SC-100 Practice Question: Design security solutions for applications and data
Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft 365. You need to create a DLP policy that detects and blocks sharing of credit card numbers in Exchange Online emails. Which TWO components must you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Action to block sharing
Option D is correct because a DLP policy must reference a sensitive information type (SIT) — in this case the built-in 'Credit Card Number' SIT — so Purview can detect the credit card patterns in Exchange Online email content. Option C is correct because detection alone does nothing; the policy rule must define an action such as 'Block' (or restrict access/encrypt) to prevent the credit card data from being shared via email. Option A is incorrect because retention labels govern data lifecycle and retention, not real-time blocking of sensitive data sharing. Option B is incorrect because auto-labeling policies apply sensitivity labels to content and do not enforce DLP blocking actions. Option E is incorrect because trainable classifiers are used for custom content categories (e.g., resumes, contracts), not for detecting standardized numeric patterns like credit card numbers, which are handled by built-in SITs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retention label for financial data
Why it's wrong here
Retention labels are designed for data lifecycle management, not for real-time enforcement in data loss prevention. This label controls how long financial data is retained or when it is deleted, but it cannot block an email containing credit card numbers from leaving the organization. DLP requires a rule with an action, and a retention label alone does not inspect or react to sensitive content.
- ✗
Auto-labeling policy
Why it's wrong here
Auto-labeling policies apply sensitivity labels to content based on detected conditions, such as sensitive info types, but they do not take action to block or restrict data sharing. While sensitivity labels can be referenced in DLP rules, the auto-labeling policy itself only classifies the item; it does not trigger an inline block notification in Exchange Online. In a DLP policy, you must explicitly configure an action like 'Block' to prevent transmission of credit card data.
- ✓
Action to block sharing
Why this is correct
A DLP rule is incomplete without an action that defines the enforcement response. For an email containing credit card data, the 'Block' action (often configured as 'Block the message from being sent' or 'Block sharing externally') is the critical component that stops the data exfiltration, fulfilling the DLP policy's purpose. This action ensures that when the sensitive info type condition matches, the mail flow is interrupted and the sender is notified or the message is quarantined.
- ✓
Sensitive info type for credit card number
Why this is correct
The sensitive info type 'Credit Card Number' is what identifies the data in the email as a credit card, using pattern matching, checksum validation (Luhn algorithm), and formatted regex to provide high confidence detection. Without defining this condition, the DLP policy has nothing to evaluate, and even if an action is configured, it will never trigger because the policy does not know what to look for. This sensitive info type is a predefined rule in Microsoft Purview, so you do not need to train a classifier.
- ✗
Trainable classifier for credit card numbers
Why it's wrong here
Trainable classifiers are intended for content that lacks a fixed pattern, such as unstructured text or domain-specific categories, and they require sample data and training iterations. Credit card numbers, in contrast, are a well-defined pattern already covered by the built-in 'Credit Card Number' sensitive info type, which uses algorithmic checks like the Luhn mod-10 test. Attempting to use a trainable classifier for credit card numbers would be both unnecessary and technically inappropriate, as it would introduce complexity and potential false positives in a case where a deterministic detector already exists.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.