SC-100 Practice Question: Design security solutions for applications and data
A healthcare organization uses Microsoft Purview Information Protection to classify and protect patient data. They want to automatically apply a 'High Confidentiality' label to any document containing a patient ID pattern (###-####). The label should also encrypt the document. Which configuration should they use?
⚠ Common exam trap
SC-100 often tests the confusion between retention labels, DLP policies, and sensitivity labels, and candidates may incorrectly choose DLP or retention when the requirement is automatic classification with encryption, which is a sensitivity label feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity label with auto-labeling for sensitive info types
To automatically apply a label that encrypts documents containing a patient ID pattern, the organization should use a sensitivity label with auto-labeling configured for sensitive info types. Sensitivity labels can enforce encryption and are applied automatically based on conditions such as the presence of sensitive information types (e.g., a custom regex for ###-####).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Retention label with auto-labeling policy
Why it's wrong here
A retention label with an auto-labeling policy is designed to govern the data lifecycle by retaining or deleting content after a defined period, not to safeguard its confidentiality. While auto-labeling can be triggered by sensitive info types, the label itself only carries retention/disposition settings and has no native mechanism to encrypt files or restrict access. Because the goal here is protecting PHI with encryption at rest and in transit, this option fails the security requirement.
- ✗
Data Loss Prevention (DLP) policy with a block action
Why it's wrong here
A Data Loss Prevention (DLP) policy with a block action prevents sensitive data from being shared via email, Teams, or cloud locations by blocking the violating transfer, but it does not classify the file or change its protection state. DLP actions are enforced at the point of transmission or access and are not persisted with the document as metadata; if a file is already at rest, DLP alone does not encrypt it. This stops exfiltration but never applies a label or encryption, so it doesn't meet the automatic protection requirement.
- ✓
Sensitivity label with auto-labeling for sensitive info types
Why this is correct
This is the correct choice: a sensitivity label with auto-labeling for sensitive info types (e.g., a patient ID regex) can be delivered through an auto-labeling policy in Purview, and the label can be configured with encryption via Azure Rights Management. When the label is applied, it encrypts the file, sets viewer/edit permissions, and embeds persistent protection metadata so that the PHI remains protected both at rest and when shared. Because both the classification trigger and the encryption action are integral to the sensitivity label, it uniquely combines automated detection with immediate protection.
- ✗
Trainable classifier with a retention policy
Why it's wrong here
A trainable classifier with a retention policy relies on machine learning to infer content type (e.g., medical records) after training, but the classifier itself only emits a label for classification, not a security policy. Coupling it only with a retention policy adds lifecycle management like delete or hold, not encryption or access controls; the label used would be a retention label, which lacks protection settings. Moreover, trainable classifiers require manual training, seed data, and review cycles, making them unreliable for deterministic PHI patterns and slower to deliver the encryption outcome that sensitivity labels with sensitive info types provide.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO Microsoft Purview features can be used to classify and label data in Microsoft 365?
easy- A.Retention policies
- B.eDiscovery
- ✓ C.Auto-labeling policies
- D.Audit logs
- ✓ E.Sensitive info types
Why C: Auto-labeling policies (C) are a Microsoft Purview Information Protection capability that automatically applies sensitivity labels to content by scanning items for sensitive data, so they directly classify and label data in Microsoft 365. Sensitive info types (E) are the pattern-based classifiers (for example, credit card or national ID patterns) that define what sensitive data looks like and are used by auto-labeling and other Purview rules to classify data. Retention policies (A) govern how long content is kept or deleted rather than classifying or labeling it, eDiscovery (B) is used for identifying and collecting content for legal cases, and Audit logs (D) record user and admin activity for investigation and compliance reporting, so none of these three perform classification or labeling.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.