SC-100 Practice Question: Microsoft Purview Data Loss Prevention (DLP)…
Your organization is deploying Microsoft Copilot for Security and wants to ensure that the AI model does not expose sensitive data in its responses. You need to configure data loss prevention (DLP) policies that apply to Copilot interactions. Which Microsoft Purview capability should you use?
⚠ Common exam trap
The trap is that candidates may confuse Communication Compliance as the DLP solution for Copilot, but Microsoft has specifically extended DLP policies to cover Copilot interactions, making standard DLP policies the correct choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention policies
Microsoft Purview Data Loss Prevention (DLP) policies for Copilot are designed to prevent sensitive data from being exposed in AI interactions. These policies can scan prompts and responses for sensitive information and take actions like blocking or alerting. Communication Compliance (Option D) is intended for monitoring communications, such as emails and Teams messages, but not specifically for DLP in AI interactions. Therefore, DLP policies are the correct capability for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
eDiscovery
Why it's wrong here
eDiscovery identifies and collects content for legal and investigative cases, so it cannot enforce preventive controls over Copilot prompts and responses. It is tempting because it surfaces sensitive content across workloads, but DLP requires Microsoft Purview Data Loss Prevention policies scoped to Copilot interactions to block or audit exposure.
- ✓
Data Loss Prevention policies
Why this is correct
DLP policies in Microsoft Purview inspect prompts and responses during Copilot interactions, detecting sensitive information types and blocking or auditing exposure. This directly satisfies the requirement to prevent sensitive data appearing in AI-generated responses, since the policy evaluates content at the interaction layer rather than relying on model training.
- ✗
Information Protection and sensitivity labels
Why it's wrong here
Sensitivity labels classify and protect content at rest and in transit, but they do not evaluate Copilot prompts and responses against DLP rules to prevent sensitive data exposure. It is tempting because labels underpin protection, yet the required capability is Microsoft Purview Data Loss Prevention with policies scoped to Copilot interactions.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance detects and reviews potentially inappropriate messages after they are sent, so it cannot block sensitive data leaving Copilot responses in real time. It is tempting for monitoring policy violations, yet DLP policies scoped to Copilot interactions are configured through Microsoft Purview Data Loss Prevention, which inspects and restricts prompts and responses.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.