Automatically Applying Retention Labels to Documents with Credit Card Numbers
A company uses Microsoft Purview to classify data and enforce retention policies. They need to automatically apply a retention label to all documents containing credit card numbers. Which approach should they use?
Quick Answer
The answer is to configure an auto-labeling policy with a sensitive info type. This is correct because Microsoft Purview auto-labeling policies use pattern matching against built-in sensitive info types (SITs), such as the credit card number SIT, to automatically apply retention labels to documents without user intervention. On the Microsoft Cybersecurity Architect exam, this scenario tests your understanding of how Purview’s auto-labeling differs from manual or default labeling—a common trap is confusing it with a retention policy that lacks a label, or assuming you need a trainable classifier for a fixed pattern like credit card numbers. Remember, SITs handle structured data like credit card numbers via regex patterns, while trainable classifiers are for unstructured content. A quick memory tip: for fixed patterns, think “SIT and auto-label,” not manual or machine learning.
⚠ Common exam trap
It's easy for candidates to confuse trainable classifiers with sensitive info types, thinking that 'intelligent' classification is always better, but SITs are the correct choice for specific, pattern-based data like credit card numbers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an auto-labeling policy with a sensitive info type
Microsoft Purview auto-labeling policies can automatically apply retention labels to documents based on sensitive info types (SITs), such as credit card numbers. This approach uses pattern matching to detect the credit card number format and applies the label without user intervention, meeting the requirement for automatic enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an auto-labeling policy with a sensitive info type
Why this is correct
Auto-labeling policies scan content and apply retention labels when items match a sensitive info type, such as credit card numbers. This delivers automatic, condition-based labelling at scale, satisfying the requirement without relying on manual user classification.
- ✗
Use a trainable classifier
Why it's wrong here
Trainable classifiers learn from labelled examples of document categories, not fixed patterns like card numbers, so they cannot reliably detect credit card data. It is tempting because they handle custom or hard-to-describe content, but credit card numbers are a built-in sensitive information type matched by regex and checksum.
- ✗
Create a manual labeling policy for users
Why it's wrong here
Manual labelling relies on users choosing labels themselves, which does not automatically apply retention to every document containing credit card numbers. It is tempting because manual policies suit small volumes or user judgement, but the requirement is automatic detection and labelling without user action.
- ✗
Use a default label for SharePoint libraries
Why it's wrong here
A default library label applies to every item in the library regardless of content, so it cannot target documents containing credit card numbers. It is tempting because default labels give baseline retention coverage, but content-based auto-application requires a sensitive information type or auto-labelling policy instead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company uses Microsoft Purview to classify and label sensitive data. They want to automatically apply a sensitivity label to documents containing a specific custom sensitive information type. Which TWO components are required for this?
medium- A.Data loss prevention (DLP) policy
- B.Retention label
- ✓ C.Custom sensitive information type
- ✓ D.Auto-labeling policy
- E.Trainable classifier
Why C: Option C (Custom sensitive information type) is required because the scenario specifically calls for detecting a custom-defined pattern of sensitive data, and a custom SIT (defined via regex, function, or keyword list) is what identifies that unique content. Option D (Auto-labeling policy) is required because it is the client-side or service-side policy that automatically applies a sensitivity label to items matching a condition, and that condition can reference the custom SIT. Together, the custom SIT supplies the detection logic and the auto-labeling policy supplies the automatic label application. Option A (DLP policy) is incorrect because DLP enforces protective actions like blocking or warning on data in motion or use, not the automatic application of sensitivity labels. Option B (Retention label) is incorrect because retention labels govern how long content is kept or deleted, not classification or labeling for sensitivity. Option E (Trainable classifier) is incorrect because trainable classifiers are used for content that is hard to define by pattern (e.g., resumes, contracts), whereas this scenario calls for a specific custom SIT.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.