What Tool Reviews DLP Policy Matches in Microsoft 365?
You have a Microsoft 365 tenant that has data loss prevention (DLP) policies. You need to review DLP policy matches for the tenant. What should you use?
Community Votes
75% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the difference between Data Classification content inspection and DLP policy match event review, with Content explorer as the common trap.
This SC-400 question tests how to review Microsoft 365 DLP policy matches. The correct tool is Activity explorer in Microsoft Purview, not Content explorer or Compliance Manager.
Choosing Content explorer (A) because it sounds like the place to inspect sensitive data; however, DLP policy match events are surfaced in Activity explorer.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Activity explorer in Microsoft Purview is the reporting surface for user and admin activities, including Data Loss Prevention (DLP) rule matches. It aggregates DLP policy match events from Exchange, SharePoint, OneDrive, Teams chat and channel, on-premises SharePoint, on-premises file shares, and Windows/macOS endpoint devices. When an SC-400 question asks to review DLP policy matches for a tenant, the expected tool is Activity explorer because it shows which rule matched, what action was taken, and where the event occurred. Content explorer and Compliance Manager serve different purposes: content classification exploration and compliance posture assessment, respectively. Therefore B is the correct answer.Why the Other Options Are Wrong
A. Content explorer is part of Data Classification and shows files, emails, and other items that contain sensitive information types or sensitivity labels. It helps answer “where is sensitive content?”, not “which DLP policy matched?”. C. Compliance Manager tracks regulatory compliance assessments and improvement actions; it does not list individual DLP policy match events. D. records management events relate to retention labels, file plan descriptors, and disposition reviews, not DLP rule matches. Only Activity explorer provides the DLP policy match review this question requires.Community Comment Notes
Several learners correctly point to Activity explorer. As emartiy noted, “Activity explorer gathers DLP policy matches events” from Exchange, SharePoint, OneDrive, Teams, on-premises locations, and endpoint devices. SDiwan added that “Content Explorer is Data Classification feature and not DLP feature,” which directly addresses the main distractor. Ruslan23 and Tzu_Hsien argued for Content explorer because it can help investigate sensitive data incidents, but that confuses content inspection with DLP policy match reporting. TC1Labs simply concluded “Activity Explorer is the right answer,” matching the Microsoft Purview workflow for reviewing DLP matches.Official Reference
Exam Strategy
Use the SC-400 keyword test: “policy matches” points to Activity explorer or DLP alerts, while “sensitive content” points to Content explorer. If the question asks where to review matches, choose Activity explorer; if it asks where to inspect what data is stored, choose Content explorer.
Frequently Asked Questions
Why is Content explorer wrong for reviewing DLP policy matches?
Content explorer shows sensitive content found by classification, not DLP rule match events. Activity explorer is the tool that records DLP policy matches across workloads.
Does Activity explorer show DLP matches from endpoint devices?
Yes. Activity explorer includes endpoint DLP matches from Windows 10/11 and recent macOS devices, plus Exchange, SharePoint, OneDrive, Teams, and on-premises sources.