Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A financial institution uses Microsoft 365 and needs to prevent employees from accidentally sharing sensitive financial data (e.g., account numbers) via email. They also need to inform the sender with a policy tip if they attempt to send such data and block the email if it's shared externally. Which Microsoft Purview solution should they use?

⚠ Common exam trap

It's easy for candidates to confuse Information Protection (sensitivity labels) with DLP, not realizing that sensitivity labels handle classification and encryption of data at rest, while DLP is the solution for monitoring and controlling data in motion (e.g., email) with real-time user notifications and blocking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect, warn, and block the accidental sharing of sensitive data—such as financial account numbers—via email. DLP policies can be configured with conditions that trigger a policy tip to inform the sender and automatically block the email if it is sent externally, meeting both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Data Loss Prevention (DLP)

    Why this is correct

    Microsoft 365 Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information across various locations like Exchange Online, SharePoint Online, and OneDrive. These policies leverage sensitive information types (SITs) to detect financial data, PII, or other critical data, providing real-time policy tips to users and blocking sharing actions that violate organizational policies. This proactive approach ensures sensitive data, such as customer financial records, is not inadvertently or maliciously exfiltrated, directly addressing the institution's need for prevention.

  • Information Protection (Sensitivity labels)

    Why it's wrong here

    Information Protection, through sensitivity labels, enables the classification and persistent protection of data, such as applying encryption, visual markings, or access restrictions. While labels can be auto-applied based on content, their primary function is to protect the *data itself* wherever it travels, rather than providing real-time policy tips or blocking *sharing actions* based on content detection at the point of egress. They do not inherently prevent the initial attempt to share sensitive content in violation of a policy.

  • Communication Compliance

    Why it's wrong here

    Communication Compliance focuses on detecting and investigating policy violations within internal and external communications, such as harassment, threats, or regulatory non-compliance like insider trading. It utilizes machine learning and predefined templates to identify risky or inappropriate content for review by compliance officers, but it operates primarily as a post-transmission detection and review tool. It is not designed for real-time blocking of sensitive data egress or providing immediate policy tips to users attempting to share confidential financial information.

  • Records Management

    Why it's wrong here

    Records Management in Microsoft 365 is dedicated to governing the lifecycle of organizational content, ensuring that information is retained for specific periods to meet legal, regulatory, and business requirements, and then appropriately disposed of. This service focuses on managing content as official records, including applying retention labels, legal holds, and disposition reviews. It does not provide real-time content inspection capabilities to prevent the immediate sharing of sensitive data or offer policy tips to users during email composition.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.