SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your company uses Microsoft Purview Data Loss Prevention (DLP). You need to ensure that credit card numbers are not shared externally via email. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a DLP policy that detects credit card numbers and blocks external sharing.
The correct option is B: create a DLP policy that detects credit card numbers and blocks external sharing. Microsoft Purview DLP is purpose-built to identify sensitive information types such as credit card numbers and enforce protective actions like blocking email to external recipients, which directly satisfies the requirement. Option A is wrong because sensitivity labels apply encryption and classification but do not themselves block external email sharing based on content detection. Option C is wrong because auto-labeling applies labels rather than enforcing DLP blocking actions. Option D is wrong because retention policies govern data lifecycle and deletion, not prevention of external sharing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a sensitivity label that applies encryption to emails containing credit card numbers.
Why it's wrong here
Sensitivity labels apply classification and protection settings such as encryption, but the label itself does not contain a native 'block external sharing' action that actively intercepts outgoing messages or links. Even if the email is encrypted, a user could still attach credit card data to a message and send it to an external recipient; the recipient would simply be required to authenticate or receive limited rights. Blocking external sharing requires a DLP policy with an explicit detection rule and enforcement action, not just a label's encryption setting.
- ✓
Create a DLP policy that detects credit card numbers and blocks external sharing.
Why this is correct
A DLP policy is the correct control because it combines detection of a sensitive info type (credit card number uses patterns plus Luhn checksum validation) with a condition that the content is shared externally, and then enforces a blocking action. When you create a DLP policy in the Microsoft Purview compliance portal, you select the credit card number detector, scope it to Exchange/SharePoint/OneDrive, and set the rule to block access or block sending before the content leaves your tenant. This is the only option that directly prevents unauthorized external sharing while also providing user overrides and incident alerts.
- ✗
Configure auto-labeling for credit card numbers in Microsoft 365.
Why it's wrong here
Auto-labeling in Microsoft 365 can automatically apply a sensitivity label to documents and emails that contain credit card numbers, which is useful for classification and downstream protections, but auto-labeling is a labeling mechanism, not an enforcement mechanism. Once the label is applied, it does not by itself block the user from sharing externally; at most, the label may require a manual action or apply encryption, but those are not the same as the proactive block that DLP provides. To actually block external sharing, you still need a DLP policy because auto-labeling cannot simultaneously stop the sharing event.
- ✗
Create a retention policy for credit card data.
Why it's wrong here
Retention policies in Microsoft Purview govern how long content is retained or when it is permanently deleted, based on rules for organizational compliance or legal obligations. They do not inspect message content for sensitive data and do not prevent a user from sharing data with external parties; retention simply keeps a copy or deletes it after a period. A retention policy for credit card data will not block external sharing, so it is irrelevant to the requirement of controlling data exfiltration.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.