Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization is adopting Microsoft Copilot for Security. You need to ensure that the AI model does not expose sensitive data during interactions. What is the primary security control you should implement?

⚠ Common exam trap

Candidates often confuse data classification (sensitivity labels) with data loss prevention (DLP), assuming that labeling data is sufficient to prevent exposure, but DLP is the active enforcement mechanism required for real-time AI interactions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Data Loss Prevention policies for Copilot

Microsoft Purview Data Loss Prevention (DLP) policies for Copilot for Security are the primary control to prevent sensitive data exposure because they can inspect and block sensitive information (e.g., credit card numbers, health records) in real-time during Copilot interactions. DLP policies integrate directly with Copilot to enforce data protection rules on both prompts and responses, ensuring that sensitive data is not leaked through the AI model. This is the most direct and effective control for preventing data exposure in AI interactions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Entra Conditional Access policies

    Why it's wrong here

    Conditional Access policies are pre-authentication controls that evaluate sign-on risk, device compliance, and location to determine whether a user can enter Microsoft Copilot for Security. They do not perform any content inspection on Copilot prompts or responses, so once a user is authorized, those policies cannot detect or block sensitive data being exposed in a conversation. Therefore, they govern the front door, not the data flowing out of Copilot.

  • Microsoft Entra Privileged Identity Management

    Why it's wrong here

    Privileged Identity Management (PIM) provides just-in-time, time-bound activation of privileged roles such as Security Administrator or Global Reader, reducing the persistent standing access. However, PIM only manages role elevation and approval workflows; it does not examine the actual queries submitted to Copilot or the content of the generated results. This means PIM can grant a user access to sensitive data sources through elevated roles, but it lacks any mechanism to prevent that data from being included in a Copilot interaction.

  • Microsoft Purview Information Protection sensitivity labels

    Why it's wrong here

    Information Protection sensitivity labels classify and optionally encrypt documents and emails, and can apply visual markings or enforce access restrictions when these artifacts are consumed. Labels do not actively monitor Copilot prompts and responses in real time, so they cannot block a sensitive data point from being revealed in a chat session. While DLP policies can use labels as conditions to enforce protection, the presence of a label alone does not stop Copilot from exposing the underlying sensitive content.

  • Microsoft Purview Data Loss Prevention policies for Copilot

    Why this is correct

    Data Loss Prevention policies for Copilot are specifically designed to detect sensitive information types—such as credit card numbers or personally identifiable information—within Copilot prompts and responses, and can take automatic actions like blocking or warning the user. These policies integrate with the Microsoft Purview console and apply contextual constraints based on the data being processed, making them a content-aware control that mitigates exposure at the point of interaction. Unlike identity or classification-only controls, DLP actively prevents exfiltration by interrupting the prompt/response flow when a violation is matched.

About these practice questions

One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.