SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
You are a security administrator for a company that uses Microsoft 365. The company has a Microsoft Purview Data Loss Prevention (DLP) policy that blocks sharing of Social Security Numbers (SSNs) externally. Recently, a user accidentally sent an email containing SSNs to an external partner after overriding the policy by selecting a business justification. Management wants to prevent users from overriding the policy for SSNs. You need to update the DLP policy to ensure that users cannot override the block for SSNs. What should you do?
⚠ Common exam trap
It's easy for candidates to think removing the policy tip or changing the action to 'Block' is necessary, but the correct approach is to keep the policy tip and disable the override setting, which is a subtle but distinct configuration in the DLP rule properties.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Modify the rule to set 'Allow override' to 'No' in the policy tip configuration.
The 'Allow override' setting in the policy tip configuration directly controls whether users can bypass a DLP block action by providing a business justification. Setting this to 'No' prevents any override for the rule that blocks SSNs, ensuring that the block is enforced without exception. This is the specific mechanism in Microsoft Purview DLP to disable user overrides for a given rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Modify the rule to set 'Allow override' to 'No' in the policy tip configuration.
Why this is correct
Setting 'Allow override' to 'No' within the policy tip configuration directly controls the user's ability to bypass a Data Loss Prevention (DLP) policy. This specific setting removes the 'override' button or option from the policy tip presented to the user, effectively preventing them from providing a business justification to proceed with a blocked action. This ensures strict enforcement while still providing the user with crucial information about the policy violation, aligning with best practices for user education.
- ✗
Increase the rule priority to ensure it is enforced before other rules.
Why it's wrong here
Increasing a rule's priority in Microsoft Purview DLP policies primarily dictates the order in which rules are evaluated and which rule takes precedence if multiple rules match the same content. However, rule priority has no direct impact on whether a specific policy rule allows or disallows a user to override its enforcement. A high-priority rule, if configured with 'Block with override,' will still present the override option to the user, as priority only affects rule application, not override capability.
- ✗
Remove the policy tip from the rule to prevent users from overriding.
Why it's wrong here
Removing the policy tip from a Data Loss Prevention (DLP) rule primarily eliminates the visual notification and explanation provided to the user when a policy is triggered. While the policy tip is where the override *option* is typically displayed, simply removing the tip does not inherently disable the underlying override *functionality* of a 'Block with override' action. The system might still prompt for override through other means, or the rule's enforcement might become less clear without user guidance, failing to prevent the override itself.
- ✗
Change the action from 'Block with override' to 'Block' and remove the policy tip.
Why it's wrong here
Changing the action from 'Block with override' to a hard 'Block' would indeed prevent users from overriding the policy, as it enforces an absolute restriction on the activity. However, combining this with removing the policy tip means that users would receive no notification, explanation, or guidance regarding why their action was blocked. This approach, while preventing override, sacrifices user awareness and self-correction, potentially leading to frustration and increased help desk calls, which is often undesirable in a user-centric compliance strategy.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.