Courseiva
easyMultiple Choice

SC-100 Practice Question: Planning their Zero Trust data protection strategy

A company is planning their Zero Trust data protection strategy. They want to classify and protect sensitive data stored in SharePoint Online. Which Microsoft tool should they use?

⚠ Common exam trap

Candidates often confuse Microsoft Defender for Cloud Apps (a CASB for monitoring and controlling cloud app usage) with the data classification and labeling capabilities of Microsoft Purview Information Protection, because both tools can handle sensitive data but serve fundamentally different roles in a Zero Trust strategy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection

Microsoft Purview Information Protection (formerly Microsoft Information Protection) is the correct tool because it provides integrated classification, labeling, and protection for sensitive data across Microsoft 365 services, including SharePoint Online. It uses sensitivity labels that can automatically apply encryption, rights management, and visual markings (headers/footers) to documents based on policy conditions, directly supporting the Zero Trust principle of 'assume breach' by protecting data at rest and in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Intune

    Why it's wrong here

    Microsoft Intune is focused on device management and mobile application management, not on inspecting or classifying data. It can enforce conditional access and app protection policies that restrict data movement (e.g., preventing copy/paste or save-as) after a sensitivity label has been applied, but it has no native capability to detect sensitive information types or assign classification labels to files and emails. Therefore, Intune cannot be the primary data classification component in a Zero Trust data protection strategy.

  • ✗

    Microsoft Defender for Cloud Apps

    Why it's wrong here

    Microsoft Defender for Cloud Apps acts as a CASB that discovers cloud app usage and applies session and access controls to cloud workloads, but it does not perform data classification itself. While it can read and enforce sensitivity labels created by Microsoft Purview for actions such as blocking downloads or applying labels, the actual classification and labeling intelligence originates in Purview Information Protection. For data protection, Defender for Cloud Apps is a policy enforcement and visibility layer, not a classifier.

  • ✓

    Microsoft Purview Information Protection

    Why this is correct

    Microsoft Purview Information Protection is the correct service for implementing a Zero Trust data protection strategy because it provides data classification, sensitivity labeling, and protection directly on documents and emails. It uses sensitive information types, trainable classifiers, and exact data match to automatically detect content and apply labels, which then can trigger encryption or access restrictions. Additionally, the Content Explorer and Activity Explorer give security teams visibility into labeled data, and the labels integrate across endpoints, cloud apps, and on-premises repositories.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy enforces compliance and governance rules by evaluating the configuration of Azure resources, such as requiring specific resource SKUs or auditing that storage accounts use HTTPS, but it does not inspect the content within files, databases, or messages. Its effect is limited to resource metadata and infrastructure properties, so it cannot apply sensitivity classifications like 'Confidential' to data itself. Azure Policy may complement a data protection plan, but it is not a data classification engine.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.