MS-102 Manage compliance by using Microsoft Purview Practice Question
A compliance officer needs to ensure that all documents in a SharePoint Online library are automatically labeled with a 'Confidential' sensitivity label if they contain at least one of a predefined list of sensitive information types such as credit card numbers or social security numbers. Users should be able to override the label with a business justification. Which Microsoft Purview feature should the officer configure?
⚠ Common exam trap
Microsoft often tests the distinction between auto-labeling policies (which apply sensitivity labels automatically) and DLP policies (which enforce actions like blocking or alerting), causing candidates to confuse the two because both can detect sensitive information types.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto-labeling policy for SharePoint Online
Auto-labeling policies in Microsoft Purview can automatically apply sensitivity labels to documents in SharePoint Online based on the detection of sensitive information types (e.g., credit card numbers, SSNs). This policy supports user override with a business justification, meeting the compliance officer's requirement exactly. Manual classification (Option D) would not automate the labeling, and DLP policies (Option B) focus on preventing data loss, not applying sensitivity labels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Auto-labeling policy for SharePoint Online
Why this is correct
Auto-labeling policies in the Microsoft Purview compliance portal let you define conditions—such as sensitive info types, trainable classifiers, or custom keywords—that trigger automatic application of a sensitivity label to matching SharePoint Online documents. Once created, the policy runs continuously, and in enforcement mode it labels every existing and new file that meets the criteria, providing a scalable, centralized solution. You can also require users to justify lowering or removing the label, balancing automation with user oversight. This directly satisfies the need to ensure all relevant documents are classified automatically.
- ✗
Data Loss Prevention (DLP) policy
Why it's wrong here
DLP policies primarily monitor and control outgoing and shared content by detecting sensitive data patterns and applying protective actions like blocking access or sending alerts, but they do not apply sensitivity labels to documents. Their role is enforcement of data-handling rules, not classification; even if a DLP rule triggers, the file remains unlabeled. Consequently, DLP alone cannot deliver the required sensitivity classification across all documents.
- ✗
Retention label policy
Why it's wrong here
Retention labels are designed to manage lifecycle governance, allowing you to specify how long items are kept and what disposition action occurs afterward, such as review or deletion. They do not carry the protection conventions of sensitivity labels—like encryption or permissions—nor do they indicate the organization's classification schema. Applying a retention label would not meet the compliance officer's need for sensitivity labeling, because it addresses a completely different compliance dimension.
- ✗
Sensitivity label with manual classification
Why it's wrong here
Manual classification depends on users to actively apply a sensitivity label to each document, making it inconsistent and prone to omission; there is no automatic mechanism to guarantee every file gets labeled. While labels can be applied individually or via PowerShell, this approach fails the requirement that all documents be classified without relying on user compliance. Additionally, users could misapply or skip labels entirely, leaving content unprotected.
Go deeper
Related to this question
Learn chapter
Microsoft 365 Tenant Setup
Key term
SharePoint Online
SharePoint Online is a cloud-based collaboration platform from Microsoft that lets teams create, store, organize, and share content securely from anywhere.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every MS-102 question from scratch — 241 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.