Courseiva

Automatically Classify and Protect Sensitive Documents in SharePoint with Microsoft Purview

An organization uses Microsoft 365 E5 and wants to automatically classify and protect sensitive documents stored in SharePoint Online based on content patterns (e.g., credit card numbers). They need to apply encryption and restrict access when such content is detected. Which Microsoft 365 service should they configure?

Quick Answer

Microsoft Purview Information Protection is the service that automatically classifies and protects SharePoint content based on what the content actually contains, rather than requiring someone to label each document by hand. It works through sensitive information types and trainable classifiers that scan documents for recognisable patterns — a credit card number is a built-in sensitive information type combining a numeric pattern with a checksum validation — and when a match is found, the service can apply a sensitivity label automatically, which brings encryption and access restrictions with it. E5 licensing is what unlocks the automatic, content-based side of this: E3 supports manual labeling, but automatic classification and protection based on scanning document content specifically requires the higher-tier compliance capability that comes with E5 or the E5 Compliance add-on. Any scenario describing protection triggered by scanning content patterns, rather than a person choosing a label, is testing recognition of Purview Information Protection's automatic classification feature.

⚠ Common exam trap

Many candidates confuse Microsoft Defender for Cloud Apps (a CASB) with data classification, but it lacks the native content scanning and encryption enforcement that Purview Information Protection provides.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection

Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides content-based classification and protection for sensitive data. It uses trainable classifiers and sensitive information types (e.g., credit card numbers) to automatically apply encryption and restrict access via sensitivity labels in SharePoint Online.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID

    Why it's wrong here

    Microsoft Entra ID governs identities, authentication and conditional access; it cannot inspect document content for credit card patterns or apply encryption. Sensitivity labels with auto-labelling in Microsoft Purview handle content-based classification and protection. Entra ID would be correct for controlling who may sign in or reach a resource.

  • ✓

    Microsoft Purview Information Protection

    Why this is correct

    Microsoft Purview Information Protection applies sensitivity labels with automatic classification based on content patterns such as credit card numbers, and labels can enforce encryption and access restrictions. Configuring it in SharePoint Online satisfies the detection, encryption and access-limiting requirements.

  • ✗

    Microsoft Sentinel

    Why it's wrong here

    Microsoft Sentinel is a SIEM/SOAR platform that ingests logs, correlates alerts and triggers playbooks; it does not classify or encrypt documents in SharePoint Online. Microsoft Purview auto-labelling performs content-pattern detection and protection. Sentinel would be correct for detecting and responding to security incidents across an estate.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Defender for Cloud Apps applies session and access policies to cloud apps and detects anomalous activity, but it does not scan SharePoint document contents to auto-apply sensitivity labels with encryption. Microsoft Purview auto-labelling does that. Defender for Cloud Apps suits governing sanctioned SaaS usage and shadow IT.

About these practice questions

One of 794 original MS-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on MS-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization wants to use Microsoft 365 to automatically classify and protect sensitive data in emails and documents. Which service should they use?

easy
  • ✓ A.Microsoft Purview Information Protection
  • B.Microsoft Intune
  • C.Microsoft Defender for Office 365
  • D.Microsoft Entra ID

Why A: Microsoft Purview Information Protection (formerly Azure Information Protection) is the correct service because it provides data classification, labeling, and protection capabilities directly within Microsoft 365. It uses sensitivity labels to automatically classify emails and documents based on conditions like content patterns or custom keywords, and then applies encryption, rights management, or visual markings (e.g., headers/footers) to protect sensitive data both at rest and in transit.

Variation 2. A company uses Microsoft 365 and wants to automatically classify documents containing credit card numbers as 'Highly Confidential' and apply encryption when shared externally. Which solution should they use?

medium
  • A.Microsoft Intune
  • B.Microsoft Sentinel
  • ✓ C.Microsoft Purview Information Protection with auto-labeling
  • D.Microsoft Defender for Cloud Apps

Why C: Microsoft Purview Information Protection with auto-labeling is the correct solution because it uses trainable classifiers or exact data match (EDM) to detect sensitive data types like credit card numbers, automatically apply a 'Highly Confidential' sensitivity label, and enforce encryption when the document is shared externally. This capability is built into Microsoft 365 compliance center and integrates with sensitivity labels to protect data at rest and in transit.

Variation 3. A company uses Microsoft 365 E5 and wants to automatically classify sensitive emails containing credit card numbers and then apply encryption. Which solution should they use in combination with Microsoft Purview?

hard
  • A.Microsoft 365 Copilot
  • B.Microsoft Intune
  • ✓ C.Microsoft Purview Information Protection
  • D.Microsoft Defender for Office 365

Why C: Microsoft Purview Information Protection (formerly Azure Information Protection) enables automatic classification of sensitive data, such as credit card numbers, using built-in sensitive information types and exact data match (EDM) classifiers. When combined with sensitivity labels, it can automatically apply encryption (e.g., via Azure Rights Management) to emails containing that data, meeting the requirement without additional services.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This MS-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MS-900 exam.