Classify Sensitive Data in Azure Purview
Your organization uses Azure Purview for data governance. You need to ensure that sensitive data is properly classified and that access to it is monitored. Which THREE actions should you take? (Choose three.)
Quick Answer
The correct answer is to set up automated scanning in Azure Purview, apply sensitivity labels, and use Microsoft Defender for Cloud Apps to monitor access. Automated scanning is the foundational step to classify sensitive data in Azure Purview, as it systematically crawls your data sources—such as Azure SQL Database or Azure Data Lake Storage—to detect patterns like credit card numbers or social security numbers using built-in classification rules. Applying sensitivity labels then tags that classified data with governance policies, while Defender for Cloud Apps provides the monitoring layer by tracking user access patterns and generating alerts for anomalous behavior. On the DP-203 exam, this scenario tests your understanding of Purview’s role in the data governance lifecycle, often paired with a distractor like Azure Policy (which enforces compliance rules but does not classify or monitor data access) or Azure Sentinel (which handles security incident response, not classification). A common trap is confusing Purview’s classification with Azure Information Protection; remember that Purview discovers and labels data at scale, while Defender for Cloud Apps watches who touches it. Memory tip: “Scan, Label, Watch” — the three pillars for sensitive data governance in Purview.
⚠ Common exam trap
DP-203 often tests the boundary between governance tools — candidates confuse Azure Policy (resource configuration enforcement) and Azure Sentinel (SIEM) with Purview's actual classification and monitoring capabilities, picking them as if they performed data classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create custom sensitivity labels in Microsoft Purview Information Protection and apply them to data sources.
Option C is correct because Microsoft Purview Information Protection sensitivity labels (created in the compliance portal) are the mechanism for tagging data with sensitivity classifications, and Purview can extend these labels to data sources such as Azure SQL, Storage, and Synapse for consistent classification. Option D is correct because integrating Azure Purview with Microsoft Defender for Cloud Apps enables monitoring of user access and activities on sensitive data that Purview has classified, providing anomaly detection and governance over access. Option E is correct because Azure Purview's automated scanning uses built-in and custom classification rules to discover and classify sensitive data (for example, credit card or national ID patterns) across registered sources, which is the core way to ensure data is properly classified. Option A is not correct because Azure Policy initiatives enforce configuration and compliance states on resources; they do not perform data classification of the contents within storage accounts. Option B is not correct because Azure Sentinel is a SIEM/SOAR solution for security analytics and threat detection, not a data classification engine for ingested data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define Azure Policy initiatives to enforce classification on all storage accounts.
Why it's wrong here
Azure Policy governs resource configuration and compliance, not the classification of data content; it cannot label columns in the Purview catalog. It is tempting because policy initiatives do enforce governance controls across storage accounts, and it would be correct when the requirement is preventing non-compliant resource deployments.
- ✗
Use Azure Sentinel to classify data as it is ingested.
Why it's wrong here
Microsoft Sentinel is a SIEM that detects and investigates threats from logs; it does not scan and classify data assets. It is tempting because Sentinel does monitor access events, and it would be the right choice when the requirement is correlating security alerts rather than applying sensitivity labels in Purview.
- ✓
Create custom sensitivity labels in Microsoft Purview Information Protection and apply them to data sources.
Why this is correct
Custom sensitivity labels in Microsoft Purview Information Protection extend classification beyond built-in types, letting you tag organisation-specific sensitive data and apply those labels across registered data sources. This satisfies the stem's requirement that sensitive data be properly classified, while label usage feeds Purview's monitoring of access to labelled assets.
- ✓
Integrate Azure Purview with Microsoft Defender for Cloud Apps to monitor access to sensitive data.
Why this is correct
Defender for Cloud Apps ingests Purview classification labels and audit logs, surfacing anomalous access to sensitive assets in its activity policies. This satisfies the monitoring half of the requirement, which Purview's own scanning alone cannot deliver.
- ✓
Set up automated scanning in Azure Purview to discover and classify sensitive data.
Why this is correct
Automated scanning lets Microsoft Purview crawl your data sources, apply built-in and custom classification rules, and label assets containing sensitive information in the Data Map. This directly satisfies the stem's requirement to classify sensitive data, since classification depends on scan-discovered assets rather than manual registration alone.
Go deeper
Related to this question
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DP-203
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Azure Purview for data governance. You need to automatically scan an Azure Data Lake Storage Gen2 account and classify sensitive data such as credit card numbers and social security numbers. What should you configure?
medium- A.Azure Information Protection (AIP) scanner
- B.Microsoft Defender for Cloud
- ✓ C.A new scan rule set in Purview with classification rules for sensitive data types
- D.Azure Policy with built-in guest configuration
Why C: In Azure Purview, to automatically scan and classify sensitive data, you create a scan rule set that includes classification rules for the specific sensitive data types (e.g., credit card numbers, SSNs). The scan rule set is applied to the scan of the Azure Data Lake Storage Gen2 account, and Purview uses built-in or custom classification rules to identify and tag sensitive data.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.