SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization is implementing Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. You need to design a policy that prevents users from sharing credit card numbers via email. Which THREE components are required to build this DLP policy?
⚠ Common exam trap
Watch out — candidates often confuse optional enhancements (like policy tips or trainable classifiers) with mandatory components, but the core requirement is a rule with a sensitive info type, a scope (Exchange Online), and an action to block and notify.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A rule that includes a sensitive info type for credit card numbers
Option B is correct because a DLP rule must reference a sensitive information type (SIT), such as the built-in Credit Card Number SIT, to detect the credit card data the policy is meant to protect. Option D is correct because the policy must be scoped to the Exchange Online workload so that email traffic is actually evaluated by the DLP engine. Option E is correct because a rule needs an action, such as blocking the email and notifying the sender or admin, to enforce protection once credit card numbers are detected. Option A is not required because a policy tip is an optional user-notification enhancement, not a mandatory component for the policy to function. Option C is not required because trainable classifiers are used for content that is hard to identify with patterns, whereas credit card numbers are detected by a built-in sensitive information type.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A policy tip to warn users before sending
Why it's wrong here
A policy tip is a user-facing notification that appears in Outlook or Outlook on the web when a message might violate a DLP rule. While policy tips are useful for educating users and encouraging them to self-correct, they do not, by themselves, stop the email from being sent. Unless the rule also includes an action like "Block the message" (possibly with an overridable justification), a user can ignore the tip and the email will still be delivered, so this alone does not meet a blocking requirement.
- ✓
A rule that includes a sensitive info type for credit card numbers
Why this is correct
The rule must include a condition that matches the data you want to protect; for credit card numbers, Microsoft Purview DLP provides a built-in sensitive information type (SIT) called "Credit Card Number" that detects 15-16 digit card numbers and uses Luhn checksum validation to reduce false positives. Without this SIT as a condition, the policy has no trigger and will never be evaluated against outgoing mail. This SIT is part of the default DLP rule conditions and is the correct, deterministic way to identify credit card data versus using experimental AI classifiers.
- ✗
A trainable classifier for financial data
Why it's wrong here
A trainable classifier is a machine-learning-based model that you train on your organization's own content to identify unstructured documents like contracts, proposals, or employee letters. For credit card numbers, a structured, pattern-based sensitive info type is far more accurate and requires no training or seed documents. Trainable classifiers also need a sample set and training time, and they can yield inconsistent results; thus, using one here is an unnecessary and less reliable approach compared to the built-in "Credit Card Number" SIT.
- ✓
A policy scope that includes Exchange Online
Why this is correct
A DLP policy's scope determines which workload locations will be inspected; to protect email, you must explicitly include the Exchange Online location in the policy scope. Without this location selected, the policy applies only to other included workloads such as SharePoint Online, OneDrive for Business, or Teams—not to email messages in transit. When Exchange Online is included, the DLP rules are enforced by Exchange transport rules, and you can further narrow scope to specific distribution groups, users, or exclude certain recipients to tune enforcement.
- ✓
An action to block the email and send a notification
Why this is correct
The action defined in the rule is what actually enforces the block; for Exchange Online, setting the action to "Block the message" prevents delivery of the email and can optionally append a notification or redirect it to the sender's manager for approval. Simply detecting the data is insufficient; without a block action, a rule that only notifies or sends a policy tip allows the data to leave the organization. Including a notification alongside the block reinforces security awareness while ensuring the sensitive content never reaches the recipient.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.