Microsoft Purview Data Loss Prevention: Block Emails with Confidential Phrases
A company needs to ensure that employees cannot share sensitive financial reports with external parties via email. They want to automatically detect and block emails that contain the phrase 'Confidential-Financial' in the subject line or body, regardless of the recipient's domain. Which Microsoft Purview solution should they configure?
Quick Answer
The answer is Microsoft Purview Data Loss Prevention (DLP). DLP is the correct choice because it allows you to create a policy that inspects both the subject line and body of an email for specific phrases like 'Confidential-Financial', and then automatically blocks the message from being sent—regardless of whether the recipient's domain is internal or external. This capability is central to preventing unauthorized sharing of sensitive financial reports, as DLP policies enforce actions such as blocking delivery or sending a notification to the user. On the SC-900 exam, this scenario tests your understanding of how DLP differs from other solutions like Information Protection or Insider Risk Management; a common trap is confusing DLP with sensitivity labels, but remember that DLP focuses on *detecting and blocking* content in transit, not just classifying it. For a quick memory tip, think "DLP = Detect, Lock, Prevent"—it actively stops the email from leaving your organization.
⚠ Common exam trap
It's easy for candidates to confuse Information Protection (sensitivity labels) with DLP, thinking labels alone can block emails, but labels only classify and encrypt—blocking requires a DLP policy to enforce actions based on label conditions or content matches.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Microsoft Purview Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and automatically block sensitive content—such as the phrase 'Confidential-Financial'—in emails, regardless of the recipient's domain. DLP policies can inspect subject lines and body text, then enforce actions like blocking delivery or notifying the user, making it ideal for preventing unauthorized external sharing of financial reports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Loss Prevention (DLP)
Why this is correct
Data Loss Prevention in Microsoft Purview inspects email content and can detect the phrase 'Confidential-Financial' in the subject or body, then block or restrict the message regardless of recipient domain. This satisfies the requirement to stop external sharing automatically.
- ✗
Information Protection (sensitivity labels)
Why it's wrong here
Sensitivity labels classify and protect content but do not detect a specific phrase and block the email outright. Information Protection is the correct choice when the goal is persistent encryption and labelling that travels with the document, not transport-level blocking.
- ✗
Data Lifecycle Management (retention policies)
Why it's wrong here
Retention policies govern how long content is kept and when it is deleted, not the transmission of outbound email, so they cannot inspect subject lines or block messages to external domains. They are tempting because they do label and preserve sensitive items, but that applies to lifecycle governance, not transport-rule enforcement.
- ✗
Audit
Why it's wrong here
Audit only records user and admin activity for later review; it cannot inspect message content or block delivery. Audit is the right choice when the requirement is investigation and retention of who did what, not real-time prevention of email.
Go deeper
Related to this question
Learn chapter
Retention Policies and Labels
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft 365 and wants to automatically quarantine suspicious emails before they reach users' inboxes. Which solution should you configure?
medium- A.Microsoft Purview Data Loss Prevention
- B.Microsoft Sentinel
- C.Microsoft Intune
- ✓ D.Microsoft Defender for Office 365
Why D: Microsoft Defender for Office 365 includes Exchange Online Protection (EOP) and advanced threat protection features such as Safe Attachments and Safe Links. These capabilities automatically quarantine suspicious emails—including those with malicious attachments, phishing URLs, or spoofed senders—before they reach user inboxes, based on policy-defined actions like 'Quarantine message'.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.