Classify Sensitive Data in Azure Purview
Your organization uses Azure Purview for data governance. You need to ensure that sensitive data is properly classified and that access to it is monitored. Which THREE actions should you take? (Choose three.)
Quick Answer
The correct answer is to set up automated scanning in Azure Purview, apply sensitivity labels, and use Microsoft Defender for Cloud Apps to monitor access. Automated scanning is the foundational step to classify sensitive data in Azure Purview, as it systematically crawls your data sources—such as Azure SQL Database or Azure Data Lake Storage—to detect patterns like credit card numbers or social security numbers using built-in classification rules. Applying sensitivity labels then tags that classified data with governance policies, while Defender for Cloud Apps provides the monitoring layer by tracking user access patterns and generating alerts for anomalous behavior. On the DP-203 exam, this scenario tests your understanding of Purview’s role in the data governance lifecycle, often paired with a distractor like Azure Policy (which enforces compliance rules but does not classify or monitor data access) or Azure Sentinel (which handles security incident response, not classification). A common trap is confusing Purview’s classification with Azure Information Protection; remember that Purview discovers and labels data at scale, while Defender for Cloud Apps watches who touches it. Memory tip: “Scan, Label, Watch” — the three pillars for sensitive data governance in Purview.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create custom sensitivity labels in Microsoft Purview Information Protection and apply them to data sources.
The correct answers are C, D, and E. Creating custom sensitivity labels in Microsoft Purview Information Protection (option C) allows data to be tagged with sensitivity levels. Integrating Azure Purview with Microsoft Defender for Cloud Apps (option D) provides monitoring of access to sensitive data. Automated scanning in Azure Purview (option E) discovers and classifies data automatically. Option A is incorrect because Azure Policy is used for governance and compliance enforcement, not for data classification or monitoring. Option B is incorrect because Azure Sentinel is a security information and event management (SIEM) solution, not a data classification tool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define Azure Policy initiatives to enforce classification on all storage accounts.
Why it's wrong here
Incorrect: Azure Policy can enforce tags but not data classification within storage.
- ✗
Use Azure Sentinel to classify data as it is ingested.
Why it's wrong here
Incorrect: Azure Sentinel is for security information and event management (SIEM), not data classification.
- ✓
Create custom sensitivity labels in Microsoft Purview Information Protection and apply them to data sources.
Why this is correct
Correct: Sensitivity labels help enforce protection policies and are used in monitoring.
- ✓
Integrate Azure Purview with Microsoft Defender for Cloud Apps to monitor access to sensitive data.
Why this is correct
Correct: Defender for Cloud Apps can detect anomalous access to sensitive data labeled by Purview.
- ✓
Set up automated scanning in Azure Purview to discover and classify sensitive data.
Why this is correct
Correct: Automated scans identify sensitive data patterns and apply classifications.
Go deeper
Related to this question
About these practice questions
One of 760 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DP-203
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Azure Purview for data governance. You need to automatically scan an Azure Data Lake Storage Gen2 account and classify sensitive data such as credit card numbers and social security numbers. What should you configure?
medium- A.Azure Information Protection (AIP) scanner
- B.Microsoft Defender for Cloud
- ✓ C.A new scan rule set in Purview with classification rules for sensitive data types
- D.Azure Policy with built-in guest configuration
Why C: A new scan rule set in Purview with classification rules for sensitive data types. Purview allows you to create custom scan rule sets that include classification rules for sensitive data types like credit card numbers and social security numbers. When you run a scan on Azure Data Lake Storage Gen2, it uses these rules to automatically detect and classify the sensitive data. Option A is incorrect because Azure Information Protection (AIP) scanner is for classifying and protecting files in on-premises file shares and SharePoint, not for scanning Azure Data Lake Storage. Option B is incorrect because Microsoft Defender for Cloud is for security posture management and threat detection, not data classification. Option D is incorrect because Azure Policy with guest configuration is for auditing and enforcing compliance settings on virtual machines, not for data classification in storage.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.