SC-100 Practice Question: Design security operations, identity, and compliance capabilities
An organization uses Microsoft Purview to classify and protect sensitive data. Which THREE capabilities can be used to discover sensitive data? (Choose three.)
⚠ Common exam trap
Microsoft often tests the distinction between discovery capabilities (which identify sensitive data) and enforcement or lifecycle management capabilities (which act on already-discovered data), causing candidates to mistakenly select DLP policies or retention labels as discovery tools.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trainable classifiers
Trainable classifiers use machine learning to identify content based on patterns and context, not just exact matches. They can be trained on sample data to recognize custom sensitive information, such as specific contract clauses or internal project codes, enabling discovery of sensitive data that predefined sensitive information types might miss.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Trainable classifiers
Why this is correct
Trainable classifiers are machine learning models in Microsoft Purview that analyze content using contextual, semantic, and visual signals to identify data types that do not rely on fixed patterns. They can be trained on seed documents unique to your organization, allowing them to classify content that lacks standardized formats, such as intellectual property or internal forms. This makes them the correct answer for a ML-driven classification approach.
- ✗
Data loss prevention policies
Why it's wrong here
Data loss prevention (DLP) policies in Microsoft Purview are enforcement controls designed to detect and block activities that could expose sensitive data, such as emailing a credit card number or uploading a file to an external site. They operate on content that has already been matched or classified by other mechanisms, such as sensitive information types or sensitivity labels. They do not discover or automatically classify content during the initial data-classification phase, which is why they are incorrect for a classification-only scenario.
- ✗
Retention labels
Why it's wrong here
Retention labels in Microsoft Purview are administrative markers that define how long content must be retained and whether it should be disposed of or deleted after a specified period. They are not used to discover or semantically analyze data content; instead, they tag content for lifecycle management based on criteria like regulatory requirements or business rules. Because their purpose is retention and disposition, not classification into content categories, they are the wrong answer when the goal is to identify and classify sensitive information.
- ✓
Data classification rules
Why this is correct
Data classification rules are condition-based logic within Microsoft Purview that automatically assign sensitivity labels by inspecting content for keywords, patterns, metadata, or other defined attributes. They do contribute to the classification process and can be customized to match business needs, but they rely on manually authored conditions rather than machine-learning-driven semantic understanding. They are correct as a classification mechanism, but their rule-based nature distinguishes them from trainable classifiers that learn organically from examples.
- ✓
Sensitive information types
Why this is correct
Sensitive information types (SITs) are built-in or custom pattern definitions used by Microsoft Purview to match known data formats, such as credit card numbers, social security numbers, or passport numbers, through regex, checksums, and keyword validation. They are highly reliable for standardized PII and satisfy the classification requirement for many compliance use cases. However, they only identify data that fits a predefined pattern and cannot categorize unstructured or conceptually similar content, which is why they are correct for pattern-based classification but do not provide the adaptive learning that trainable classifiers offer.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.