Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They want to prevent users from sharing credit card numbers in email but allow sharing via encrypted email. What should they configure?

⚠ Common exam trap

Many exam-takers confuse DLP's conditional encryption check with Message Encryption policies or mail flow rules, failing to recognize that DLP provides the specific 'unless the email is encrypted' condition and user override capability needed for this requirement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure a DLP rule that blocks sharing unless the email is encrypted, with user override

Microsoft Purview DLP can enforce a policy that blocks sharing of credit card numbers unless the email is encrypted, with a user override option to allow legitimate encrypted sharing. This directly meets the requirement to prevent unencrypted sharing while permitting encrypted email transmission, leveraging DLP's ability to inspect email content and conditionally apply actions based on encryption status.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign a sensitivity label that encrypts the email automatically

    Why it's wrong here

    Assigning a sensitivity label that automatically encrypts an email is a classification and protection action, not a policy enforcing blocking. In Microsoft Purview, sensitivity labels apply encryption and visual markings based on configured conditions, but they do not evaluate the message at the point of sharing to block unencrypted credit card data. A DLP rule is still required to inspect the content and take an enforcement action such as blocking or approving exceptions, making this option incomplete.

  • Create a Microsoft Purview Message Encryption policy

    Why it's wrong here

    A Microsoft Purview Message Encryption (OME) policy is designed to apply encryption to outgoing email using a mail flow rule, not to inspect content for sensitive data like credit card numbers. Even if such a policy is created, it will not block unencrypted sharing because OME policies only define how encryption is applied or enforced—they do not include data-loss-prevention triggers or conditional blocks based on sensitive info types. Only a DLP rule can detect the credit-card pattern and block non-encrypted messages, so this option does not meet the requirement.

  • Configure a DLP rule that blocks sharing unless the email is encrypted, with user override

    Why this is correct

    To enforce that unencrypted emails containing credit card data are blocked, you need a Microsoft Purview DLP rule. The rule can include the condition "Content contains" the sensitive info type for credit card numbers, and an action to "Block" the message if it is not encrypted, with an option to allow users to override the block for legitimate business needs. DLP integrates with Exchange Online to inspect the message in transit and conditionally allow encrypted messages as an exception, directly addressing the stated requirement, whereas proactive encryption strategies alone cannot guarantee compliance.

  • Use Exchange mail flow rules to block unencrypted credit card data

    Why it's wrong here

    Exchange mail flow rules (transport rules) can be built with regex patterns to match credit card numbers and force encryption or block delivery, but they are far less integrated than Purview DLP. Mail flow rules lack out-of-the-box sensitive information types, Policy Tips, user override workflows, and unified DLP reporting across Exchange, SharePoint, OneDrive, Teams, and endpoints. Moreover, they cannot leverage the same advanced classification and content inspection engine as DLP, making this a less accurate and more complex manual approach that still leaves coverage gaps.

About these practice questions

One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.