Courseiva
Manage compliance by using Microsoft PurviewmediumMultiple SelectObjective-mapped

MS-102 Manage compliance by using Microsoft Purview Practice Question

A global administrator at Fabrikam Inc. plans to implement Microsoft Purview to manage compliance for sensitive information. The solution must include the ability to discover, classify, and protect sensitive data across Microsoft 365 services. Which three of the following should the administrator configure? (Choose three.)

⚠ Common exam trap

Test-takers frequently confuse the roles of DLP, eDiscovery, and Insider Risk Management as classification tools, when in fact they are enforcement, search, and risk detection tools respectively, not designed for automatic discovery and labeling of sensitive data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a sensitive information type to detect custom data patterns, such as employee IDs.

Creating a sensitive information type is correct because it allows the administrator to define custom patterns (e.g., employee IDs) that Microsoft Purview can use to discover and classify sensitive data across Microsoft 365 services. This is a foundational step for building compliance policies tailored to the organization's specific data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Create a sensitive information type to detect custom data patterns, such as employee IDs.

    Why this is correct

    Microsoft Purview's sensitive information types (SITs) are pattern-based definitions that use regex or keyword lists to identify data such as credit cards, or in this case a custom employee ID format. A global administrator can create a custom SIT in the Compliance portal specifying the exact pattern, supporting characters, and confidence level. Once created, this SIT can be used across DLP, auto-labeling, and retention policies, making it a foundational step for classifying a uniquely structured data attribute.

  • Enable auto-labeling policies in Microsoft Purview to automatically apply sensitivity labels to documents containing trade secrets.

    Why this is correct

    An auto-labeling policy lets you configure content matching conditions and apply a sensitivity label at the time of scanning across SharePoint, OneDrive, and Exchange. Because the policy can reference SITs or trainable classifiers as conditions, it is the correct mechanism for automatically labeling documents containing trade secrets. This is distinct from manual labeling or default labeling, as it proactively scans content in place without user intervention.

  • Configure a trainable classifier to identify and label content that matches specific organizational patterns, such as legal contracts.

    Why this is correct

    Trainable classifiers use machine learning to recognize a category of content based on examples of positive and negative text, rather than pattern matching or keywords. After you train and publish a classifier for legal contracts, you can include it as a condition inside auto-labeling policies and DLP rules. This allows nuanced classification of organizational content that may not have a fixed format, such as contracts, which a simple regex SIT would miss.

  • Set up a data loss prevention (DLP) policy to block external sharing of files labeled as 'Highly Confidential'.

    Why it's wrong here

    A DLP policy is an enforcement control, not a classification or labeling control; it acts on content after a label has been applied, for example by blocking external sharing. Without a sensitivity label, SIT, or classifier first assigning the 'Highly Confidential' label to the content, the DLP policy has nothing to act on. DLP policies can be part of a Purview deployment, but they are not the appropriate first step for identifying and labeling content based on a custom data format like employee IDs.

  • Deploy Microsoft Purview eDiscovery to automatically classify all content in Microsoft Teams chats.

    Why it's wrong here

    eDiscovery is designed for legal discovery workflows—searching, preserving, and exporting content—not for applying classification or sensitivity labels to Teams chats. Its search functions return results based on queries, but it does not scan and categorize every chat content automatically with labels. Purview has dedicated Microsoft Teams data classification features via auto-labeling and communication compliance, but eDiscovery alone cannot classify all chat messages.

  • Enable Microsoft Purview Insider Risk Management to scan and label all historical email data.

    Why it's wrong here

    Insider Risk Management analyzes user behavior and risk indicators (for example, unusual data exfiltration patterns) using analytics templates and does not have a labeling engine to apply sensitivity labels. It also focuses on signaling risky activity for investigation, not on scanning historical email archives for classification. Historical email labeling would be done via auto-labeling or encryption policies, not by an insider risk workflow.

About these practice questions

One of 241 original MS-102 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-102 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-102 exam.