正解:A,C
Microsoft Purview Data Loss Prevention (DLP) is designed to prevent the inadvertent or inappropriate sharing of sensitive data across Microsoft 365 services. Microsoft's guidance states that DLP "helps you discover, monitor, and protect sensitive items across Microsoft 365," and that with DLP policies you can
"identify, monitor, and automatically protect sensitive items in Exchange Online, SharePoint Online, OneDrive for Business, and Microsoft Teams." This directly supports option C, because DLP can detect sensitive info in OneDrive documents and automatically apply protective actions such as blocking external sharing, restricting access, or auditing the event.
DLP also provides end-user coaching through policy tips: "Policy tips are informative notices that appear when users are working with content that contains sensitive info ... to help prevent data loss." When a user is about to send or share sensitive data in violation of policy, these tips surface in Outlook and Office apps (including when files are stored in SharePoint/OneDrive), aligning with option A.
By contrast, enabling disk encryption (e.g., BitLocker) and applying device security baselines are endpoint
/device management tasks handled through Microsoft Intune or Group Policy-not by DLP. Therefore, A and C are the correct tasks you can implement with Microsoft 365 DLP policies.