SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE of the following are capabilities of Microsoft Purview Data Loss Prevention (DLP)? (Choose three.)
⚠ Common exam trap
Candidates often confuse DLP with other security features like malware detection or network security. Candidates might select options that are not DLP capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Detect credit card numbers in Exchange Online emails
Option A is correct because Microsoft Purview DLP includes built-in sensitive information types (SITs) such as Credit Card Number that can be applied to Exchange Online as a workload location, inspecting email content and attachments for matches. Option C is correct because DLP policies support Microsoft Teams as a location, scanning chat and channel messages for sensitive information types and taking actions like blocking or warning. Option E is correct because SharePoint Online is a supported DLP workload location, and SITs such as Passport Number (e.g., the U.S. Passport Number or international variants) can be detected in documents stored there. Option B is not a DLP capability; blocking traffic from suspicious IP addresses is a network security function handled by firewalls, Azure Firewall, or Defender for Cloud, not by Purview DLP. Option D is not a DLP capability; malware detection in email attachments is performed by Exchange Online Protection and Microsoft Defender for Office 365, not by Purview DLP, which focuses on sensitive information rather than malicious code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Detect credit card numbers in Exchange Online emails
Why this is correct
Microsoft Purview DLP inspects Exchange Online mail flow, applying sensitive information type regex and checksum validation to detect credit card numbers, then enforcing policy tips, block or encrypt actions. This satisfies the stem's capability requirement for email-borne payment card data.
- ✗
Block network traffic from suspicious IP addresses
Why it's wrong here
Blocking traffic from suspicious IP addresses is a network security control provided by Azure Firewall or NSGs, not Microsoft Purview DLP, which governs sensitive data handling across locations. It is tempting because DLP can restrict transfers, but it acts on content classification, not on IP-based network filtering.
- ✓
Detect sensitive information in Microsoft Teams messages
Why this is correct
Microsoft Purview DLP extends policy evaluation to Microsoft Teams chat and channel messages, scanning content against sensitive information types and applying block or warning actions. This satisfies the stem's capability requirement, covering collaboration traffic beyond email and file stores.
- ✗
Detect malware in email attachments
Why it's wrong here
Malware detection in email attachments is performed by Microsoft Defender for Office 365, not Microsoft Purview DLP, which inspects content against sensitive information types and policies. It is tempting because DLP scans the same email flow, but its evaluation targets data classification and exfiltration rules rather than malicious payload signatures.
- ✓
Detect passport numbers in SharePoint Online documents
Why this is correct
Microsoft Purview DLP scans SharePoint Online and OneDrive documents, matching passport number patterns via sensitive information types and enforcing restrict-access or block actions. This satisfies the stem's capability requirement for detecting identity documents at rest in cloud storage.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Exchange Online
Exchange Online is Microsoft's cloud-based email, calendar, and contact hosting service that is part of the Microsoft 365 suite, allowing organizations to manage corporate messaging without maintaining their own mail servers.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.