental insider activity. It generates alerts, supports case management, and runs forensic analysis, but it does not provide an inline policy action to block a sharing event at the moment it occurs. Its purpose is to flag risky user behavior over time, not to enforce access or sharing controls, so it cannot be used as a preventive mechanism for blocking the sharing of sensitive information.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels are classification and protection metadata attached to documents and emails, and they can apply encryption or visual markings, but they do not, by themselves, actively block sharing operations. A label might restrict or remove permissions for certain users, yet a user with existing access can still share a labeled file through a link or attachment unless a separate policy such as DLP enforces a 'Block' action. Therefore, labels are a foundational element for classification and can inform DLP conditions, but they are insufficient as a standalone control to prevent sensitive data from being shared externally.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 208 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.