SC-900 DLP Policy Override Practice Question
Your organization is implementing a data loss prevention (DLP) policy to prevent sensitive data from being shared via email. Users in the finance department need to send financial reports to external auditors. What should you configure?
⚠ Common exam trap
Candidates often confuse sensitivity labels with DLP actions. While labels can enforce encryption, DLP policies directly control data sharing with overrides.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a DLP policy with an override option allowing users to justify the sharing
Configuring a DLP policy with an override option allows finance users to share financial reports with external auditors while still providing a justification, ensuring legitimate business needs are met without blocking all external sharing. Option A is incorrect because DLP policies use allow lists for exceptions, but an override with justification is more appropriate for this scenario. Option C is incorrect because sensitivity labels can encrypt emails, but they do not replace the need for a DLP policy with override for specific external sharing. Option D is incorrect because a block action would prevent all external sharing, which is not suitable for legitimate business needs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the auditors' domains to a DLP allow list
Why it's wrong here
Adding auditors' domains to a DLP allow list is not a standard or effective configuration within Microsoft Purview Data Loss Prevention. DLP policies primarily operate by inspecting content for sensitive information types and applying actions based on policy rules, rather than relying on domain-based whitelisting to bypass these content-centric controls. While mail flow rules (transport rules) in Exchange Online can utilize sender/recipient domain allow lists for email routing or processing, DLP policies are designed for granular content protection and do not typically offer a direct 'allow list' mechanism for policy exceptions based solely on external domains.
- ✓
Configure a DLP policy with an override option allowing users to justify the sharing
Why this is correct
Configuring a DLP policy with an override option that allows users to justify sharing is the most appropriate solution for balancing security with legitimate business needs. This feature enables organizations to enforce strong data protection while providing a controlled mechanism for users to temporarily bypass a policy when a valid business reason exists, such as sharing specific audit-related documents externally. The justification provided by the user is logged, creating an essential audit trail for compliance and review, ensuring accountability without completely blocking necessary collaboration.
- ✗
Assign a sensitivity label that automatically encrypts the email
Why it's wrong here
Assigning a sensitivity label that automatically encrypts the email primarily focuses on data classification and protection, ensuring that the content remains secure even if it leaves the organization's control. While sensitivity labels are crucial for data governance and can enforce encryption, they do not inherently provide the 'override with justification' capability that a DLP policy offers for user-driven exceptions to sharing rules. Their function is to apply persistent protection based on content classification, not to manage conditional sharing exceptions with an audit trail for user justification.
- ✗
Configure a DLP policy with a block action for all external sharing
Why it's wrong here
Configuring a DLP policy with a block action for all external sharing would be overly restrictive and detrimental to legitimate business operations. While blocking is a powerful DLP action, applying it universally would prevent necessary collaboration with external partners, customers, and, in this scenario, auditors, hindering productivity and operational efficiency. Effective DLP strategies require granularity, allowing for specific exceptions or user overrides with justification rather than implementing a blanket ban that impedes essential business processes.
Go deeper
Related to this question
Learn chapter
Conditional Access Policies
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.