SC-900 Practice Question: Describe the concepts of security, compliance, and identity
You are a security administrator for Contoso Ltd., a global financial services company with 5,000 employees. The company uses Microsoft 365 E5 licenses and has deployed Microsoft Entra ID, Microsoft Defender XDR, Microsoft Purview, and Microsoft Intune. Recently, the security team identified a risk: employees are sharing sensitive financial reports via external email recipients without encryption. To address this, you need to implement a solution that automatically applies encryption to emails containing the sensitive information type 'U.S. Bank Account Number' when sent to external recipients. The solution must not block the email but should encrypt it. Additionally, you want to notify the sender with a policy tip that the email will be encrypted. You have access to the Microsoft Purview compliance portal. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Data Loss Prevention (DLP) policy in Microsoft Purview that detects 'U.S. Bank Account Number' and applies encryption to emails sent to external recipients, with a policy tip.
A Data Loss Prevention (DLP) policy in Microsoft Purview can automatically detect sensitive information types like 'U.S. Bank Account Number' and apply encryption to emails sent to external recipients, while also showing a policy tip to notify the sender. Option A is incorrect because Microsoft Defender for Office 365 does not provide DLP policies; DLP is part of Microsoft Purview. Option C is incorrect because simply enabling Message Encryption for all users does not automatically apply encryption based on content; it requires a DLP policy or other mechanism. Option D is incorrect because sensitivity labels require manual application or auto-labeling rules, whereas DLP can automatically enforce encryption based on conditions like sensitive data detection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an email encryption rule in Microsoft Defender for Office 365.
Why it's wrong here
Defender for Office 365 focuses on threat protection, not DLP.
- ✓
Create a Data Loss Prevention (DLP) policy in Microsoft Purview that detects 'U.S. Bank Account Number' and applies encryption to emails sent to external recipients, with a policy tip.
Why this is correct
DLP can automatically apply encryption and show policy tips.
- ✗
Enable Microsoft Purview Message Encryption for all users.
Why it's wrong here
Message Encryption is a feature, but DLP is needed to automate application.
- ✗
Create a sensitivity label with encryption and publish it to all users, then train users to apply it manually.
Why it's wrong here
Manual application does not ensure automatic protection.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.