SC-900 DLP Policy Override Practice Question
Your organization is implementing a data loss prevention (DLP) policy to prevent sensitive data from being shared via email. Users in the finance department need to send financial reports to external auditors. What should you configure?
⚠ Common exam trap
SC-900 often tests the difference between a DLP allow list (permanent bypass) and a user override (justified, audited exception) — candidates pick the allow list because it sounds like the simplest way to let auditors receive mail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a DLP policy with an override option allowing users to justify the sharing
A DLP policy with an override (user override / allow with justification) lets finance users send reports to external auditors while still enforcing the policy — the user must provide a business justification, which is logged for audit. This balances data protection with the legitimate business need, which is exactly what Microsoft Purview DLP user overrides are designed for.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the auditors' domains to a DLP allow list
Why it's wrong here
Adding auditors' domains to a DLP allow list is not a standard or effective configuration within Microsoft Purview Data Loss Prevention. DLP policies primarily operate by inspecting content for sensitive information types and applying actions based on policy rules, rather than relying on domain-based whitelisting to bypass these content-centric controls. While mail flow rules (transport rules) in Exchange Online can utilize sender/recipient domain allow lists for email routing or processing, DLP policies are designed for granular content protection and do not typically offer a direct 'allow list' mechanism for policy exceptions based solely on external domains.
- ✓
Configure a DLP policy with an override option allowing users to justify the sharing
Why this is correct
Configuring a DLP policy with an override option that allows users to justify sharing is the most appropriate solution for balancing security with legitimate business needs. This feature enables organizations to enforce strong data protection while providing a controlled mechanism for users to temporarily bypass a policy when a valid business reason exists, such as sharing specific audit-related documents externally. The justification provided by the user is logged, creating an essential audit trail for compliance and review, ensuring accountability without completely blocking necessary collaboration.
- ✗
Assign a sensitivity label that automatically encrypts the email
Why it's wrong here
Assigning a sensitivity label that automatically encrypts the email primarily focuses on data classification and protection, ensuring that the content remains secure even if it leaves the organization's control. While sensitivity labels are crucial for data governance and can enforce encryption, they do not inherently provide the 'override with justification' capability that a DLP policy offers for user-driven exceptions to sharing rules. Their function is to apply persistent protection based on content classification, not to manage conditional sharing exceptions with an audit trail for user justification.
- ✗
Configure a DLP policy with a block action for all external sharing
Why it's wrong here
Configuring a DLP policy with a block action for all external sharing would be overly restrictive and detrimental to legitimate business operations. While blocking is a powerful DLP action, applying it universally would prevent necessary collaboration with external partners, customers, and, in this scenario, auditors, hindering productivity and operational efficiency. Effective DLP strategies require granularity, allowing for specific exceptions or user overrides with justification rather than implementing a blanket ban that impedes essential business processes.
Go deeper
Related to this question
Learn chapter
Azure DDoS Protection and Firewall
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.