Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

A company uses Microsoft Purview Data Lifecycle Management. They need to retain financial records for 7 years and then delete them. Which TWO actions should they configure?

⚠ Common exam trap

Watch out — candidates often confuse sensitivity labels (used for classification and protection) with retention labels (used for lifecycle management), leading candidates to incorrectly select Option B instead of understanding that retention labels are the correct mechanism for timed deletion.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a retention label with a 7-year retention period

Option C is correct because a retention label in Microsoft Purview Data Lifecycle Management is the mechanism that defines how long content is retained (here, 7 years) and what happens at the end of that period, such as deletion. Option E is correct because a disposition review can be attached to a retention label so that when the 7-year retention period expires, designated reviewers must approve the deletion before the records are permanently removed, which is a common compliance requirement for financial records. Option A is incorrect because DLP policies are designed to prevent data loss or leakage, not to enforce retention or deletion schedules. Option B is incorrect because sensitivity labels classify and protect content (for example, encryption and access restrictions) but do not by themselves define retention or deletion periods. Option D is incorrect because trainable classifiers identify content types for classification or auto-labeling; they do not enforce a 7-year retention-then-delete lifecycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a DLP policy that blocks deletion

    Why it's wrong here

    A Microsoft Purview DLP policy is designed to detect and prevent unauthorized sharing or leakage of sensitive data across endpoints, services, and on-premises locations. It does not intercept or control deletion operations on existing records, because deletion management falls under retention and disposition policies, not DLP rules. Attempting to block deletion through DLP would not enforce a retention period; the underlying record could still be deleted by the user or system without any administrative alert or block. Therefore, it is incorrect for ensuring records are kept for 7 years.

  • ✗

    Apply a sensitivity label to the records

    Why it's wrong here

    Sensitivity labels classify content by business sensitivity (for example, General or Confidential) and can apply encryption, visual markings, or access restrictions. They do not specify a retention duration or deletion behavior; these are separate properties managed exclusively by retention labels in Purview. Applying a sensitivity label alone leaves the record free to be deleted prematurely, as it carries no time-based enforcement. Hence, it does not fulfill the 7-year retention requirement.

  • ✓

    Create a retention label with a 7-year retention period

    Why this is correct

    A retention label is the Purview mechanism that directly enforces retention and deletion behavior on documents, emails, and other content. By creating a retention label with a 7-year retention period and publishing it (or auto-applying it), the organization ensures the record remains immutable and un-deletable during that period, and the label can also trigger a disposition review at expiration. This aligns with regulatory requirements for retaining records. Thus, it is the correct action to preserve the records for the mandated timeframe.

  • ✗

    Use a trainable classifier to identify records

    Why it's wrong here

    Trainable classifiers are machine learning models in Purview that recognize content types (e.g., contracts, invoices) and can automatically assign a label to matching items. Even if a classifier accurately identifies a record, it only determines what the content is; it has no built-in authority to retain it for a certain number of days or years. The classifier must be configured to apply a retention label, and it is the retention label, not the classifier, that actually enforces the 7-year period. Therefore, using a classifier alone is insufficient and incorrect in this context.

  • ✓

    Configure a disposition review to approve deletion

    Why this is correct

    A disposition review is a workflow-based approval step that occurs at the end of a retention period, where an authorized user decides whether to permanently delete content or extend its retention. It provides a human checkpoint to ensure that deletion happens appropriately and auditably, which is an important part of a compliant records management process. However, it is not the primary instrument for establishing the 7-year duration; it operates only after that duration has elapsed. Thus, while it is a valid corrective component for deletion governance, the core solution is the retention label.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.