SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company is adopting Microsoft Copilot for Microsoft 365 to improve productivity. The security team is concerned about data leakage, as Copilot can access emails, documents, and other content. You need to ensure that sensitive data, such as credit card numbers and social security numbers, is not inadvertently exposed by Copilot. The organization uses Microsoft Purview sensitivity labels and DLP. You need to configure a solution that automatically detects and prevents Copilot from accessing or generating content containing these sensitive data types. What should you do?
⚠ Common exam trap
SC-900 often tests the difference between classifying data (sensitivity labels) and enforcing action (DLP) — the trap is picking 'apply sensitivity labels' when the requirement explicitly says 'automatically detect and prevent.'
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a DLP policy in Microsoft Purview that detects sensitive data types and blocks Copilot actions
A Microsoft Purview DLP policy that detects sensitive information types (credit card numbers, SSNs) and is scoped to Copilot interactions will block Copilot from processing or generating content containing that data. Purview DLP natively integrates with Copilot for Microsoft 365, so policies can enforce restrictions on prompts and responses in real time. This is the purpose-built control for the stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Microsoft Defender for Cloud Apps to control Copilot
Why it's wrong here
Defender for Cloud Apps governs sanctioned cloud app usage and session controls, but it does not evaluate Microsoft Purview sensitive information types inside Copilot prompts or responses. It fits discovering shadow IT and anomalous SaaS activity, not enforcing DLP against credit card or social security number patterns in Copilot.
- ✗
Disable Copilot for users who handle sensitive data
Why it's wrong here
Disabling Copilot removes the productivity capability entirely rather than detecting and preventing sensitive data exposure, and the requirement is automatic detection. Licence removal suits organisations choosing not to deploy Copilot at all, not one needing DLP enforcement across emails, documents and generated content.
- ✗
Apply sensitivity labels to all documents containing sensitive data
Why it's wrong here
Sensitivity labels classify and protect content but do not automatically detect credit card or social security number patterns in Copilot interactions, nor block generation. Labels suit manual or auto-classification of documents and emails; the stem requires DLP policy enforcement covering Copilot prompts and responses.
- ✓
Create a DLP policy in Microsoft Purview that detects sensitive data types and blocks Copilot actions
Why this is correct
A Microsoft Purview DLP policy scoped to Copilot detects sensitive information types such as credit card and social security numbers in prompts and responses, then blocks the action. This directly prevents Copilot from accessing or generating content containing those data types.
Go deeper
Related to this question
Learn chapter
Defence-in-Depth Security Layers
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.