An organization uses Microsoft Purview to classify data processed by Azure OpenAI. A security engineer must configure a DLP policy that prevents Azure OpenAI API responses containing credit card numbers from being returned to the calling application. Which Microsoft Purview capability supports this scenario?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — c is correct because Microsoft Purview DLP policies can be scoped to Azure AI services including Azure OpenAI, enabling detection of sensitive information types such as credit card numbers in AI model prompts and responses, and can be configured to block or alert when such content is detected. B is incorrect because while the AI Hub provides visibility into AI interactions, the active enforcement mechanism is the DLP policy.
Full explanation below image
Full Explanation
C is correct because Microsoft Purview DLP policies can be scoped to Azure AI services including Azure OpenAI, enabling detection of sensitive information types such as credit card numbers in AI model prompts and responses, and can be configured to block or alert when such content is detected. B is incorrect because while the AI Hub provides visibility into AI interactions, the active enforcement mechanism is the DLP policy. A is incorrect because endpoint DLP monitors browser-based data actions, not server-side Azure OpenAI API calls. D is incorrect because Communication Compliance is designed for human communications review, not API response content enforcement.