Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company wants to automatically prevent users from sharing files containing personal data (e.g., passport numbers) via email. Which Microsoft Purview solution should they configure?

⚠ Common exam trap

Candidates often confuse Communication Compliance with DLP because both involve monitoring communications, but Communication Compliance is for auditing and review, not for automatic blocking of sensitive data in transit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Loss Prevention (DLP)

Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and automatically block the sharing of sensitive information, such as passport numbers, via email. DLP policies use deep content analysis (e.g., regular expressions, keyword matching, and data classification) to inspect email attachments and body text in transit, and can enforce actions like blocking the message or sending a policy tip to the user. This aligns directly with the requirement to prevent users from sharing files containing personal data through email.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance focuses on detecting and investigating inappropriate messages, harassment, or sensitive information sharing within an organization's communication channels like Microsoft Teams and Exchange. While it identifies policy violations and alerts administrators for review, its primary function is auditing and insider risk management. It does not provide real-time, automatic prevention capabilities to block a user from initiating a sharing action.

  • Data Loss Prevention (DLP)

    Why this is correct

    Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations, including cloud services, endpoints, and on-premises. DLP can detect specific sensitive data types, such as credit card numbers or personally identifiable information (PII), and enforce rules to prevent sharing, copying, or transferring this data outside defined organizational boundaries. It directly fulfills the requirement to automatically block sharing actions based on content.

  • Sensitivity labels

    Why it's wrong here

    Sensitivity labels provide a persistent classification and protection mechanism for data, allowing organizations to apply encryption, visual markings, and access restrictions to documents and emails. While labels can enforce protection *after* content is labeled and can restrict who can access or share labeled content, they do not inherently or automatically prevent a user from attempting to share content in the first place, especially if the content is not yet labeled. Their primary role is data governance and post-sharing protection, not pre-sharing prevention.

  • eDiscovery

    Why it's wrong here

    eDiscovery tools, such as those within Microsoft Purview, are primarily used for identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI) for legal, regulatory, or internal investigations. Its function is entirely reactive, focusing on data retrieval and management to support litigation or compliance audits. eDiscovery has no capabilities to actively monitor user actions or automatically prevent data sharing in real-time, as its purpose is post-event data collection.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.