← All SC-900 Flashcard Decks

Microsoft Purview Data Loss Prevention Flashcards

6 cards from real SC-900 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Microsoft Purview Data Loss Prevention flashcards as text
  1. What is the primary goal of a Microsoft Purview Data Loss Prevention (DLP) policy?

    Answer: To prevent the unintentional sharing of sensitive information

    DLP policies are designed to identify, monitor, and automatically protect sensitive information across Microsoft 365 services. Their main purpose is to prevent the accidental or inappropriate sharing of this data with people who shouldn't have it, both inside and outside the organization.

  2. A DLP policy is configured to detect credit card numbers in emails. What component of the DLP policy identifies the pattern for a credit card number?

    Answer: A Sensitive Information Type (SIT)

    Sensitive Information Types (SITs) are pattern-based classifiers that detect sensitive information like financial data, PII, and health information. DLP policies use SITs as a condition to identify content that needs to be protected.

  3. When creating a DLP policy, you must specify where it applies. Which of the following are valid locations for a DLP policy?

    Answer: Exchange Online, SharePoint Online, and Microsoft Teams

    DLP policies can be scoped to protect data across various Microsoft 365 services. This includes Exchange Online for emails, SharePoint Online and OneDrive for Business for files, and Microsoft Teams for chats and channel messages.

  4. A user tries to send an email containing sensitive data, and a 'policy tip' appears warning them of a potential policy violation. What part of the DLP policy is responsible for this?

    Answer: The user notifications and policy tips setting

    DLP policies consist of conditions, actions, and user notifications. Policy tips are a form of user notification designed to educate users about compliance policies in real-time and help them avoid violations before they happen.

  5. An administrator wants to implement a new DLP policy but wants to evaluate its impact before enforcing it. Which mode should they use?

    Answer: Test it out with policy tips

    DLP policies can be run in different modes. 'Test it out first' or 'Test it out with policy tips' allows the policy to run and generate audit logs and alerts without actually blocking any user actions, enabling administrators to fine-tune the policy before full enforcement.

  6. What is a key difference between a DLP policy and a sensitivity label?

    Answer: DLP policies prevent data exfiltration from locations, while sensitivity labels classify and protect the data itself.

    While both are part of information protection, their focus is different. Sensitivity labels classify and apply persistent protection (like encryption) to the data itself, wherever it goes. DLP policies focus on the context of data sharing, preventing data exfiltration from specific locations like email or Teams based on rules.