Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft 365 and wants to implement a data loss prevention (DLP) strategy. You need to ensure that sensitive data is protected both at rest and in transit, and that incidents are automatically reported to the security team. Which THREE actions should you take?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Endpoint DLP for Windows 10/11 devices

Option C is correct because Endpoint DLP extends Microsoft Purview DLP to Windows 10/11 devices, monitoring and restricting sensitive data actions on endpoints (copy to USB, print, upload to cloud) so data at rest on devices and in use is protected. Option D is correct because configuring Microsoft Purview DLP policies for Exchange Online, SharePoint Online, and OneDrive for Business enforces protection for data at rest and in transit across email and cloud storage workloads, detecting sensitive information types and blocking or auditing risky sharing. Option E is correct because configuring DLP incident reports to be sent to the security team via email or Teams ensures automatic alerting and reporting of policy matches, satisfying the requirement that incidents are automatically reported. Option A is not correct because Intune app protection policies manage mobile app permissions and are not the DLP mechanism that detects and protects sensitive data at rest and in transit. Option B is not correct because Conditional Access governs sign-in and access conditions, not DLP content inspection or automatic incident reporting for sensitive data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy Microsoft Intune to control app permissions on mobile devices

    Why it's wrong here

    Intune's app protection policies (MAM) can restrict data transfer between managed apps, but they don't inspect content or generate DLP incident reports. This addresses device app permissions, not the DLP detection and reporting requirement. Intune lacks Purview's DLP policy matching, alerting, and incident management capabilities.

  • ✗

    Implement Conditional Access policies to block external sharing of sensitive data

    Why it's wrong here

    Conditional Access evaluates sign-in risk and session constraints, not data content. It cannot classify sensitive information or prevent a user from sharing a document externally; it only gates access at authentication time. DLP incident reporting is outside its scope.

  • ✓

    Enable Endpoint DLP for Windows 10/11 devices

    Why this is correct

    Endpoint DLP extends Microsoft Purview DLP to devices, inspecting content in documents, emails, and clipboard operations. When a policy match occurs, it blocks the action and raises an alert that appears in the Purview DLP incident report. This directly supports the requirement to protect data in use and report incidents.

  • ✓

    Configure Microsoft Purview DLP policies for Exchange, SharePoint, and OneDrive

    Why this is correct

    Purview DLP for Exchange monitors email messages in transit; SharePoint and OneDrive DLP monitors documents at rest and when shared. Policy matches generate detections that populate the DLP incident report, covering data protection across collaboration workloads. Combining with Endpoint DLP provides full lifecycle coverage.

  • ✓

    Configure DLP incident reports to be sent to the security team via email or Teams

    Why this is correct

    DLP incident reports aggregate policy matches with severity, user, and location details; administrators can subscribe to email digests or Teams notifications. This ensures the security team is alerted without manually checking the Purview portal. It closes the loop on monitoring and response.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.