DP-203 Practice Question: Secure, monitor, and optimize data storage and data processing
Your organization uses Microsoft Purview to catalog data assets. You need to ensure that sensitive data such as credit card numbers are automatically detected and labeled. Which Purview feature should you configure?
⚠ Common exam trap
The trap is confusing classification with labeling or with policy enforcement; Purview scans and classifies sensitive data, but labels are applied through auto-labeling policies or MIP, not by Azure Policy or the catalog search.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a scan rule set with built-in classification rules for sensitive data types.
Microsoft Purview automatically detects sensitive data types such as credit card numbers through classification rules that are part of a scan rule set. When you configure a scan rule set and include the built-in system classification rules (e.g., Credit Card Number, which matches patterns like 16-digit numbers with Luhn validation), Purview applies those classifications during scans and can then apply sensitivity labels. This is the native mechanism for automated sensitive data detection and labeling in Purview.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an Azure Policy to enforce tagging.
Why it's wrong here
Azure Policy enforces resource governance, such as requiring tags or allowed SKUs, and cannot inspect data contents for credit card patterns. It is tempting because it governs compliance across Azure resources, and would be correct for enforcing organisational standards like mandatory tags or permitted regions, not for detecting and labelling sensitive data.
- ✓
Configure a scan rule set with built-in classification rules for sensitive data types.
Why this is correct
Scan rule sets bundle classification rules, including built-in system rules for credit card and other sensitive types, which Purview applies during scans to detect and label matching data automatically. This satisfies the automatic detection requirement in the stem.
- ✗
Enable the Data Catalog self-service search.
Why it's wrong here
Self-service search only surfaces assets already registered in the catalog; it performs no classification or labelling of credit card numbers. It is tempting because it governs how analysts discover and request access to known assets, which would be the right configuration when the requirement is catalog discoverability rather than automated sensitive-data detection.
- ✗
Enable Microsoft Information Protection for the data sources.
Why it's wrong here
Microsoft Information Protection applies sensitivity labels to files and emails, not to catalogued data assets in Microsoft Purview. It is tempting because MIP does classify and label sensitive content, and would be correct for protecting documents in SharePoint, Exchange or Teams — but the scenario requires classification rules that scan data sources and tag assets during cataloguing.
About these practice questions
One of 509 original DP-203 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DP-203
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are using Azure Purview to scan an Azure Data Lake Storage Gen2 account. After scanning, you notice that some files are not classified. What is the most likely reason?
medium- A.The storage account is not registered in Purview
- B.The files are in Parquet format
- C.The classification rules are disabled
- ✓ D.The file types are not included in the scan rule set
Why D: Azure Purview scans use a scan rule set that defines which file types are included for classification. If a file's extension or type is not listed in the rule set, Purview skips classification for that file even though the scan completes. This is the most common reason specific files remain unclassified after a successful scan.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-203 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-203 exam.