SC-100 Practice Question: Design security operations, identity, and compliance capabilities
A company uses Microsoft Purview to classify and label sensitive data. They want to automatically apply a sensitivity label to documents containing a specific custom sensitive information type. Which TWO components are required for this?
⚠ Common exam trap
Test-takers frequently confuse the role of a DLP policy (which enforces actions like blocking) with an auto-labeling policy (which applies labels), or they mistakenly think a trainable classifier is needed when a custom sensitive information type already provides deterministic pattern matching.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Custom sensitive information type
Option C (Custom sensitive information type) is required because the scenario specifically calls for detecting a custom-defined pattern of sensitive data, and a custom SIT (defined via regex, function, or keyword list) is what identifies that unique content. Option D (Auto-labeling policy) is required because it is the client-side or service-side policy that automatically applies a sensitivity label to items matching a condition, and that condition can reference the custom SIT. Together, the custom SIT supplies the detection logic and the auto-labeling policy supplies the automatic label application. Option A (DLP policy) is incorrect because DLP enforces protective actions like blocking or warning on data in motion or use, not the automatic application of sensitivity labels. Option B (Retention label) is incorrect because retention labels govern how long content is kept or deleted, not classification or labeling for sensitivity. Option E (Trainable classifier) is incorrect because trainable classifiers are used for content that is hard to define by pattern (e.g., resumes, contracts), whereas this scenario calls for a specific custom SIT.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data loss prevention (DLP) policy
Why it's wrong here
Data loss prevention (DLP) policies enforce protective actions such as blocking, restricting, or auditing data sharing, but they do not apply sensitivity labels. DLP is focused on preventing unauthorized transmission of sensitive data, not on classifying or labeling content for metadata purposes. Even if a DLP policy can detect sensitive info types, it cannot assign a sensitivity label to a document.
- ✗
Retention label
Why it's wrong here
Retention labels are designed to govern data lifecycle by specifying how long content is kept and whether it should be deleted after that period. They do not convey sensitivity level nor apply classification markings; a document can have both a retention label and a sensitivity label independently. For sensitivity classification, you need a sensitivity label rather than a retention label.
- ✓
Custom sensitive information type
Why this is correct
A custom sensitive information type allows you to define a pattern using regular expressions, keywords, and validity checks to match specific sensitive data (e.g., employee IDs). When this type is referenced in an auto-labeling policy, Purview scans content and applies the configured sensitivity label on matches. It is the mechanism that identifies the content pattern, making it the correct choice for classification and labeling based on custom-defined data.
- ✓
Auto-labeling policy
Why this is correct
Auto-labeling policies in Purview can automatically apply sensitivity labels to files and emails based on conditions like sensitive information types or trainable classifiers. They are a valid way to label content at scale, but they rely on sensitivity information types (such as custom types) to detect the data patterns. While this option is correct for automatically applying labels, it complements rather than replaces the custom sensitive information type.
- ✗
Trainable classifier
Why it's wrong here
Trainable classifiers use machine learning to recognize content based on examples and patterns, rather than exact custom-defined rules. They are useful for identifying categories like resumes or source code, but they do not allow you to define a precise numeric pattern for a specific label. Consequently, they are not suitable when you need to match a bespoke pattern for sensitivity classification.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.