Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Purview complianceMedium

A financial institution needs to implement a policy to ensure that no sensitive client financial data (e.g., account numbers, credit card numbers) can be copied from their internal SharePoint sites to unmanaged personal devices or shared with unauthorized external cloud storage services. The policy should also prevent printing of such data. Which Microsoft Purview feature is specifically designed to prevent these types of data exfiltration scenarios?

  1. AInsider Risk Management (IRM)
  2. BInformation Barriers (IB)
  3. CCommunication Compliance policies
  4. DData Loss Prevention (DLP) policies
Show answer & explanation

Correct answer: D. Data Loss Prevention (DLP) policies

Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and protect sensitive information by preventing it from being accidentally or maliciously shared, copied, or printed to unauthorized locations or devices.

Why the other options are wrong

  • A. IRM detects broad risky user behaviors, but DLP is specifically for preventing sensitive data exfiltration based on content and destination.
  • B. Information Barriers prevent communication between specific user groups, not data exfiltration.
  • C. Communication Compliance policies monitor communications for policy violations, not to prevent data exfiltration from documents.

Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) policies identify, monitor, and automatically protect sensitive information across Microsoft 365 services and endpoints, preventing its unauthorized sharing, transfer, or use.

  • Detects sensitive information types.
  • Prevents data exfiltration to unauthorized locations/devices.
  • Can block, notify, or audit actions.

Memory trick: DLP stops data from flying, keeping secrets from prying.

More Implement and manage Microsoft Purview compliance questions