How to Use Microsoft Purview Data Classification to Discover Sensitive Data Without Applying Protection
A compliance officer needs to discover and review documents in SharePoint Online that contain driver's license numbers, but the officer does not want to apply any protection actions automatically. Which Microsoft Purview solution should be used?
Quick Answer
The answer is Microsoft Purview Data Classification. This solution is correct because it enables you to discover sensitive data, such as driver’s license numbers in SharePoint Online, by scanning content for sensitive information types and optionally applying labels, but it does not enforce protection actions like encryption or access restrictions unless you explicitly configure an auto-labeling policy with protection. On the MS-102 exam, this scenario tests your ability to distinguish between discovery-focused tools and enforcement-focused tools like Data Loss Prevention or sensitivity labels; a common trap is assuming that any labeling automatically triggers protection, but Data Classification is purely for identification and review unless you add a policy. Remember the key distinction: Data Classification is for “find and see,” not “block and lock.” A useful memory tip is to think of Data Classification as a flashlight that reveals sensitive data without locking the door behind it.
⚠ Common exam trap
Microsoft often tests the distinction between discovery-only solutions (Data Classification) and enforcement solutions (Information Protection), so the trap here is assuming that any sensitive data solution must automatically apply protection, leading candidates to choose Information Protection instead of Data Classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Classification
Data Classification in Microsoft Purview allows you to identify and label sensitive content, such as driver's license numbers, across SharePoint Online without automatically applying protection actions like encryption or access restrictions. This solution is ideal for discovery and review scenarios where the compliance officer needs to locate sensitive data but does not want to enforce automated policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data Lifecycle Management
Why it's wrong here
Data Lifecycle Management manages retention and disposition, not content discovery and review.
- ✗
Records Management
Why it's wrong here
Records Management is used to declare items as records and apply retention, not for discovery without protection.
- ✓
Data Classification
Why this is correct
Data Classification includes Content Explorer, which enables browsing and reviewing items containing sensitive info without applying protection.
- ✗
Information Protection
Why it's wrong here
Information Protection labels can be auto-applied and may apply encryption; it is not designed for passive discovery only.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on MS-102
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A compliance officer needs to identify documents in SharePoint Online that contain credit card numbers. The officer wants a solution that can automatically detect and mark these documents for further review without applying any protection actions. Which Microsoft Purview solution should the officer use?
easy- A.Microsoft Purview Data Loss Prevention (DLP) policy
- ✓ B.Microsoft Purview Information Protection sensitivity label auto-labeling
- C.Microsoft Purview eDiscovery content search
- D.Microsoft Purview Records Management retention label
Why B: Microsoft Purview Information Protection sensitivity label auto-labeling can automatically detect sensitive information types such as credit card numbers in SharePoint Online and apply a sensitivity label to mark the document for review. The label can be configured with no protection actions (e.g., no encryption or access restrictions), satisfying the requirement of detection and marking without protection. DLP policies are more focused on preventing data loss via actions like blocking or alerting, and do not 'mark' documents.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.