Courseiva
Manage compliance by using Microsoft PurvieweasyMultiple ChoiceObjective-mapped

MS-102 Manage compliance by using Microsoft Purview Practice Question

A compliance officer needs to ensure that all documents in a SharePoint Online library are automatically labeled with a 'Confidential' sensitivity label if they contain at least one of a predefined list of sensitive information types such as credit card numbers or social security numbers. Users should be able to override the label with a business justification. Which Microsoft Purview feature should the officer configure?

⚠ Common exam trap

Microsoft often tests the distinction between auto-labeling policies (which apply sensitivity labels automatically) and DLP policies (which enforce actions like blocking or alerting), causing candidates to confuse the two because both can detect sensitive information types.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Auto-labeling policy for SharePoint Online

Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on the detection of sensitive information types (e.g., credit card numbers, SSNs). This policy supports user override with a business justification, meeting the compliance officer's requirement exactly. Manual classification (Option D) would not automate the labeling, and DLP policies (Option B) focus on preventing data loss, not applying sensitivity labels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Auto-labeling policy for SharePoint Online

    Why this is correct

    Auto-labeling policies in the Microsoft Purview compliance portal let you define conditions—such as sensitive info types, trainable classifiers, or custom keywords—that trigger automatic application of a sensitivity label to matching SharePoint Online documents. Once created, the policy runs continuously, and in enforcement mode it labels every existing and new file that meets the criteria, providing a scalable, centralized solution. You can also require users to justify lowering or removing the label, balancing automation with user oversight. This directly satisfies the need to ensure all relevant documents are classified automatically.

  • Data Loss Prevention (DLP) policy

    Why it's wrong here

    DLP policies primarily monitor and control outgoing and shared content by detecting sensitive data patterns and applying protective actions like blocking access or sending alerts, but they do not apply sensitivity labels to documents. Their role is enforcement of data-handling rules, not classification; even if a DLP rule triggers, the file remains unlabeled. Consequently, DLP alone cannot deliver the required sensitivity classification across all documents.

  • Retention label policy

    Why it's wrong here

    Retention labels are designed to manage lifecycle governance, allowing you to specify how long items are kept and what disposition action occurs afterward, such as review or deletion. They do not carry the protection conventions of sensitivity labels—like encryption or permissions—nor do they indicate the organization's classification schema. Applying a retention label would not meet the compliance officer's need for sensitivity labeling, because it addresses a completely different compliance dimension.

  • Sensitivity label with manual classification

    Why it's wrong here

    Manual classification depends on users to actively apply a sensitivity label to each document, making it inconsistent and prone to omission; there is no automatic mechanism to guarantee every file gets labeled. While labels can be applied individually or via PowerShell, this approach fails the requirement that all documents be classified without relying on user compliance. Additionally, users could misapply or skip labels entirely, leaving content unprotected.

About these practice questions

Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.