Courseiva

SC-100 Practice Question: Design security solutions for applications and data

A company uses Microsoft 365 and wants to protect sensitive documents from being shared externally. They need a solution that automatically classifies documents containing personally identifiable information (PII) and applies appropriate protection. Which two services should they combine?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection and Data Loss Prevention (DLP)

Microsoft Purview Information Protection allows for classification and labeling of documents based on content, while Data Loss Prevention (DLP) policies can enforce actions such as blocking external sharing or applying encryption. Together, they provide automated protection for sensitive documents like those containing PII. Option D is correct because these two services work together to classify and protect documents. Option A is incorrect because Microsoft Defender for Cloud Apps focuses on SaaS app security and Intune is for device management; they do not directly classify documents. Option B is incorrect because Compliance Manager is for managing compliance posture, and Sentinel is a SIEM; they are not used for automatic document classification. Option C is incorrect because Azure Information Protection is a previous version, now part of Purview, and Microsoft Entra ID is an identity service; they do not provide the same integrated classification and DLP capabilities as the Purview solutions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Defender for Cloud Apps and Microsoft Intune

    Why it's wrong here

    Microsoft Defender for Cloud Apps is a cloud access security broker (CASB) that discovers shadow IT and enforces session-based conditional access policies, while Microsoft Intune handles device compliance, configuration, and mobile application management. Neither product performs content inspection or sensitivity labeling of documents, so they cannot classify sensitive data or enforce document-level sharing restrictions. Without Purview Information Protection's labeling engine or DLP's policy detection, these tools only control access at the device or session layer, not protect the document's payload itself.

  • ✗

    Microsoft Purview Compliance Manager and Microsoft Sentinel

    Why it's wrong here

    Microsoft Purview Compliance Manager is a governance tool that maps regulatory requirements (e.g., GDPR, ISO 27001) to pre-configured assessments and generates compliance scorecards, while Microsoft Sentinel is a SIEM/SOAR platform that aggregates security alerts and drives incident response. Neither service evaluates document content for sensitive data or applies/retains sensitivity labels. DLP and Information Protection are content-centric; Compliance Manager and Sentinel are posture- and telemetry-centric, leaving document classification and exfiltration prevention outside their scope.

  • ✗

    Azure Information Protection and Microsoft Entra ID

    Why it's wrong here

    Azure Information Protection, as a standalone unified labeling client, is deprecated and its labeling capabilities have been folded into Microsoft Purview Information Protection, so using it is an outdated path. Microsoft Entra ID provides authentication, conditional access, and identity governance but operates at the identity/device level rather than inspecting document payloads. Combining an identity provider with a deprecated classifier does not deliver the required persistent, content-aware labels or DLP enforcement needed to prevent external sharing of sensitive documents.

  • ✓

    Microsoft Purview Information Protection and Data Loss Prevention (DLP)

    Why this is correct

    Microsoft Purview Information Protection is the unified labeling engine that applies sensitivity labels to documents and emails, enabling persistent classification, encryption, and visual markings, while DLP policies inspect content and detect labeled data to enforce actions such as blocking external sharing or quarantining risky messages. These two services work symbiotically: labels drive policy decisions, and DLP can also use content patterns alongside labels to catch violations. This is the current recommended architecture for protecting sensitive information in Microsoft 365, with AIP's legacy functionality replaced by Purview.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.