SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Your company needs to detect and prevent employees from sharing confidential product plans via email with external parties. Which Microsoft Purview solution should you configure?
⚠ Common exam trap
It's easy for candidates to confuse sensitivity labels (which apply protection at rest) with DLP (which enforces actions in transit), leading them to select sensitivity labels when the question explicitly requires detection and prevention of sharing via email.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP)
Data Loss Prevention (DLP) is the correct solution because it is specifically designed to detect and prevent the unauthorized sharing of sensitive information, such as confidential product plans, via email and other channels. DLP policies can inspect email content and attachments for sensitive data types (e.g., custom keywords or patterns) and automatically block or quarantine the message if it is sent to external recipients. This aligns directly with the requirement to prevent employees from sharing confidential plans externally.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels apply classification to data, which can then trigger protective actions like encryption or visual markings based on the label's configuration. However, they primarily identify and mark sensitive content, and while they can be used by DLP policies to enforce restrictions, they do not inherently block sharing on their own. Their role is to categorize data, not to directly prevent its unauthorized movement.
- ✗
Communication compliance
Why it's wrong here
Communication compliance policies are designed to detect and investigate potential regulatory, legal, or internal policy violations within an organization's communications, such as email or Teams chats. It operates by monitoring and reviewing content for specific patterns or keywords, generating alerts for human review. While it identifies problematic sharing after it occurs, it does not actively prevent the initial act of sharing sensitive data in real-time.
- ✓
Data Loss Prevention (DLP)
Why this is correct
Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and automatically protect sensitive information across various locations, including endpoints, cloud apps, and services like Exchange, SharePoint, and OneDrive. By detecting specific sensitive information types or content, DLP can actively block sharing, encrypt data, or notify users and administrators in real-time. This direct enforcement capability is crucial for preventing unauthorized data exfiltration or sharing.
- ✗
Retention policies
Why it's wrong here
Retention policies are established to manage the lifecycle of data, ensuring it is kept for a specific period to meet regulatory, legal, or business requirements, and then disposed of appropriately. Their primary function is data governance related to storage and deletion over time, not to actively prevent the unauthorized sharing or exfiltration of sensitive information. They address how long data exists, not who can share it.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Quarantine
Quarantine is a security process that isolates a potentially malicious file, email, or device from the rest of the system to prevent harm while it is analyzed or remediated.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.