Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

Which THREE of the following are capabilities of Microsoft Purview Data Loss Prevention (DLP)? (Choose three.)

⚠ Common exam trap

Candidates often confuse DLP with other security features like malware detection or network security. Candidates might select options that are not DLP capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Detect credit card numbers in Exchange Online emails

Option A is correct because Microsoft Purview DLP includes built-in sensitive information types (SITs) such as Credit Card Number that can be applied to Exchange Online as a workload location, inspecting email content and attachments for matches. Option C is correct because DLP policies support Microsoft Teams as a location, scanning chat and channel messages for sensitive information types and taking actions like blocking or warning. Option E is correct because SharePoint Online is a supported DLP workload location, and SITs such as Passport Number (e.g., the U.S. Passport Number or international variants) can be detected in documents stored there. Option B is not a DLP capability; blocking traffic from suspicious IP addresses is a network security function handled by firewalls, Azure Firewall, or Defender for Cloud, not by Purview DLP. Option D is not a DLP capability; malware detection in email attachments is performed by Exchange Online Protection and Microsoft Defender for Office 365, not by Purview DLP, which focuses on sensitive information rather than malicious code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Detect credit card numbers in Exchange Online emails

    Why this is correct

    Microsoft Purview DLP inspects Exchange Online mail flow, applying sensitive information type regex and checksum validation to detect credit card numbers, then enforcing policy tips, block or encrypt actions. This satisfies the stem's capability requirement for email-borne payment card data.

  • ✗

    Block network traffic from suspicious IP addresses

    Why it's wrong here

    Blocking traffic from suspicious IP addresses is a network security control provided by Azure Firewall or NSGs, not Microsoft Purview DLP, which governs sensitive data handling across locations. It is tempting because DLP can restrict transfers, but it acts on content classification, not on IP-based network filtering.

  • ✓

    Detect sensitive information in Microsoft Teams messages

    Why this is correct

    Microsoft Purview DLP extends policy evaluation to Microsoft Teams chat and channel messages, scanning content against sensitive information types and applying block or warning actions. This satisfies the stem's capability requirement, covering collaboration traffic beyond email and file stores.

  • ✗

    Detect malware in email attachments

    Why it's wrong here

    Malware detection in email attachments is performed by Microsoft Defender for Office 365, not Microsoft Purview DLP, which inspects content against sensitive information types and policies. It is tempting because DLP scans the same email flow, but its evaluation targets data classification and exfiltration rules rather than malicious payload signatures.

  • ✓

    Detect passport numbers in SharePoint Online documents

    Why this is correct

    Microsoft Purview DLP scans SharePoint Online and OneDrive documents, matching passport number patterns via sensitive information types and enforcing restrict-access or block actions. This satisfies the stem's capability requirement for detecting identity documents at rest in cloud storage.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.