Courseiva

SC-200 Manage a security operations environment Practice Question

Your organization uses Microsoft Purview Data Loss Prevention (DLP). You need to receive an alert when a user attempts to share a credit card number via email. What should you configure?

⚠ Common exam trap

Watch out — candidates often confuse sensitivity labels or retention labels with DLP policies, not realizing that only DLP policies can directly detect and alert on sensitive data in transit like email sharing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a DLP policy in Microsoft Purview with the credit card number sensitive info type.

Microsoft Purview DLP policies can be configured to detect sensitive information types, such as credit card numbers, and trigger alerts when users attempt to share that data via email. By creating a DLP policy with the credit card number sensitive info type and setting an action to send an alert, you meet the requirement to receive an alert on such sharing attempts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a sensitivity label that blocks sharing.

    Why it's wrong here

    A sensitivity label with a sharing-blocking configuration enforces protective actions such as encryption or user-defined permissions, but it does not perform active content scanning or generate alerting when credit card data is shared. Labels are classification and protection tools, not detection controls, so they cannot satisfy the requirement to be alerted on the specific data loss event.

  • ✓

    Create a DLP policy in Microsoft Purview with the credit card number sensitive info type.

    Why this is correct

    A DLP policy in Microsoft Purview is the correct control because it can be configured with the Credit Card Number sensitive info type, which uses pattern matching and checksum validation to detect this data in Exchange Online mail. The policy can specify an action to send an alert to the security team whenever the data is detected, meeting the alerting requirement precisely.

  • ✗

    Create a retention label that identifies credit card data.

    Why it's wrong here

    Retention labels govern data lifecycle by applying rules for how long content is retained and whether it is deleted, but they do not scan for or detect credit card numbers and cannot raise security alerts on data loss. They are designed for records management and compliance purposes, not for real-time monitoring or notification of sensitive information sharing.

  • ✗

    Create a file policy in Microsoft Defender for Cloud Apps.

    Why it's wrong here

    A file policy in Microsoft Defender for Cloud Apps is used to monitor and enforce policies on files stored in or shared through third-party cloud apps such as Box or Dropbox, not on email messages exchanged in your organization. Without an appropriate app connector and with no native email workload support, this option fails to address the stated email-based data loss scenario and cannot produce the required alerts.

About these practice questions

One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.