SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to prevent users from sharing credit card numbers via email outside the company. Which type of DLP rule action should they configure?
⚠ Common exam trap
Test-takers frequently confuse 'Block' with 'Encrypt' or 'Notify', thinking that encryption or notification alone is sufficient to prevent data loss, but only Block actually stops the transmission of sensitive data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block
To prevent users from sharing credit card numbers via email outside the company, a DLP rule action of 'Block' is required. This action stops the email from being sent when sensitive content (e.g., credit card numbers) is detected, ensuring data exfiltration is prevented. The Block action can also be configured to show a policy tip to the user, but the core enforcement is the blocking of the message.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Block
Why this is correct
The "Block" action in Microsoft Purview Data Loss Prevention (DLP) policies is designed to actively prevent sensitive information from being transmitted outside the organization. When a DLP policy rule configured with this action is triggered by an email containing sensitive data, the system will immediately stop the email from being sent to its intended external recipients. This action directly fulfills the requirement to prevent data exfiltration, often accompanied by a policy tip informing the sender of the block and potential override options.
- ✗
Notify
Why it's wrong here
The "Notify" action within a Microsoft Purview DLP policy primarily serves to alert administrators and/or inform the end-user about a potential policy violation without stopping the data transfer. When this action is configured, an incident report is generated for security teams, and a policy tip may be displayed to the sender as a warning. However, the email containing the sensitive information will still be successfully delivered, meaning the data loss itself is not prevented, only reported.
- ✗
Audit only
Why it's wrong here
The "Audit only" action is the least intrusive enforcement option in Microsoft Purview DLP policies, intended for monitoring and policy testing rather than prevention. When a DLP rule with this action is matched, the system records an event in the DLP reports, detailing the policy violation for review and analysis. Crucially, this action takes no steps to prevent the email from being sent, allowing organizations to understand potential policy impacts before implementing stricter controls, but it does not prevent data loss.
- ✗
Encrypt
Why it's wrong here
While encryption is a vital security measure, the "Encrypt" action in Microsoft Purview DLP policies, often leveraging Microsoft Purview Message Encryption, focuses on protecting the confidentiality of the email's content. It ensures that sensitive information within the email is secured in transit and at rest, accessible only by authorized recipients. However, this action does not prevent the email from being sent to its destination; it merely protects the content, which is distinct from blocking the transmission to prevent data loss entirely.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.