nerdexam
Microsoft

MS-102 · Question #121

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named site1. You need to ensure that site1 meets the following requirements: - Retains all data for 10 years…

The correct answer is A. a retention policy B. a data loss prevention (DLP) policy. To retain all data on a SharePoint site for 10 years and prevent external data sharing, you should apply a retention policy and a data loss prevention (DLP) policy to the site.

Submitted by satoshi_tk· Apr 18, 2026Manage compliance by using Microsoft Purview

Question

You have a Microsoft 365 E5 subscription that contains a Microsoft SharePoint site named site1. You need to ensure that site1 meets the following requirements:

  • Retains all data for 10 years
  • Prevents the sharing of data outside the organization

Which two items should you create and apply to site1? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

Options

  • Aa retention policy
  • Ba data loss prevention (DLP) policy
  • Ca retention label policy
  • Da sensitive info type
  • Ea retention label
  • Fa sensitivity label

How the community answered

(31 responses)
  • A
    84% (26)
  • C
    3% (1)
  • D
    3% (1)
  • E
    10% (3)

Why each option

To retain all data on a SharePoint site for 10 years and prevent external data sharing, you should apply a retention policy and a data loss prevention (DLP) policy to the site.

Aa retention policyCorrect

A retention policy can be applied to an entire SharePoint site to ensure all data within it is retained for a specified duration, such as 10 years, meeting the retention requirement.

Ba data loss prevention (DLP) policyCorrect

A data loss prevention (DLP) policy is specifically designed to detect and prevent sensitive information from being shared inappropriately, including outside the organization, directly addressing the requirement to prevent external data sharing.

Ca retention label policy

A retention label policy publishes retention labels, which are applied to individual items, and would not as comprehensively ensure 'all data' on a site is retained as a site-wide retention policy.

Da sensitive info type

A sensitive info type defines patterns of sensitive data (e.g., credit card numbers) that DLP policies detect, but it is a component of a DLP policy, not a policy itself to be applied.

Ea retention label

A retention label is applied to individual documents or emails, providing granular retention, but a site-wide retention policy is more effective for retaining 'all data' on a site.

Fa sensitivity label

A sensitivity label provides classification and protection (like encryption) and can restrict sharing, but a DLP policy is the dedicated and primary tool for preventing data loss through sharing activities.

Concept tested: SharePoint retention policies and DLP policies

Source: https://learn.microsoft.com/en-us/microsoft-365/compliance/retention?view=o365-worldwide

Topics

#Retention Policies#DLP Policies#SharePoint Compliance#Microsoft Purview

Community Discussion

No community discussion yet for this question.

Full MS-102 Practice