SC-100 Data Loss Prevention (DLP) Practice Question
Your organization is designing a solution to protect sensitive data in Microsoft 365. You need to implement Microsoft Purview Data Loss Prevention (DLP) policies. Which TWO actions can a DLP policy take when a match occurs? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the sharing of sensitive information.
Option D is correct because Microsoft Purview DLP policies can block sharing of sensitive information across workloads such as Exchange Online, SharePoint, OneDrive, and Teams, preventing users from sending or sharing content that matches a DLP rule. Option E is correct because DLP policies can display policy tips to users in supported apps (for example, Outlook, Word, Excel, and Teams), notifying them that content matches a rule and offering override or report options. Option A is not a native DLP action; encryption with Azure Information Protection is typically achieved through sensitivity labels or auto-labeling policies, not directly as a DLP policy action. Option B is not a standard DLP action in Microsoft Purview; DLP can block, restrict access, or notify, but it does not quarantine files for administrator review. Option C is not a DLP policy action; automatically applying a sensitivity label is performed by auto-labeling policies in Microsoft Purview, not by DLP policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the file with Azure Information Protection.
Why it's wrong here
Encrypting a file is not a DLP action. In Microsoft Purview, encryption is applied through sensitivity labels (e.g., the 'Encrypt' protection action in a label), which can be assigned manually or via auto-labeling policies. DLP policies do not encrypt files; they focus on detecting and restricting sharing or transmission. At most, a DLP policy can use a sensitivity label as a condition, but the DLP action itself cannot apply encryption.
- ✗
Quarantine the file for administrator review.
Why it's wrong here
Quarantining files for administrator review is a feature of email protection (e.g., Exchange Online Protection for malware/phishing) or Microsoft Defender for Endpoint's device investigation, not of Microsoft Purview DLP. DLP policies do not quarantine files or emails; they block or alert on policy violations. While DLP can generate incident reports and allow user override, it never removes or isolates the item — the item remains in place but sharing is blocked.
- ✗
Automatically apply a sensitivity label.
Why it's wrong here
Automatically applying a sensitivity label is performed by auto-labeling policies in Microsoft Purview (or by client-side labeling), not by DLP. DLP uses sensitivity labels as conditions (e.g., 'if label is Confidential, block external sharing') but the DLP action itself cannot change or assign labels. Confusing these two is common; auto-labeling is a separate policy type that evaluates content and applies metadata without a DLP enforcement action.
- ✓
Block the sharing of sensitive information.
Why this is correct
Blocking the sharing of sensitive information is a core DLP enforcement action. In Microsoft Purview, you can configure DLP policies to block sharing via email (e.g., 'Block only people outside your organization'), block uploads to external sites, or block copy/paste to unsanitized apps. This action can be configured with an override option or a policy tip, directly preventing data loss. It is the definitive 'enforce' behavior for DLP scenarios.
- ✓
Show a policy tip to the user.
Why this is correct
Showing a policy tip to the user is a common DLP action that provides real-time user education. Policy tips appear in Outlook, SharePoint, OneDrive, and Office apps, informing the user why the content is restricted and how to comply. They can be configured as a non-blocking notification or as part of a block action with an override request. This is distinct from blocking because it does not enforce the restriction but encourages correct behavior.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.