SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data. Which THREE actions can be taken automatically when a DLP policy matches?
⚠ Common exam trap
It's easy for candidates to assume DLP can delete content (B) or notify any arbitrary department (A). Microsoft Purview DLP primarily supports direct enforcement actions like blocking (E), encrypting (D), and showing policy tips (C). While it can send notifications, these are typically to predefined administrators or policy owners for incident management, not a generic 'legal department' as one of the primary automatic actions on the data or user interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Show a policy tip to the user
Option C is correct because Microsoft Purview DLP policies can display a policy tip (a user notification/override prompt) in supported workloads such as Exchange, SharePoint, OneDrive, Teams, and Office apps when a rule matches. Option D is correct because DLP rules can apply encryption through actions like restricting access or applying a sensitivity label with encryption to the matched content. Option E is correct because DLP can block sharing or restrict access to sensitive data, for example by preventing external sharing or blocking the email/file from being sent. Options A and B are not standard automatic DLP actions: DLP does not automatically notify a legal department as a built-in action, and it does not delete sensitive content automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automatically notify the legal department
Why it's wrong here
Microsoft Purview DLP policies are designed to identify, monitor, and protect sensitive information. While DLP can generate alerts for security and compliance administrators when a policy is matched, directly notifying a specific department like legal is not a standard, configurable *action* within a DLP policy itself. Such notifications would typically be part of a broader incident response workflow, potentially triggered by a DLP alert, rather than a direct DLP enforcement action.
- ✗
Delete the sensitive content
Why it's wrong here
Microsoft Purview Data Loss Prevention policies are designed to prevent the unauthorized sharing or exfiltration of sensitive data, not to delete content. DLP focuses on monitoring, blocking, or encrypting data based on policy matches, ensuring data remains secure and compliant. Deleting content falls under data lifecycle management or retention policies, which are distinct functions within Microsoft Purview, rather than a direct action of a DLP policy.
- ✓
Show a policy tip to the user
Why this is correct
A core capability of Microsoft Purview DLP is to educate users in real-time about their compliance obligations. When a user attempts an action that violates a DLP policy, a policy tip can be displayed directly within the application (e.g., Outlook, Word, SharePoint). These tips provide immediate feedback, explaining why the action is blocked or flagged, and sometimes offering an override option, thereby fostering a culture of data protection.
- ✓
Encrypt the sensitive content
Why this is correct
Microsoft Purview DLP policies can be configured to automatically apply encryption to sensitive content that matches specific policy conditions. This is often achieved by integrating with Microsoft Information Protection (MIP) sensitivity labels. When a DLP policy detects sensitive data, it can automatically apply a label that encrypts the content, restricting access to authorized individuals and protecting it even if it leaves the organization's control.
- ✓
Block the sharing of sensitive data
Why this is correct
A fundamental action of Microsoft Purview DLP is to prevent the unauthorized sharing or exfiltration of sensitive data. DLP policies can be configured to block users from sharing content containing sensitive information externally, or even internally to unauthorized groups. This enforcement can occur across various locations, including email, SharePoint Online, OneDrive for Business, Microsoft Teams, and endpoint devices, effectively stopping data loss at the point of attempted sharing.
Go deeper
Related to this question
Learn chapter
Cross-Tenant Access Settings
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.