SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. They need to ensure that when a user tries to share a document containing a credit card number externally via email, the user sees a policy tip and the email is blocked. Which DLP rule action should they configure?
⚠ Common exam trap
It's easy for candidates to confuse 'Notify user with policy tip only' as sufficient because it provides a warning, but they overlook the explicit requirement to block the message, which requires the combined action of blocking and notifying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Block the message and notify the user with a policy tip
The requirement is to both block the email and show a policy tip to the user. In Microsoft Purview DLP, the 'Block the message and notify the user with a policy tip' action enforces the block at the transport level while simultaneously displaying a customizable policy tip in Outlook or Outlook on the web, informing the user why the message was blocked. This meets the dual need of prevention and user notification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Notify user with policy tip only
Why it's wrong here
This action provides a policy tip to the user, informing them of a potential data loss prevention (DLP) policy violation. While it raises user awareness and educates them on sensitive information handling, it does not actively prevent the transmission of the sensitive data. The user retains the ability to override the policy tip and send the message, thus failing to enforce data loss prevention.
- ✓
Block the message and notify the user with a policy tip
Why this is correct
This action effectively prevents data loss by blocking the transmission of the message containing sensitive information, ensuring the policy is enforced. Simultaneously, it provides a policy tip to the user, explaining why the message was blocked and offering guidance on how to remediate the issue or comply with organizational policies. This combination both enforces security and educates the user, aligning perfectly with robust data loss prevention objectives.
- ✗
Block the message only
Why it's wrong here
While blocking the message successfully prevents the sensitive information from being transmitted, this action lacks a crucial user feedback mechanism. Without a policy tip or notification, the sender is unaware of why their message failed to send, leading to potential confusion, frustration, and repeated attempts. This approach hinders user education and makes it difficult for individuals to understand and comply with DLP policies proactively in the future.
- ✗
Redirect the message to the compliance admin
Why it's wrong here
Redirecting the message to a compliance administrator allows for post-incident review and investigation of potential data loss incidents. However, this action does not prevent the initial transmission of the sensitive information, meaning the data loss has already occurred. Furthermore, it fails to notify the original sender about the policy violation, missing an opportunity for real-time user education and immediate remediation, which are critical components of proactive data loss prevention.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Outlook
Microsoft Outlook is an email, calendar, and contact management application that is part of the Microsoft 365 suite, used by businesses and individuals to organize communications and schedules.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.