Design solutions that align with security best practices and priorities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization is adopting Microsoft Copilot for Security. You need to ensure that the AI model does not expose sensitive data during interactions. What is the primary security control you should implement?
⚠ Common exam trap
Candidates often confuse data classification (sensitivity labels) with data loss prevention (DLP), assuming that labeling data is sufficient to prevent exposure, but DLP is the active enforcement mechanism required for real-time AI interactions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention policies for Copilot
Microsoft Purview Data Loss Prevention (DLP) policies for Copilot for Security are the primary control to prevent sensitive data exposure because they can inspect and block sensitive information (e.g., credit card numbers, health records) in real-time during Copilot interactions. DLP policies integrate directly with Copilot to enforce data protection rules on both prompts and responses, ensuring that sensitive data is not leaked through the AI model. This is the most direct and effective control for preventing data exposure in AI interactions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra Conditional Access policies
Why it's wrong here
Conditional Access policies are pre-authentication controls that evaluate sign-on risk, device compliance, and location to determine whether a user can enter Microsoft Copilot for Security. They do not perform any content inspection on Copilot prompts or responses, so once a user is authorized, those policies cannot detect or block sensitive data being exposed in a conversation. Therefore, they govern the front door, not the data flowing out of Copilot.
- ✗
Microsoft Entra Privileged Identity Management
Why it's wrong here
Privileged Identity Management (PIM) provides just-in-time, time-bound activation of privileged roles such as Security Administrator or Global Reader, reducing the persistent standing access. However, PIM only manages role elevation and approval workflows; it does not examine the actual queries submitted to Copilot or the content of the generated results. This means PIM can grant a user access to sensitive data sources through elevated roles, but it lacks any mechanism to prevent that data from being included in a Copilot interaction.
- ✗
Microsoft Purview Information Protection sensitivity labels
Why it's wrong here
Information Protection sensitivity labels classify and optionally encrypt documents and emails, and can apply visual markings or enforce access restrictions when these artifacts are consumed. Labels do not actively monitor Copilot prompts and responses in real time, so they cannot block a sensitive data point from being revealed in a chat session. While DLP policies can use labels as conditions to enforce protection, the presence of a label alone does not stop Copilot from exposing the underlying sensitive content.
- ✓
Microsoft Purview Data Loss Prevention policies for Copilot
Why this is correct
Data Loss Prevention policies for Copilot are specifically designed to detect sensitive information types—such as credit card numbers or personally identifiable information—within Copilot prompts and responses, and can take automatic actions like blocking or warning the user. These policies integrate with the Microsoft Purview console and apply contextual constraints based on the data being processed, making them a content-aware control that mitigates exposure at the point of interaction. Unlike identity or classification-only controls, DLP actively prevents exfiltration by interrupting the prompt/response flow when a violation is matched.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.