SC-200 Manage a security operations environment Practice Question
Your organization uses Microsoft Purview Data Loss Prevention (DLP). You need to receive an alert when a user attempts to share a credit card number via email. What should you configure?
⚠ Common exam trap
Watch out — candidates often confuse sensitivity labels or retention labels with DLP policies, not realizing that only DLP policies can directly detect and alert on sensitive data in transit like email sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a DLP policy in Microsoft Purview with the credit card number sensitive info type.
Microsoft Purview DLP policies can be configured to detect sensitive information types, such as credit card numbers, and trigger alerts when users attempt to share that data via email. By creating a DLP policy with the credit card number sensitive info type and setting an action to send an alert, you meet the requirement to receive an alert on such sharing attempts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a sensitivity label that blocks sharing.
Why it's wrong here
A sensitivity label with a sharing-blocking configuration enforces protective actions such as encryption or user-defined permissions, but it does not perform active content scanning or generate alerting when credit card data is shared. Labels are classification and protection tools, not detection controls, so they cannot satisfy the requirement to be alerted on the specific data loss event.
- ✓
Create a DLP policy in Microsoft Purview with the credit card number sensitive info type.
Why this is correct
A DLP policy in Microsoft Purview is the correct control because it can be configured with the Credit Card Number sensitive info type, which uses pattern matching and checksum validation to detect this data in Exchange Online mail. The policy can specify an action to send an alert to the security team whenever the data is detected, meeting the alerting requirement precisely.
- ✗
Create a retention label that identifies credit card data.
Why it's wrong here
Retention labels govern data lifecycle by applying rules for how long content is retained and whether it is deleted, but they do not scan for or detect credit card numbers and cannot raise security alerts on data loss. They are designed for records management and compliance purposes, not for real-time monitoring or notification of sensitive information sharing.
- ✗
Create a file policy in Microsoft Defender for Cloud Apps.
Why it's wrong here
A file policy in Microsoft Defender for Cloud Apps is used to monitor and enforce policies on files stored in or shared through third-party cloud apps such as Box or Dropbox, not on email messages exchanged in your organization. Without an appropriate app connector and with no native email workload support, this option fails to address the stated email-based data loss scenario and cannot produce the required alerts.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.