SC-100 Practice Question: Design security solutions for applications and data
Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft Teams. You need to prevent users from sharing credit card numbers in Teams chat messages. However, the policy should allow sharing with external vendors if they are in your organization's approved list. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a DLP policy with a condition to block sharing of credit card numbers to external users except those from approved domains.
You can configure a DLP policy in Microsoft Purview to block sensitive data like credit card numbers in Teams messages, and use the 'Block sharing to external users except' condition to allow sharing with approved domains. This meets the requirement to prevent sharing with unauthorized external users while allowing sharing with approved vendors. Option B is wrong because blocking all external sharing is too restrictive and does not allow the approved external vendors. Option C is wrong because Information Protection labels do not have the granular control over sharing conditions based on external domains. Option D is wrong because sensitivity labels are not designed for DLP actions such as blocking sharing in Teams chat based on external approval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a DLP policy with a condition to block sharing of credit card numbers to external users except those from approved domains.
Why this is correct
A DLP policy lets you combine the sensitive info type condition (credit card numbers) with 'External sharing' and then use the action 'Restrict access to external users' to specify an allowed domain list via the 'Only people in domains on your approved list' option. This grants exceptions to approved external vendors while any other external recipient is blocked, exactly matching the requirement.
- ✗
Create a DLP policy that blocks credit card numbers and set the action to 'Block external sharing' for all external users.
Why it's wrong here
Choosing the simple 'Block external sharing' action in a DLP policy is a blunt instrument: once a credit card number is detected and shared externally, the entire message is blocked for every external recipient, including the approved vendors. This action has no built-in list of exempted domains, so while it prevents leaks to unapproved parties, it also halts legitimate business traffic.
- ✗
Use Microsoft Purview Information Protection to automatically apply a 'Confidential' label to messages containing credit card numbers and block forwarding.
Why it's wrong here
Auto-applying a 'Confidential' label with 'Do Not Forward' via Microsoft Purview Information Protection does encrypt and restrict the message, but the label condition and its protection are not recipient-aware. Any condition that would need to compare the recipient's domain against an approved vendor list cannot be expressed in a sensitivity label, so a 'Do Not Forward' action would block forwarding to approved vendors as well, making it over-restrictive.
- ✗
Create a sensitivity label for credit card data and publish it to Teams, then configure auto-labeling.
Why it's wrong here
Publishing a sensitivity label to Teams marks the team container as 'Confidential' and can restrict guest access, but it never inspects or classifies the actual credit card numbers inside messages or files. Auto-labeling policies in Purview can scan content, but they cannot condition actions based on the external recipient's domain, so they cannot implement an exception for approved external parties.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.