SC-100 Practice Question: Design security solutions for applications and data
A security architect is designing a data protection strategy for a Microsoft 365 tenant. The company must prevent users from sharing sensitive documents with external users via SharePoint Online. They want to apply a policy that automatically detects sensitive content and blocks external sharing. Which Microsoft Purview solution should they use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policy
Microsoft Purview Data Loss Prevention (DLP) policies can detect sensitive data and block external sharing. Option C is correct. Option A is wrong because sensitivity labels require manual application or automatic classification, but blocking external sharing is typically done by DLP. Option B is wrong because retention policies are for data retention, not blocking sharing. Option D is wrong because Microsoft Purview Information Protection is the umbrella, but the specific policy is DLP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels are metadata tags that classify data and can apply encryption or rights management, but they are not a runtime enforcement mechanism for blocking sharing actions. While labels can mark content as confidential, they do not natively intercept an attempt to share externally; that detection-and-block behavior requires a DLP policy with a rule targeting external sharing activities.
- ✗
Retention policies
Why it's wrong here
Retention policies focus on governing content lifecycle by preserving data for a specified period or initiating deletion at the end of that period. They have no capability to inspect data in transit or block an external sharing event in real time, so they are completely orthogonal to the requirement of preventing sensitive information from leaving the organization.
- ✓
Data Loss Prevention (DLP) policy
Why this is correct
Data Loss Prevention (DLP) policies are purpose-built to detect sensitive information (e.g., credit card numbers, PII) using sensitive info types and then take protective actions including blocking external sharing. In Microsoft Purview, a DLP policy can be scoped to SharePoint/OneDrive and configured with a rule that blocks sharing outside your organization while allowing users to override with justification, making it the correct control for this scenario.
- ✗
Microsoft Purview Information Protection
Why it's wrong here
Microsoft Purview Information Protection is the umbrella product suite that encompasses sensitivity labels, DLP, and encryption, not a single implementable feature. Selecting this option is similar to choosing 'Microsoft 365' as a solution—it names the platform rather than the specific policy object (DLP policy) that actually enforces the block on external sharing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.