An administrator wants protection that classifies an item and then keeps controls such as encryption attached to the file even after it leaves the organisation, while separately blocking risky sharing actions in real time. Which TWO Microsoft Purview capabilities together deliver this, one for each requirement? Select TWO.
- ASensitivity labels, which classify content and embed protection that travels with the file Correct
- BRetention policies, which decide how long content is kept or when it is deleted
- CRecords management, which declares items as records and disposes of them on a schedule
- DData loss prevention, which detects and blocks inappropriate sharing of sensitive items Correct
- EAudit, which records the user and admin activity for later review
Why A is correct: Sensitivity labels classify and apply persistent protection such as encryption that stays with the file wherever it goes.
Why B is wrong: Retention governs lifecycle duration, not classification or real-time sharing control, so it answers neither requirement.
Why C is wrong: Records management handles regulatory record declaration and disposal, not portable encryption or sharing blocks.
Why D is correct: DLP policies inspect content and can block or warn on risky sharing in real time across Microsoft 365 locations.
Why E is wrong: Audit logs activity after the fact; it neither protects files nor prevents the sharing action from happening.