What Tool Reviews DLP Policy Matches in Microsoft 365?

Answer Correct answer: B — Use Activity explorer to review Microsoft Purview DLP policy matches across Exchange, SharePoint, OneDrive, Teams, and endpoints.

You have a Microsoft 365 tenant that has data loss prevention (DLP) policies. You need to review DLP policy matches for the tenant. What should you use?

  1. Content explorer
  2. Activity explorer Correct Answer
  3. Compliance Manager
  4. records management events

Community Votes

B
75%
A
25%

75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the difference between Data Classification content inspection and DLP policy match event review, with Content explorer as the common trap.

This SC-400 question tests how to review Microsoft 365 DLP policy matches. The correct tool is Activity explorer in Microsoft Purview, not Content explorer or Compliance Manager.

Choosing Content explorer (A) because it sounds like the place to inspect sensitive data; however, DLP policy match events are surfaced in Activity explorer.

Community Discussion (6 comments)

TC1Labs 👍 1
Activity Explorer is the right answer
SDiwan 👍 1 Selected: B
Activity Explorer is the right answer. Content Explorer is Data Classification feature and not DLP feature.
emartiy 👍 4 Selected: B
Correct- B- In addition, using Endpoint data loss prevention (DLP), Activity explorer gathers DLP policy matches events from Exchange, SharePoint, OneDrive, Teams Chat and Channel, on-premises SharePoint folders and libraries, on-premises file shares, and devices running Windows 10, Windows 11, and any of the three most recent major macOS versions. Ref: https://learn.microsoft.com/en-us/purview/data-classification-activity-explorer Fouces to words between ( )
Ruslan23 👍 2 Selected: A
To review DLP policy matches for the tenant, you should use the Content Explorer (Option A). The Content Explorer in the Microsoft 365 compliance center allows you to view and manage sensitive information that matches your Data Loss Prevention (DLP) policies. It provides insights into where sensitive information resides in your organization and helps you manage risks associated with this data. Please note that appropriate permissions are required to access the Content Explorer. - Copilot -
Kodoi 👍 1 Selected: B
In addition, using Endpoint data loss prevention (DLP), Activity explorer gathers DLP policy matches events from Exchange, SharePoint, OneDrive, Teams Chat and Channel, on-premises SharePoint folders and libraries, on-premises file shares, and devices running Windows 10, Windows 11, and any of the three most recent major macOS versions. https://learn.microsoft.com/en-us/purview/data-classification-activity-explorer
Tzu_Hsien 👍 1
I think it is (A)content explorer which can Investigating incidents related to data loss, security, or compliance.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Activity explorer in Microsoft Purview is the reporting surface for user and admin activities, including Data Loss Prevention (DLP) rule matches. It aggregates DLP policy match events from Exchange, SharePoint, OneDrive, Teams chat and channel, on-premises SharePoint, on-premises file shares, and Windows/macOS endpoint devices. When an SC-400 question asks to review DLP policy matches for a tenant, the expected tool is Activity explorer because it shows which rule matched, what action was taken, and where the event occurred. Content explorer and Compliance Manager serve different purposes: content classification exploration and compliance posture assessment, respectively. Therefore B is the correct answer.

Why the Other Options Are Wrong

A. Content explorer is part of Data Classification and shows files, emails, and other items that contain sensitive information types or sensitivity labels. It helps answer “where is sensitive content?”, not “which DLP policy matched?”. C. Compliance Manager tracks regulatory compliance assessments and improvement actions; it does not list individual DLP policy match events. D. records management events relate to retention labels, file plan descriptors, and disposition reviews, not DLP rule matches. Only Activity explorer provides the DLP policy match review this question requires.

Community Comment Notes

Several learners correctly point to Activity explorer. As emartiy noted, “Activity explorer gathers DLP policy matches events” from Exchange, SharePoint, OneDrive, Teams, on-premises locations, and endpoint devices. SDiwan added that “Content Explorer is Data Classification feature and not DLP feature,” which directly addresses the main distractor. Ruslan23 and Tzu_Hsien argued for Content explorer because it can help investigate sensitive data incidents, but that confuses content inspection with DLP policy match reporting. TC1Labs simply concluded “Activity Explorer is the right answer,” matching the Microsoft Purview workflow for reviewing DLP matches.

Official Reference

Exam Strategy

Use the SC-400 keyword test: “policy matches” points to Activity explorer or DLP alerts, while “sensitive content” points to Content explorer. If the question asks where to review matches, choose Activity explorer; if it asks where to inspect what data is stored, choose Content explorer.

Frequently Asked Questions

Why is Content explorer wrong for reviewing DLP policy matches?

Content explorer shows sensitive content found by classification, not DLP rule match events. Activity explorer is the tool that records DLP policy matches across workloads.

Does Activity explorer show DLP matches from endpoint devices?

Yes. Activity explorer includes endpoint DLP matches from Windows 10/11 and recent macOS devices, plus Exchange, SharePoint, OneDrive, Teams, and on-premises sources.

Related Analysis

← Back to SC-400 Study Guide