Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Purview complianceEasy

A company is concerned about employees accidentally or maliciously sharing sensitive customer data, such as Social Security Numbers (SSNs) and credit card numbers, with external parties via email and Microsoft Teams. They want to prevent this data from leaving the organization. Which Microsoft Purview solution should be implemented?

  1. ACommunication Compliance
  2. BData Loss Prevention (DLP)
  3. CInsider Risk Management
  4. DInformation Protection (Sensitivity Labels)
Show answer & explanation

Correct answer: B. Data Loss Prevention (DLP)

Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information from being accidentally or maliciously shared outside the organization.

Why the other options are wrong

  • A. Communication Compliance monitors internal communications for policy violations, not primarily preventing external data sharing.
  • C. Insider Risk Management identifies risky user activities, but DLP is the direct control to prevent data exfiltration.
  • D. Sensitivity Labels classify and protect data but don't inherently prevent sharing unless combined with DLP.

Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) prevents sensitive information from being shared inappropriately, either accidentally or maliciously, across various locations and applications.

  • Identifies sensitive information based on SITs.
  • Monitors data in transit and at rest.
  • Can block sharing, alert users, or audit activities.

Memory trick: DLP: Don't Let Pass!

More Implement and manage Microsoft Purview compliance questions