What Actions Can Microsoft Purview DLP Policies Perform?
Which THREE actions can be performed by Microsoft Purview Data Loss Prevention (DLP) policies?
Quick Answer
The answer is that Microsoft Purview DLP policies can perform the actions of blocking unauthorized sharing, sending policy tip notifications to users, and applying encryption via sensitivity labels. These three actions are correct because DLP policies are designed to prevent data loss by controlling how sensitive information is shared or used, not by managing the lifecycle of files. For instance, when a user attempts to share a document containing credit card numbers, the policy can block the action, notify the user with a tip, and automatically encrypt the file using a sensitivity label to protect it. On the SC-900 exam, this question tests your understanding of DLP’s enforcement capabilities versus retention or audit features—a common trap is confusing DLP with retention policies, which can delete or move files, or with the Audit feature, which logs events but does not take direct action. Remember the mnemonic “Block, Notify, Encrypt” to recall the three core actions of DLP policies.
⚠ Common exam trap
Watch out — candidates often confuse DLP's ability to generate alerts or logs with the separate audit log functionality, or assume DLP can delete files when it only blocks or encrypts data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Send notification to users
Microsoft Purview DLP policies can send email notifications to users when a policy match occurs, alerting them to potential policy violations and providing guidance on proper data handling. This is a core end-user notification feature that helps educate users and reduce accidental data leaks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create audit reports of policy matches
Why it's wrong here
DLP generates activity logs, but audit reports are separate.
- ✓
Send notification to users
Why this is correct
DLP can show policy tips and send email notifications.
- ✓
Block sharing of sensitive data
Why this is correct
DLP can block sharing actions.
- ✗
Automatically delete files containing sensitive data
Why it's wrong here
DLP does not automatically delete files.
- ✓
Apply encryption via sensitivity labels
Why this is correct
DLP can auto-apply sensitivity labels that enforce encryption.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE actions can Microsoft Purview Data Loss Prevention (DLP) policies perform when a sensitive data match is detected?
hard- A.Apply a retention label
- ✓ B.Encrypt the content automatically
- ✓ C.Block the sharing of the content
- ✓ D.Send a notification to the user
- E.Delete the content permanently
Why B: Microsoft Purview DLP policies are designed to prevent sensitive data from being shared inappropriately. When a sensitive data match is detected, DLP policies can perform several actions. These include automatically **encrypting the content** (B), often leveraging Azure Information Protection or Microsoft 365 Message Encryption, to restrict access to authorized users. They can also **block the sharing of the content** (C), preventing it from being sent via email, copied to unauthorized locations, or accessed externally. Additionally, DLP policies can **send a notification to the user** (D) who is attempting the action, informing them of the policy violation, and can also notify administrators.
Variation 2. Which THREE actions can be performed using a Microsoft Purview Data Loss Prevention (DLP) policy?
medium- ✓ A.Notify users via policy tip when they try to share sensitive data
- ✓ B.Block sharing of sensitive data with external users
- C.Automatically retain emails for 7 years
- D.Encrypt emails containing sensitive data
- ✓ E.Apply a sensitivity label automatically
Why A: Microsoft Purview Data Loss Prevention (DLP) policies are designed to identify, monitor, and protect sensitive information across various Microsoft 365 services. Key actions include: notifying users via policy tips when they try to share sensitive data (Option A), blocking sharing of sensitive data with external users (Option B), and automatically applying sensitivity labels to content that contains sensitive information (Option E).
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.