Courseiva

SC-100 Practice Question: Microsoft Purview Data Loss Prevention (DLP)…

Your organization is deploying Microsoft Copilot for Security and wants to ensure that the AI model does not expose sensitive data in its responses. You need to configure data loss prevention (DLP) policies that apply to Copilot interactions. Which Microsoft Purview capability should you use?

⚠ Common exam trap

The trap is that candidates may confuse Communication Compliance as the DLP solution for Copilot, but Microsoft has specifically extended DLP policies to cover Copilot interactions, making standard DLP policies the correct choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data Loss Prevention policies

Microsoft Purview Data Loss Prevention (DLP) policies for Copilot are designed to prevent sensitive data from being exposed in AI interactions. These policies can scan prompts and responses for sensitive information and take actions like blocking or alerting. Communication Compliance (Option D) is intended for monitoring communications, such as emails and Teams messages, but not specifically for DLP in AI interactions. Therefore, DLP policies are the correct capability for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    eDiscovery

    Why it's wrong here

    eDiscovery identifies and collects content for legal and investigative cases, so it cannot enforce preventive controls over Copilot prompts and responses. It is tempting because it surfaces sensitive content across workloads, but DLP requires Microsoft Purview Data Loss Prevention policies scoped to Copilot interactions to block or audit exposure.

  • ✓

    Data Loss Prevention policies

    Why this is correct

    DLP policies in Microsoft Purview inspect prompts and responses during Copilot interactions, detecting sensitive information types and blocking or auditing exposure. This directly satisfies the requirement to prevent sensitive data appearing in AI-generated responses, since the policy evaluates content at the interaction layer rather than relying on model training.

  • ✗

    Information Protection and sensitivity labels

    Why it's wrong here

    Sensitivity labels classify and protect content at rest and in transit, but they do not evaluate Copilot prompts and responses against DLP rules to prevent sensitive data exposure. It is tempting because labels underpin protection, yet the required capability is Microsoft Purview Data Loss Prevention with policies scoped to Copilot interactions.

  • ✗

    Communication Compliance

    Why it's wrong here

    Communication Compliance detects and reviews potentially inappropriate messages after they are sent, so it cannot block sensitive data leaving Copilot responses in real time. It is tempting for monitoring policy violations, yet DLP policies scoped to Copilot interactions are configured through Microsoft Purview Data Loss Prevention, which inspects and restricts prompts and responses.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.