SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Your organization uses Microsoft Purview to enforce data loss prevention (DLP) policies. You need to ensure that when a user attempts to share a document containing credit card numbers via email, the document is blocked and the user receives a policy tip. What should you configure in the DLP policy?
⚠ Common exam trap
Candidates often assume that a policy tip requires 'Block with override', but the standard 'Block' action already blocks sharing and displays a policy tip. 'Block with override' is only needed when users must be able to bypass the block.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the action to 'Block'
The requirement is to block sharing of a document containing credit card numbers via email and show the user a policy tip. In Microsoft Purview DLP, the 'Block' action prevents the sensitive data from being shared and displays a policy tip to the user. 'Block with override' would additionally allow the user to bypass the block with a justification or false positive, which is not required here. Therefore, 'Block' is the correct action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the action to 'Audit only'
Why it's wrong here
Set the action to 'Audit only' [wrong]
- ✗
Set the action to 'Block with override'
Why it's wrong here
'Block with override' prevents the email from being sent while presenting the user a policy tip explaining the violation and offering an override with justification, satisfying both the blocking and user-notification requirements for credit card content.
- ✓
Set the action to 'Block'
Why this is correct
Set the action to 'Block' [wrong]
- ✗
Set the action to 'Notify only'
Why it's wrong here
Set the action to 'Notify only' [wrong]
Go deeper
Related to this question
Learn chapter
Session and Access Policies in Defender for Cloud Apps
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.