Courseiva

What Actions Can Microsoft Purview DLP Policies Perform?

Which THREE actions can be performed by Microsoft Purview Data Loss Prevention (DLP) policies?

Quick Answer

The answer is that Microsoft Purview DLP policies can perform the actions of blocking unauthorized sharing, sending policy tip notifications to users, and applying encryption via sensitivity labels. These three actions are correct because DLP policies are designed to prevent data loss by controlling how sensitive information is shared or used, not by managing the lifecycle of files. For instance, when a user attempts to share a document containing credit card numbers, the policy can block the action, notify the user with a tip, and automatically encrypt the file using a sensitivity label to protect it. On the SC-900 exam, this question tests your understanding of DLP’s enforcement capabilities versus retention or audit features—a common trap is confusing DLP with retention policies, which can delete or move files, or with the Audit feature, which logs events but does not take direct action. Remember the mnemonic “Block, Notify, Encrypt” to recall the three core actions of DLP policies.

⚠ Common exam trap

Watch out — candidates often confuse DLP's ability to generate alerts or logs with the separate audit log functionality, or assume DLP can delete files when it only blocks or encrypts data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Send notification to users

Microsoft Purview DLP policies can send email notifications to users when a policy match occurs, alerting them to potential policy violations and providing guidance on proper data handling. This is a core end-user notification feature that helps educate users and reduce accidental data leaks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create audit reports of policy matches

    Why it's wrong here

    DLP generates activity logs, but audit reports are separate.

  • Send notification to users

    Why this is correct

    DLP can show policy tips and send email notifications.

  • Block sharing of sensitive data

    Why this is correct

    DLP can block sharing actions.

  • Automatically delete files containing sensitive data

    Why it's wrong here

    DLP does not automatically delete files.

  • Apply encryption via sensitivity labels

    Why this is correct

    DLP can auto-apply sensitivity labels that enforce encryption.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE actions can Microsoft Purview Data Loss Prevention (DLP) policies perform when a sensitive data match is detected?

hard
  • A.Apply a retention label
  • B.Encrypt the content automatically
  • C.Block the sharing of the content
  • D.Send a notification to the user
  • E.Delete the content permanently

Why B: Microsoft Purview DLP policies are designed to prevent sensitive data from being shared inappropriately. When a sensitive data match is detected, DLP policies can perform several actions. These include automatically **encrypting the content** (B), often leveraging Azure Information Protection or Microsoft 365 Message Encryption, to restrict access to authorized users. They can also **block the sharing of the content** (C), preventing it from being sent via email, copied to unauthorized locations, or accessed externally. Additionally, DLP policies can **send a notification to the user** (D) who is attempting the action, informing them of the policy violation, and can also notify administrators.

Variation 2. Which THREE actions can be performed using a Microsoft Purview Data Loss Prevention (DLP) policy?

medium
  • A.Notify users via policy tip when they try to share sensitive data
  • B.Block sharing of sensitive data with external users
  • C.Automatically retain emails for 7 years
  • D.Encrypt emails containing sensitive data
  • E.Apply a sensitivity label automatically

Why A: Microsoft Purview Data Loss Prevention (DLP) policies are designed to identify, monitor, and protect sensitive information across various Microsoft 365 services. Key actions include: notifying users via policy tips when they try to share sensitive data (Option A), blocking sharing of sensitive data with external users (Option B), and automatically applying sensitivity labels to content that contains sensitive information (Option E).

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.