SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Contoso Ltd. is a financial services company that must comply with strict regulatory requirements. They use Microsoft 365 E5, Microsoft Entra ID P2, Microsoft Purview, and Microsoft Defender for Cloud Apps. The compliance team needs to implement a data loss prevention (DLP) policy that detects and prevents the sharing of credit card numbers in Microsoft Teams messages. Additionally, they want to ensure that only users with a specific custom sensitivity label can access documents containing credit card numbers. The sensitivity label is named 'Financial-Confidential' and is applied automatically via auto-labeling. The DLP policy should block sharing of credit card numbers in Teams but allow users to override the block with a business justification. Which combination of actions should you configure in the Microsoft Purview DLP policy to meet these requirements?
⚠ Common exam trap
SC-900 often tests the confusion between DLP policies that block without override and those that allow override with justification, as well as the distinction between DLP and sensitivity label policies for access control. DLP policies do not grant or restrict access based on sensitivity labels; that is the role of sensitivity label policies with encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a DLP policy in Microsoft Purview that blocks sharing of credit card numbers in Teams and allows overrides with business justification. Configure the policy to apply to content containing the 'Financial-Confidential' sensitivity label.
A Microsoft Purview DLP policy can detect credit card numbers in Teams messages and block sharing while allowing users to override with a business justification. Scoping the DLP policy to content containing the 'Financial-Confidential' sensitivity label applies the policy only to content with that label; it does not by itself restrict document access to only users with that label. Restricting access based on a sensitivity label requires a sensitivity label policy with encryption and access permissions. Therefore, option C addresses the Teams DLP requirement but does not fully implement the label-based access control; a separate sensitivity label policy would also be required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a DLP policy in Microsoft Purview that blocks sharing of credit card numbers in Teams and does not allow overrides. Configure the policy to apply to all content.
Why it's wrong here
No override allowed, and applies to all content, not just labeled documents.
- ✗
Configure a session policy in Microsoft Defender for Cloud Apps that monitors Teams for credit card numbers and blocks sharing. Use the 'Block with override' action.
Why it's wrong here
Defender for Cloud Apps is not the primary tool for DLP in Teams; Purview is correct.
- ✓
Create a DLP policy in Microsoft Purview that blocks sharing of credit card numbers in Teams and allows overrides with business justification. Configure the policy to apply to content containing the 'Financial-Confidential' sensitivity label.
Why this is correct
Meets all requirements.
- ✗
Use the built-in DLP template for financial data in Microsoft Purview and enable the 'Block with override' action. Set the scope to Teams.
Why it's wrong here
Built-in templates may not automatically use custom sensitivity labels.
Go deeper
Related to this question
Learn chapter
Cloud Security Posture Management (CSPM)
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.