SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
An organization uses Microsoft 365. They need to prevent users from sharing credit card numbers in emails and Microsoft Teams messages. When a user attempts to share such sensitive information externally, the message should be blocked and the user should receive a policy tip notification. Which Microsoft Purview solution should they configure?
⚠ Common exam trap
Many exam-takers confuse Information Protection (sensitivity labels) with DLP, not realizing that DLP is the solution for actively blocking and notifying on sensitive data in transit, while Information Protection is for classification and persistent protection of data at rest.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and protect sensitive information, such as credit card numbers, through deep content analysis using built-in sensitive information types. DLP policies can be configured to block the sharing of this data in emails and Microsoft Teams messages and to display a policy tip notification to the user, enforcing compliance in real time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Lifecycle Management
Why it's wrong here
Data Lifecycle Management primarily focuses on the governance of data retention and deletion throughout its lifecycle, ensuring compliance with regulatory requirements. It defines how long data should be kept and when it should be disposed of, but it lacks the real-time content inspection and enforcement capabilities necessary to actively block the sharing of sensitive information.
- ✓
Data Loss Prevention (DLP)
Why this is correct
Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information across Microsoft 365 services. By utilizing sensitive information types, keywords, and sensitivity labels, DLP can detect when sensitive content is being shared inappropriately and enforce real-time actions, such as blocking the sharing, notifying administrators, or prompting users with policy tips, directly preventing data exfiltration.
- ✗
Insider Risk Management
Why it's wrong here
Insider Risk Management is designed to detect and investigate potentially malicious or inadvertent risky activities by internal users that could lead to data exfiltration or other security incidents. It analyzes user behavior patterns and signals to identify risks, providing alerts for investigation. However, its primary function is not to provide real-time, automated blocking of sensitive content sharing at the point of action.
- ✗
Information Protection
Why it's wrong here
Microsoft Information Protection (MIP) focuses on classifying and protecting data through sensitivity labels, which can apply encryption, visual markings, and access restrictions to content. While these labels are crucial for persistent data protection, MIP itself does not inherently provide the real-time enforcement mechanism to actively block sharing based on content analysis. DLP policies often leverage MIP labels as conditions to then enforce blocking actions.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.