SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A security administrator needs to enforce that all Microsoft 365 documents containing credit card numbers are automatically encrypted before being shared externally. Which Microsoft Purview solution should they use?
⚠ Common exam trap
Watch out — candidates often confuse Information Protection (which handles labeling and classification) with DLP (which enforces protective actions like encryption), but Microsoft Purview DLP is the engine that actually triggers automatic encryption based on content detection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention
Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it can automatically detect sensitive data types, such as credit card numbers, in Microsoft 365 documents and enforce protective actions like encryption before external sharing. DLP policies use sensitive information types (e.g., Credit Card Number) and conditions to trigger encryption via Azure Information Protection, ensuring data is protected at rest and in transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Audit
Why it's wrong here
Microsoft Purview Audit records user and administrator activities across various Microsoft 365 services, providing a comprehensive log for security investigations, compliance adherence, and forensic analysis. While crucial for visibility and accountability, Audit is fundamentally a logging and reporting service. It does not possess the capability to actively scan content for sensitive information or automatically enforce protective actions like encryption on documents.
- ✗
Microsoft Purview Communication Compliance
Why it's wrong here
Microsoft Purview Communication Compliance is designed to help organizations detect, investigate, and act on inappropriate messages within internal and external communications, such as Microsoft Teams, Exchange Online, and Yammer. Its primary function is to monitor for policy violations like harassment, regulatory non-compliance, or the sharing of sensitive information within communication channels. This service does not, however, automatically apply encryption to documents or files based on their content.
- ✓
Microsoft Purview Data Loss Prevention
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information across endpoints, cloud apps, and services. When a DLP policy detects sensitive data in a document, it can be configured to automatically apply protective actions, including the application of sensitivity labels that enforce encryption, thereby preventing unauthorized sharing or exfiltration and ensuring data protection.
- ✗
Microsoft Purview Information Protection
Why it's wrong here
Microsoft Purview Information Protection (MPIP) provides the framework for classifying, labeling, and protecting sensitive data, allowing organizations to define sensitivity labels with associated encryption, visual markings, and access restrictions. While MPIP defines *how* data is protected, it is typically Microsoft Purview Data Loss Prevention (DLP) policies that *automatically apply* these MPIP sensitivity labels and their inherent encryption based on content detection, rather than MPIP directly enforcing content-based automatic encryption.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.