SC-900 Data Loss Prevention (DLP) Practice Question
You are the security administrator for a large healthcare organization that uses Microsoft 365 E5. The organization must comply with HIPAA and GDPR regulations. You have implemented Microsoft Purview Information Protection with sensitivity labels to classify and protect patient data. Recently, the compliance team identified that some documents containing Protected Health Information (PHI) are being shared externally without protection. You need to prevent users from sharing documents classified as 'Highly Confidential' with external users unless the document is encrypted and labeled. Additionally, you must ensure that any external sharing of such documents is automatically blocked. You have the following options available. Which action should you take?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a data loss prevention (DLP) policy in Microsoft Purview that detects the 'Highly Confidential' label and blocks sharing with external users
The correct action is to create a DLP policy in Microsoft Purview that detects the 'Highly Confidential' label and blocks sharing with external users. DLP policies are designed to inspect content and labels on documents, then take protective actions such as blocking external sharing, sending notifications, or applying restrictions. Auto-labeling (option A) applies labels automatically but does not enforce sharing restrictions. Conditional access policies (option C) control access at the authentication level, not based on document labels. Retention policies (option D) manage data lifecycle, not sharing permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure auto-labeling for SharePoint to automatically apply the 'Highly Confidential' label to all documents containing PHI
Why it's wrong here
Auto-labeling applies sensitivity labels automatically but does not block external sharing; it only labels the content.
- ✓
Create a data loss prevention (DLP) policy in Microsoft Purview that detects the 'Highly Confidential' label and blocks sharing with external users
Why this is correct
A DLP policy can detect the 'Highly Confidential' label and automatically block external sharing, meeting the requirement.
- ✗
Configure a conditional access policy in Microsoft Entra ID to block external access to SharePoint sites containing PHI
Why it's wrong here
Conditional access policies control access to resources based on user, device, or location, not document labels.
- ✗
Create a retention policy for SharePoint that prevents deletion of documents with the 'Highly Confidential' label
Why it's wrong here
Retention policies are used to retain or delete documents, not to control sharing permissions.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.