Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft 365. You need to create a DLP policy that detects and blocks sharing of credit card numbers in Exchange Online emails. Which TWO components must you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Action to block sharing

Option D is correct because a DLP policy must reference a sensitive information type (SIT) — in this case the built-in 'Credit Card Number' SIT — so Purview can detect the credit card patterns in Exchange Online email content. Option C is correct because detection alone does nothing; the policy rule must define an action such as 'Block' (or restrict access/encrypt) to prevent the credit card data from being shared via email. Option A is incorrect because retention labels govern data lifecycle and retention, not real-time blocking of sensitive data sharing. Option B is incorrect because auto-labeling policies apply sensitivity labels to content and do not enforce DLP blocking actions. Option E is incorrect because trainable classifiers are used for custom content categories (e.g., resumes, contracts), not for detecting standardized numeric patterns like credit card numbers, which are handled by built-in SITs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Retention label for financial data

    Why it's wrong here

    Retention labels are designed for data lifecycle management, not for real-time enforcement in data loss prevention. This label controls how long financial data is retained or when it is deleted, but it cannot block an email containing credit card numbers from leaving the organization. DLP requires a rule with an action, and a retention label alone does not inspect or react to sensitive content.

  • ✗

    Auto-labeling policy

    Why it's wrong here

    Auto-labeling policies apply sensitivity labels to content based on detected conditions, such as sensitive info types, but they do not take action to block or restrict data sharing. While sensitivity labels can be referenced in DLP rules, the auto-labeling policy itself only classifies the item; it does not trigger an inline block notification in Exchange Online. In a DLP policy, you must explicitly configure an action like 'Block' to prevent transmission of credit card data.

  • ✓

    Action to block sharing

    Why this is correct

    A DLP rule is incomplete without an action that defines the enforcement response. For an email containing credit card data, the 'Block' action (often configured as 'Block the message from being sent' or 'Block sharing externally') is the critical component that stops the data exfiltration, fulfilling the DLP policy's purpose. This action ensures that when the sensitive info type condition matches, the mail flow is interrupted and the sender is notified or the message is quarantined.

  • ✓

    Sensitive info type for credit card number

    Why this is correct

    The sensitive info type 'Credit Card Number' is what identifies the data in the email as a credit card, using pattern matching, checksum validation (Luhn algorithm), and formatted regex to provide high confidence detection. Without defining this condition, the DLP policy has nothing to evaluate, and even if an action is configured, it will never trigger because the policy does not know what to look for. This sensitive info type is a predefined rule in Microsoft Purview, so you do not need to train a classifier.

  • ✗

    Trainable classifier for credit card numbers

    Why it's wrong here

    Trainable classifiers are intended for content that lacks a fixed pattern, such as unstructured text or domain-specific categories, and they require sample data and training iterations. Credit card numbers, in contrast, are a well-defined pattern already covered by the built-in 'Credit Card Number' sensitive info type, which uses algorithmic checks like the Luhn mod-10 test. Attempting to use a trainable classifier for credit card numbers would be both unnecessary and technically inappropriate, as it would introduce complexity and potential false positives in a case where a deterministic detector already exists.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.