SC-100 Practice Question: Design security solutions for applications and data
A company is designing a data classification strategy using Microsoft Purview. They need to automatically classify and protect sensitive data stored in Azure Blob Storage. Which TWO capabilities should they use? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels
The correct options are A and D. Sensitivity labels (A) can be applied to automatically classify and protect sensitive data, including in Azure Blob Storage. Microsoft Purview Data Map (D) provides auto-discovery and classification of data assets. Option B (DLP policies) is primarily for endpoint and Microsoft 365 workloads, not for Azure Blob. Option C (Information Barriers) is for restricting communication, not data classification. Option E (Azure Policy) is for governance, not data classification or protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sensitivity labels
Why this is correct
Sensitivity labels are a correct part of a Microsoft Purview classification strategy because they allow you to tag files and emails with classification, and optionally apply encryption or watermarks. They can be auto-applied through content inspection of sensitive information types and can extend to other workloads, yet they mark the content rather than maintain a centralized data map. In an Azure-centric design, they complement, rather than replace, Purview Data Map's asset-level classification.
- ✗
Data Loss Prevention (DLP) policies
Why it's wrong here
Microsoft Purview Data Loss Prevention policies monitor and protect sensitive data from unauthorized exposure across Exchange, SharePoint, OneDrive, Teams, and supported endpoints through rules that block, restrict, or alert on content. These policies rely on existing classification results, and natively they do not scan Azure Blob Storage or assign new classification metadata to assets. Using DLP alone would miss the required data classification and inventory baseline.
- ✗
Information Barriers
Why it's wrong here
Information Barriers are designed to prevent communication and collaboration between defined user groups, such as restricting traders from sharing chats or documents with banking analysts. They operate as access-control and communication policies in Teams/SharePoint, not as content-inspection or data-classification mechanisms. Consequently, they cannot identify, label, or categorize sensitive data and would not satisfy a data classification strategy.
- ✓
Microsoft Purview Data Map
Why this is correct
Microsoft Purview Data Map is the central service that automatically discovers data assets across Azure, on-premises, and multi-cloud sources, scanning Blob Storage, SQL, and other repositories. It applies built-in and custom sensitive information types to register classification metadata in a unified, searchable catalog, giving the data steward a complete view of the estate. This auto-discovery and classification of assets is foundational for any data classification strategy.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces organizational governance by evaluating Azure resource configurations against rules, such as denying storage accounts without encryption or requiring specific tags. It operates at the control-plane and resource-property level and cannot inspect file or blob content for sensitive data. Therefore, Azure Policy supports compliance but is not a data-classification solution.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.