Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A security architect is designing a data protection strategy for a Microsoft 365 tenant. The company must prevent users from sharing sensitive documents with external users via SharePoint Online. They want to apply a policy that automatically detects sensitive content and blocks external sharing. Which Microsoft Purview solution should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention (DLP) policy

Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive data and block external sharing. Option C is correct. Option A is wrong because sensitivity labels require manual application or automatic classification, but blocking external sharing is typically done by DLP. Option B is wrong because retention policies are for data retention, not blocking sharing. Option D is wrong because Microsoft Purview Information Protection is the umbrella, but the specific policy is DLP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Sensitivity labels

    Why it's wrong here

    Sensitivity labels are metadata tags that classify data and can apply encryption or rights management, but they are not a runtime enforcement mechanism for blocking sharing actions. While labels can mark content as confidential, they do not natively intercept an attempt to share externally; that detection-and-block behavior requires a DLP policy with a rule targeting external sharing activities.

  • ✗

    Retention policies

    Why it's wrong here

    Retention policies focus on governing content lifecycle by preserving data for a specified period or initiating deletion at the end of that period. They have no capability to inspect data in transit or block an external sharing event in real time, so they are completely orthogonal to the requirement of preventing sensitive information from leaving the organization.

  • ✓

    Data Loss Prevention (DLP) policy

    Why this is correct

    Data Loss Prevention (DLP) policies are purpose-built to detect sensitive information (e.g., credit card numbers, PII) using sensitive info types and then take protective actions including blocking external sharing. In Microsoft Purview, a DLP policy can be scoped to SharePoint/OneDrive and configured with a rule that blocks sharing outside your organization while allowing users to override with justification, making it the correct control for this scenario.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection is the umbrella product suite that encompasses sensitivity labels, DLP, and encryption, not a single implementable feature. Selecting this option is similar to choosing 'Microsoft 365' as a solution—it names the platform rather than the specific policy object (DLP policy) that actually enforces the block on external sharing.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.