SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company uses Microsoft Purview to classify and protect data. They need to ensure that when a user attempts to share a file containing a credit card number externally, the file is blocked and the user is prompted with a policy tip. Which type of Microsoft Purview policy should they configure?
⚠ Common exam trap
SC-900 often tests the distinction between DLP, sensitivity labels, and retention policies — candidates confuse classification (labels) with enforcement (DLP) and pick the label option when blocking and policy tips are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policy
Data Loss Prevention (DLP) policies in Microsoft Purview are designed to detect sensitive information types such as credit card numbers and take action — blocking sharing, showing policy tips, or restricting access. DLP policies evaluate content in Exchange, SharePoint, OneDrive, Teams, and endpoints, and can trigger user notifications when a policy match occurs. This directly satisfies the requirement to block external sharing and prompt the user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retention policy
Why it's wrong here
A retention policy defines how long specific types of data should be kept or deleted to comply with regulatory requirements or organizational policies. Its primary function is data lifecycle management, ensuring data is retained for the correct period, not to actively scan the content of documents for sensitive information like credit card numbers or to block real-time sharing attempts based on that content. It operates on the age and type of data, not its sensitive content.
- ✗
Insider Risk Management policy
Why it's wrong here
An Insider Risk Management policy is designed to identify, investigate, and act on risky activities within an organization, such as data exfiltration by employees. While it monitors user behavior for potential data misuse, its focus is on detecting patterns of risk and facilitating investigations, rather than providing real-time, content-based blocking of specific sensitive data types during a sharing event. It's a behavioral analytics tool, not a real-time content blocker.
- ✗
Sensitivity label policy
Why it's wrong here
A sensitivity label policy allows organizations to classify data and apply protection settings, such as encryption, watermarks, or access restrictions, based on the data's sensitivity. While labels can be auto-applied and their presence can be a condition for a DLP policy, the label itself is a classification and protection marker. It does not inherently perform the real-time content inspection for credit card numbers or directly block external sharing; those enforcement actions are executed by a Data Loss Prevention (DLP) policy that responds to the label or the content.
- ✓
Data Loss Prevention (DLP) policy
Why this is correct
A Data Loss Prevention (DLP) policy is specifically engineered to identify, monitor, and automatically protect sensitive information across various locations and sharing scenarios. It leverages sensitive information types (SITs) to detect specific content patterns, such as credit card numbers, within documents or emails. Upon detection, a DLP policy can be configured to block external sharing in real-time, notify administrators, and provide policy tips to users, directly addressing the need to prevent sensitive data from leaving the organization.
Go deeper
Related to this question
Learn chapter
Sensitivity Labels and Information Protection
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your company uses Microsoft Purview Information Protection to classify sensitive data. A user reports that when they try to share a document containing a credit card number via email, the email is blocked. Which Purview feature is most likely causing this behavior?
hard- ✓ A.Data Loss Prevention (DLP) policy
- B.Audit log
- C.Sensitivity label
- D.Retention label
Why A: A Data Loss Prevention (DLP) policy in Microsoft Purview is specifically designed to detect and block sensitive data—such as credit card numbers—from being shared via email. When a user attempts to send a document containing a credit card number, the DLP policy scans the email content and attachments, matches the credit card pattern (e.g., using the predefined Sensitive Info Type for credit card numbers), and enforces an action like blocking the message. This is the most likely cause of the email being blocked.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.