SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft 365 and wants to implement a data loss prevention (DLP) strategy. You need to ensure that sensitive data is protected both at rest and in transit, and that incidents are automatically reported to the security team. Which THREE actions should you take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Endpoint DLP for Windows 10/11 devices
Option C is correct because Endpoint DLP extends Microsoft Purview DLP to Windows 10/11 devices, monitoring and restricting sensitive data actions on endpoints (copy to USB, print, upload to cloud) so data at rest on devices and in use is protected. Option D is correct because configuring Microsoft Purview DLP policies for Exchange Online, SharePoint Online, and OneDrive for Business enforces protection for data at rest and in transit across email and cloud storage workloads, detecting sensitive information types and blocking or auditing risky sharing. Option E is correct because configuring DLP incident reports to be sent to the security team via email or Teams ensures automatic alerting and reporting of policy matches, satisfying the requirement that incidents are automatically reported. Option A is not correct because Intune app protection policies manage mobile app permissions and are not the DLP mechanism that detects and protects sensitive data at rest and in transit. Option B is not correct because Conditional Access governs sign-in and access conditions, not DLP content inspection or automatic incident reporting for sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy Microsoft Intune to control app permissions on mobile devices
Why it's wrong here
Intune's app protection policies (MAM) can restrict data transfer between managed apps, but they don't inspect content or generate DLP incident reports. This addresses device app permissions, not the DLP detection and reporting requirement. Intune lacks Purview's DLP policy matching, alerting, and incident management capabilities.
- ✗
Implement Conditional Access policies to block external sharing of sensitive data
Why it's wrong here
Conditional Access evaluates sign-in risk and session constraints, not data content. It cannot classify sensitive information or prevent a user from sharing a document externally; it only gates access at authentication time. DLP incident reporting is outside its scope.
- ✓
Enable Endpoint DLP for Windows 10/11 devices
Why this is correct
Endpoint DLP extends Microsoft Purview DLP to devices, inspecting content in documents, emails, and clipboard operations. When a policy match occurs, it blocks the action and raises an alert that appears in the Purview DLP incident report. This directly supports the requirement to protect data in use and report incidents.
- ✓
Configure Microsoft Purview DLP policies for Exchange, SharePoint, and OneDrive
Why this is correct
Purview DLP for Exchange monitors email messages in transit; SharePoint and OneDrive DLP monitors documents at rest and when shared. Policy matches generate detections that populate the DLP incident report, covering data protection across collaboration workloads. Combining with Endpoint DLP provides full lifecycle coverage.
- ✓
Configure DLP incident reports to be sent to the security team via email or Teams
Why this is correct
DLP incident reports aggregate policy matches with severity, user, and location details; administrators can subscribe to email digests or Teams notifications. This ensures the security team is alerted without manually checking the Purview portal. It closes the loop on monitoring and response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.