SC-100 Practice Question: Design security solutions for applications and data
A retail company uses Microsoft Purview to protect customer data across Microsoft 365 and Azure. The compliance team wants to detect when sensitive information such as credit card numbers is uploaded to SharePoint Online and automatically apply a sensitivity label that encrypts the content. The label must be applied without user interaction. You need to recommend the Purview capability to use. What should you recommend?
⚠ Common exam trap
The trap here is conflating DLP, which blocks or warns, with auto-labeling, which applies the label and encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An auto-labeling policy for sensitive information types in Microsoft Purview.
The scenario requires automatic detection of sensitive information and automatic application of an encrypting sensitivity label, with no user involvement. Microsoft Purview auto-labeling policies are purpose-built for this: they use sensitive information types and trainable classifiers to find content in SharePoint Online and other locations and apply the designated label. DLP, mandatory labeling, and Insider Risk Management serve different purposes and do not apply encryption labels automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An Insider Risk Management policy that flags credit card numbers in SharePoint.
Why it's wrong here
Insider Risk Management detects and scores risky user behavior and generates alerts for investigation, but it does not apply sensitivity labels or encrypt content. It is an analytics and response tool, not a labeling mechanism, so it cannot satisfy the automatic encryption requirement.
- ✗
A sensitivity label with user-defined permissions and mandatory labeling in SharePoint.
Why it's wrong here
Mandatory labeling forces users to choose a label, which is manual interaction and does not guarantee the correct label is applied. The requirement explicitly states the label must be applied without user interaction. User-defined permissions also depend on the user selecting recipients, so this does not meet the automatic requirement.
- ✓
An auto-labeling policy for sensitive information types in Microsoft Purview.
Why this is correct
Auto-labeling policies in Microsoft Purview scan locations such as SharePoint Online for sensitive information types like credit card numbers and apply the configured sensitivity label automatically, with no user action. This directly matches the requirement to detect and encrypt sensitive content at rest without interaction.
- ✗
A data loss prevention policy that blocks uploads containing credit card numbers.
Why it's wrong here
A DLP policy can detect and block or warn on sensitive content, but it does not apply an encryption label to the item. The requirement is to label and encrypt the content, not to prevent its upload. DLP and auto-labeling are complementary, but DLP alone does not fulfill the stated outcome.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.