SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A multinational company deploys Microsoft Purview Data Loss Prevention (DLP) to protect credit card numbers. The compliance team reports that a DLP policy blocks a legitimate payment processing workflow. What should the compliance administrator do to allow the workflow while maintaining protection?
⚠ Common exam trap
A common mix-up: candidates think adding the server to an allow list (Option A) is the simplest fix, but this creates a security gap by exempting all data from that server, whereas the policy tip override maintains protection while allowing legitimate exceptions with accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a DLP policy tip that allows users to override the block with a business justification.
DLP policy tips allow users to override a block by providing a business justification, which enables legitimate workflows to proceed while maintaining data protection. This approach ensures that the payment processing workflow is not permanently blocked, but the override is auditable and subject to compliance review. It balances security and operational needs without disabling or weakening the DLP policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the payment processing server to the DLP policy’s allow list.
Why it's wrong here
Adding the payment processing server to a DLP policy's allow list would create a critical security vulnerability. This action means that any data originating from or passing through that specific server would be entirely exempt from all DLP scanning and enforcement rules. Consequently, sensitive payment processing data could be freely exfiltrated or inadvertently shared without any protective measures, completely undermining the purpose of implementing data loss prevention.
- ✓
Configure a DLP policy tip that allows users to override the block with a business justification.
Why this is correct
Configuring a DLP policy tip that allows users to override the block with a business justification is the optimal solution. This approach provides real-time notification to users when a potential policy violation occurs, offering them the flexibility to proceed if they can provide a valid business reason. This balances robust data protection with operational continuity, ensuring legitimate workflows can proceed while maintaining an auditable record of all overrides and their justifications for compliance and accountability.
- ✗
Reduce the minimum confidence level in the DLP policy.
Why it's wrong here
Reducing the minimum confidence level in a DLP policy would make the detection criteria less strict, leading to a higher tolerance for ambiguity in identifying sensitive information. While this might decrease false positives, it significantly increases the risk of false negatives, meaning the policy would be less effective at accurately identifying and blocking actual instances of sensitive data loss. This could allow legitimate policy violations to go undetected and unblocked, compromising data security.
- ✗
Disable the DLP policy for the payment processing department.
Why it's wrong here
Disabling the DLP policy for the payment processing department would completely remove all data loss prevention controls for that critical group. This action would leave all sensitive payment information handled by the department entirely unprotected, exposing it to significant risks of accidental or malicious data exfiltration, non-compliance with regulatory requirements, and severe financial and reputational damage. Such a measure directly contradicts the fundamental objective of deploying Microsoft Purview DLP.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.