SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company is implementing Microsoft Purview Data Loss Prevention (DLP). You need to prevent users from sharing sensitive data like credit card numbers via email with external recipients, but allow internal sharing. What should you configure?
⚠ Common exam trap
SC-900 often tests whether candidates confuse DLP (content inspection and sharing prevention) with sensitivity labels (classification and encryption) or retention policies (lifecycle management) — the trap is picking a label or retention option because it sounds like it protects data, when only DLP inspects content and blocks external sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A DLP policy for Exchange Online with a condition 'content contains sensitive information type' and 'shared with people outside my organization'
Microsoft Purview DLP policies are designed exactly for this scenario: you create a DLP policy scoped to Exchange Online, add a rule with the condition 'Content contains sensitive information type' (e.g., Credit Card Number), and add the condition 'Shared with people outside my organization' to restrict external sharing while allowing internal. This is the canonical DLP configuration for preventing sensitive data exfiltration via email. Sensitivity labels and retention labels serve different purposes (classification/encryption and lifecycle management), and Conditional Access controls access to services, not content sharing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sensitivity labels with encryption
Why it's wrong here
Sensitivity labels with encryption primarily focus on protecting data at rest and in transit by restricting who can access the content itself. While they enforce access controls based on user permissions, they do not inherently prevent a user with authorized access from initiating a sharing action, such as sending an encrypted email to an external recipient. The objective of Data Loss Prevention (DLP) is to actively block the sharing action based on content and destination, which encryption alone does not achieve.
- ✓
A DLP policy for Exchange Online with a condition 'content contains sensitive information type' and 'shared with people outside my organization'
Why this is correct
This option directly addresses the requirement of preventing data loss by blocking external sharing of sensitive information. A Microsoft Purview Data Loss Prevention (DLP) policy configured for Exchange Online can accurately detect specific sensitive information types within email content. By combining this detection with a condition specifying 'shared with people outside my organization,' the policy can automatically block the email transmission, notify the sender, and alert administrators, effectively preventing unauthorized external disclosure.
- ✗
Retention labels and policies
Why it's wrong here
Retention labels and policies are specifically designed to govern the lifecycle of data, ensuring it is kept for a required period or deleted when no longer needed, aligning with regulatory compliance and organizational policies. Their primary function is data governance for retention and deletion, not to actively monitor or prevent the unauthorized sharing of sensitive data. They lack the real-time capability to detect sensitive content in sharing events and block those actions.
- ✗
Conditional Access policies with session controls
Why it's wrong here
Conditional Access policies primarily enforce controls at the point of access to cloud applications, based on user, device, location, and application conditions. While session controls can restrict actions like downloading or printing after access is granted, they do not specifically monitor the content being shared within an application like Exchange Online to prevent sensitive data from being sent externally. Their focus is on access management and session behavior, not content-aware data loss prevention.
Go deeper
Related to this question
Learn chapter
Azure Policy and Initiatives
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.