Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

An organization uses Microsoft Purview Data Loss Prevention (DLP) to prevent sensitive data from being shared externally. They need to block sharing of credit card numbers in emails and Teams messages. What should they create?

⚠ Common exam trap

Watch out — candidates often confuse sensitivity labels (which classify and protect data) with DLP policies (which enforce actions like blocking based on content detection), leading them to select a sensitivity label instead of the DLP policy that actually blocks the sharing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A DLP policy with a rule that detects credit card numbers and blocks sharing

Microsoft Purview DLP policies are specifically designed to detect and automatically block the sharing of sensitive data, such as credit card numbers, across services like Exchange Online (email) and Microsoft Teams. By creating a DLP policy with a rule that includes a sensitive information type for credit card numbers and an action to block external sharing, the organization can enforce the required protection. Retention labels, audit policies, and sensitivity labels do not provide the real-time blocking capability needed for this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • A retention label to retain credit card data

    Why it's wrong here

    A retention label is designed to manage the lifecycle of data, ensuring it is kept for a specific period or deleted after a set duration to meet regulatory or organizational requirements. While crucial for data governance, retention labels do not actively scan content for sensitive information types (SITs) like credit card numbers to prevent sharing or exfiltration. Their function is data retention and deletion, not real-time data loss prevention.

  • A DLP policy with a rule that detects credit card numbers and blocks sharing

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information across various locations, including Microsoft 365 services, endpoints, and cloud apps. A DLP policy configured with a rule to detect credit card numbers (a sensitive information type) can automatically block sharing attempts, notify users, or encrypt content, thereby preventing unauthorized data exfiltration. This directly addresses the requirement to block sharing of sensitive data.

  • An audit policy to log credit card sharing

    Why it's wrong here

    An audit policy is designed to record user and administrator activities within Microsoft 365 services, creating a comprehensive log of events for compliance, security investigations, and forensic analysis. While an audit policy could log instances of credit card data being shared, its function is purely reactive—it documents what happened after the fact. It does not possess the capability to proactively detect sensitive content or block the sharing action in real-time.

  • A sensitivity label that marks credit card data

    Why it's wrong here

    Sensitivity labels in Microsoft Purview are used to classify and apply persistent protection to sensitive content by adding visual markings (like headers, footers, or watermarks) and encryption. While a sensitivity label can indicate that data contains credit card information, the label's primary function is classification and persistent protection, not the real-time blocking of sharing actions. Blocking sharing is typically an enforcement action taken by a DLP policy, often in conjunction with or triggered by a sensitivity label, but not solely by the label itself.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.