The correct answer is Data Loss Prevention because the requirement is to stop sensitive data from being pasted into untrusted websites from managed endpoint devices. Microsoft Purview Endpoint DLP extends DLP monitoring and enforcement to Windows and macOS devices and can enforce protective actions on sensitive items when users attempt risky activities. Microsoft states that Endpoint DLP makes endpoint activity visible in Activity Explorer and allows administrators to enforce protective actions through DLP policies. Microsoft also provides a specific Endpoint DLP scenario to restrict users from pasting sensitive content into browser-based applications . That scenario evaluates content at the moment it is pasted and controls sensitive information in real time, regardless of the source. The endpoint DLP settings include browser and domain restrictions for sensitive data, including controls that help prevent leakage by restricting paste actions into browsers. DSPM for AI can surface AI-related data security insights and recommendations, but it is not the direct enforcement solution for blocking paste actions to untrusted websites. Communication Compliance reviews risky communications, and Information Barriers restrict collaboration between groups. Neither is designed to enforce endpoint copy/paste protection. References/topics: Microsoft Purview Data Loss Prevention, Endpoint DLP, browser and domain restrictions, sensitive content paste protection.