A compliance officer needs to automatically detect documents stored in SharePoint Online that contain sensitive data types (e.g., credit card numbers) and apply a sensitivity label that restricts access to only certain users. The classification should occur without user intervention and the label must be applied to the document. Which Microsoft Purview solution should be configured?
Sensitivity labels with auto-labeling meet this requirement because they combine detection and protection: an auto-labeling policy in Microsoft Purview can scan files in SharePoint or OneDrive for predefined sensitive information types or trainable classifiers. When a match occurs, the policy automatically assigns a sensitivity label configured with encryption, rights management permissions, and visual markings. This creates a persistent classification that travels with the document, exactly matching the officer's need to automatically detect and protect sensitive documents.
Why this answer
Sensitivity labels with auto-labeling are the correct solution because they can automatically classify documents based on sensitive data types (such as credit card numbers) and apply a sensitivity label that enforces protection actions like restricting access to specific users. This occurs without user intervention, meeting the requirement for automatic classification and labeling in SharePoint Online.
Exam trap
The trap here is that candidates often confuse DLP policies with auto-labeling, but DLP only detects and blocks sharing actions, whereas auto-labeling applies the sensitivity label and its associated protection directly to the document.
How to eliminate wrong answers
Option A is wrong because Data Loss Prevention (DLP) policies detect and prevent the sharing of sensitive data but do not apply sensitivity labels or enforce access restrictions on documents; they trigger alerts or block actions. Option C is wrong because retention labels are designed to manage data retention and deletion policies, not to classify documents based on sensitive data types or apply access restrictions. Option D is wrong because information barriers are used to restrict communication and collaboration between specific groups or users, not to automatically detect sensitive data or apply labels to documents.