SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A financial institution uses Microsoft 365 and needs to prevent employees from accidentally sharing sensitive financial data (e.g., account numbers) via email. They also need to inform the sender with a policy tip if they attempt to send such data and block the email if it's shared externally. Which Microsoft Purview solution should they use?
⚠ Common exam trap
It's easy for candidates to confuse Information Protection (sensitivity labels) with DLP, not realizing that sensitivity labels handle classification and encryption of data at rest, while DLP is the solution for monitoring and controlling data in motion (e.g., email) with real-time user notifications and blocking.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, warn, and block the accidental sharing of sensitive data—such as financial account numbers—via email. DLP policies can be configured with conditions that trigger a policy tip to inform the sender and automatically block the email if it is sent externally, meeting both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP)
Why this is correct
Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations like Exchange Online, SharePoint Online, and OneDrive. These policies leverage sensitive information types (SITs) to detect financial data, PII, or other critical data, providing real-time policy tips to users and blocking sharing actions that violate organizational policies. This proactive approach ensures sensitive data, such as customer financial records, is not inadvertently or maliciously exfiltrated, directly addressing the institution's need for prevention.
- ✗
Information Protection (Sensitivity labels)
Why it's wrong here
Information Protection, through sensitivity labels, enables the classification and persistent protection of data, such as applying encryption, visual markings, or access restrictions. While labels can be auto-applied based on content, their primary function is to protect the *data itself* wherever it travels, rather than providing real-time policy tips or blocking *sharing actions* based on content detection at the point of egress. They do not inherently prevent the initial attempt to share sensitive content in violation of a policy.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance focuses on detecting and investigating policy violations within internal and external communications, such as harassment, threats, or regulatory non-compliance like insider trading. It utilizes machine learning and predefined templates to identify risky or inappropriate content for review by compliance officers, but it operates primarily as a post-transmission detection and review tool. It is not designed for real-time blocking of sensitive data egress or providing immediate policy tips to users attempting to share confidential financial information.
- ✗
Records Management
Why it's wrong here
Records Management in Microsoft 365 is dedicated to governing the lifecycle of organizational content, ensuring that information is retained for specific periods to meet legal, regulatory, and business requirements, and then appropriately disposed of. This service focuses on managing content as official records, including applying retention labels, legal holds, and disposition reviews. It does not provide real-time content inspection capabilities to prevent the immediate sharing of sensitive data or offer policy tips to users during email composition.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.