Courseiva

How to Configure Microsoft Purview DLP to Block Credit Card Numbers in Email

A company plans to implement Microsoft Purview to enforce data loss prevention (DLP) policies. They need to prevent users from sharing credit card numbers via email. What should they configure?

Quick Answer

The correct answer is to create a DLP policy that detects and blocks credit card numbers in Exchange Online. This works because Microsoft Purview includes built-in sensitive information types, such as the credit card number entity, which uses pattern matching and checksum validation to identify the data. When you configure a DLP rule with an action to block the email—either by rejecting the message or sending it to quarantine—you directly prevent the sharing of credit card numbers via email, enforcing compliance at the transport layer. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how Purview DLP policies integrate with Exchange Online mail flow, often appearing as a straightforward configuration task where the trap is choosing a broader endpoint DLP rule or an incorrect sensitive info type. Remember the key: for email-specific blocking, the action must be applied to Exchange, not Teams or SharePoint. A useful memory tip is “CC Block: Check Content, Block Exchange.”

⚠ Common exam trap

It's easy for candidates to confuse sensitivity labels (which classify data) with DLP policies (which enforce actions on data in motion), leading them to select Option A instead of the correct DLP policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a DLP policy that detects and blocks credit card numbers in Exchange Online

Microsoft Purview Data Loss Prevention (DLP) policies can be configured to detect sensitive data types, such as credit card numbers, in Exchange Online emails. When a DLP policy is created with a rule that identifies credit card numbers and blocks the email from being sent, it directly prevents users from sharing that data via email. This is the native mechanism for enforcing DLP on email traffic in Microsoft 365.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a sensitivity label and apply it to emails

    Why it's wrong here

    Sensitivity labels classify data but do not enforce blocking actions in email.

  • Enable communication compliance policies

    Why it's wrong here

    Communication compliance is for monitoring communications for policy violations, not for blocking DLP.

  • Create a DLP policy that detects and blocks credit card numbers in Exchange Online

    Why this is correct

    DLP policies in Microsoft Purview can detect sensitive info types like credit card numbers and block sharing via email.

  • Configure a retention policy for email

    Why it's wrong here

    Retention policies preserve or delete data, not block sharing of sensitive info.

About these practice questions

This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-100

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Your company uses Microsoft Purview Data Loss Prevention (DLP). You need to ensure that credit card numbers are not shared externally via email. What should you configure?

easy
  • A.Create a sensitivity label that applies encryption to emails containing credit card numbers.
  • B.Create a DLP policy that detects credit card numbers and blocks external sharing.
  • C.Configure auto-labeling for credit card numbers in Microsoft 365.
  • D.Create a retention policy for credit card data.

Why B: DLP policies are designed to detect sensitive information, such as credit card numbers, and enforce actions like blocking external sharing. Option A is incorrect because sensitivity labels primarily classify and protect content (e.g., encryption) but do not directly block sharing; DLP policies handle that. Option C is incorrect because auto-labeling applies labels automatically but does not enforce blocking; DLP policies are needed for enforcement. Option D is incorrect because retention policies manage data retention periods, not sharing restrictions.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.