How to Configure Microsoft Purview DLP to Block Credit Card Numbers in Email
A company plans to implement Microsoft Purview to enforce data loss prevention (DLP) policies. They need to prevent users from sharing credit card numbers via email. What should they configure?
Quick Answer
The correct answer is to create a DLP policy that detects and blocks credit card numbers in Exchange Online. This works because Microsoft Purview includes built-in sensitive information types, such as the credit card number entity, which uses pattern matching and checksum validation to identify the data. When you configure a DLP rule with an action to block the email—either by rejecting the message or sending it to quarantine—you directly prevent the sharing of credit card numbers via email, enforcing compliance at the transport layer. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how Purview DLP policies integrate with Exchange Online mail flow, often appearing as a straightforward configuration task where the trap is choosing a broader endpoint DLP rule or an incorrect sensitive info type. Remember the key: for email-specific blocking, the action must be applied to Exchange, not Teams or SharePoint. A useful memory tip is “CC Block: Check Content, Block Exchange.”
⚠ Common exam trap
It's easy for candidates to confuse sensitivity labels (which classify data) with DLP policies (which enforce actions on data in motion), leading them to select Option A instead of the correct DLP policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a DLP policy that detects and blocks credit card numbers in Exchange Online
Microsoft Purview Data Loss Prevention (DLP) policies can be configured to detect sensitive data types, such as credit card numbers, in Exchange Online emails. When a DLP policy is created with a rule that identifies credit card numbers and blocks the email from being sent, it directly prevents users from sharing that data via email. This is the native mechanism for enforcing DLP on email traffic in Microsoft 365.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a sensitivity label and apply it to emails
Why it's wrong here
Sensitivity labels classify and protect content through encryption and markings, but they do not automatically inspect email bodies for credit card patterns and block sending. Labels are the correct choice when data must be classified and protected at rest and in transit.
- ✗
Enable communication compliance policies
Why it's wrong here
Communication compliance policies detect inappropriate or risky communications for review by investigators; they flag and surface content rather than prevent it being sent. They suit insider-risk and code-of-conduct monitoring, not real-time blocking of card numbers in email.
- ✓
Create a DLP policy that detects and blocks credit card numbers in Exchange Online
Why this is correct
A DLP policy scoped to Exchange Online inspects email traffic and applies sensitive information type matching for credit card numbers, blocking sharing at the transport layer. This directly satisfies the stem's requirement to prevent email exfiltration, since Exchange Online is the workload governing mail flow within Microsoft Purview.
- ✗
Configure a retention policy for email
Why it's wrong here
Retention policies govern how long email is kept and when it is deleted; they neither inspect message content nor block transmission. They are the right control for regulatory record-keeping obligations, not for stopping credit card numbers leaving the organisation.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company uses Microsoft Purview Data Loss Prevention (DLP). You need to ensure that credit card numbers are not shared externally via email. What should you configure?
easy- A.Create a sensitivity label that applies encryption to emails containing credit card numbers.
- ✓ B.Create a DLP policy that detects credit card numbers and blocks external sharing.
- C.Configure auto-labeling for credit card numbers in Microsoft 365.
- D.Create a retention policy for credit card data.
Why B: The correct option is B: create a DLP policy that detects credit card numbers and blocks external sharing. Microsoft Purview DLP is purpose-built to identify sensitive information types such as credit card numbers and enforce protective actions like blocking email to external recipients, which directly satisfies the requirement. Option A is wrong because sensitivity labels apply encryption and classification but do not themselves block external email sharing based on content detection. Option C is wrong because auto-labeling applies labels rather than enforcing DLP blocking actions. Option D is wrong because retention policies govern data lifecycle and deletion, not prevention of external sharing.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.