Courseiva

How to Auto-Apply a Sensitivity Label That Encrypts Documents in SharePoint When Credit Card Numbers Are Detected

A compliance officer wants to automatically apply a 'Confidential' sensitivity label to documents in SharePoint Online that contain credit card numbers. The label should be applied when the documents are created or modified. Which Microsoft Purview feature should be configured?

⚠ Common exam trap

It's easy for candidates to confuse a DLP policy's ability to detect sensitive data with the ability to automatically apply a sensitivity label, but DLP policies only trigger alerts or block actions, not label documents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an auto-labeling policy for sensitivity labels

Auto-labeling policies for sensitivity labels in Microsoft Purview can automatically apply a sensitivity label to documents in SharePoint Online based on sensitive information types, such as credit card numbers. This policy scans documents when they are created or modified and applies the label without user intervention, meeting the compliance officer's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an auto-labeling policy for sensitivity labels

    Why this is correct

    Auto-labeling policies for sensitivity labels scan content in Microsoft 365 using sensitive information types and pattern matching to detect data such as personal, financial, or health information. When a match occurs, the policy automatically applies a configured sensitivity label—like 'Confidential'—directly to the file or email. This is the only mechanism here that both analyzes content and applies a sensitivity label, satisfying the compliance officer's requirement. Additionally, auto-labeling policies can run in simulation mode to tune detection before full enforcement.

  • ✗

    Create a retention label policy

    Why it's wrong here

    Retention label policies focus on retention and disposition rules, such as retaining items for a specific number of years or deleting them after a period. They do not classify content based on its sensitivity; instead, they are applied manually or via auto-apply rules based on keywords or trainable classifiers, and they do not assign sensitivity labels. Even if a retention label is added, it does not create the 'Confidential' sensitivity label that the compliance officer needs. Therefore, this option fails to meet the content-scanning and labeling requirement.

  • ✗

    Create a Data Loss Prevention (DLP) policy

    Why it's wrong here

    Data Loss Prevention (DLP) policies in Microsoft Purview monitor and block the sharing or transfer of sensitive data, implementing actions like blocking user access or sending an alert. While DLP uses sensitive information types, its purpose is to enforce protection actions, not to apply metadata like a sensitivity label. The compliance officer needs automatic classification as 'Confidential,' which is the role of an auto-labeling policy, not a DLP policy. DLP can later consume the sensitivity label for enforcement, but it does not create the label.

  • ✗

    Configure a default sensitivity label

    Why it's wrong here

    Configuring a default sensitivity label makes that label the initial selection for all new content in a SharePoint, Teams, or file location, but it is applied without examining the content of each item. It does not distinguish between documents that actually contain confidential or sensitive data; it simply stamps the same label on everything. A user can also override the default setting, which further weakens the guarantee. The requirement calls for content-based scanning to automatically apply a confidential label only when sensitive data is detected, which a default label cannot achieve.

About these practice questions

One of 712 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.