Courseiva

SC-100 Practice Question: Design security solutions for applications and data

You are designing a data classification strategy for a Microsoft 365 tenant. You need to automatically classify documents that contain personally identifiable information (PII) and apply a retention label. Which Microsoft Purview feature should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-labeling policies

Auto-labeling policies (option A) are the correct choice because they can automatically apply sensitivity or retention labels to documents in Microsoft 365 services such as SharePoint, OneDrive, and Exchange when content matches specified conditions, including sensitive information types like PII. They are designed specifically for automatic classification and labeling at scale, which matches the requirement to classify PII-containing documents and apply a retention label. Trainable classifiers (option B) can identify content based on examples, but they are used to detect custom content types and still require a labeling policy to apply labels, so they are not the primary feature for this scenario. Manual labeling (option C) requires user intervention and does not meet the need for automatic classification. DLP policies (option D) can detect and protect sensitive information, but they do not apply retention labels; they enforce actions like blocking or notifying.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Auto-labeling policies

    Why this is correct

    Auto-labeling policies in Microsoft Purview apply sensitivity labels automatically to emails and files when they match configured conditions, such as sensitive information types like Social Security numbers or credit card numbers. Because they rely on built-in detection engines rather than user input or custom model training, they are the simplest and most consistent way to automatically label PII content in a data classification strategy. A policy can be run in simulation mode to review the labels before enforcing, then set to auto-label new and existing items.

  • ✗

    Trainable classifiers

    Why it's wrong here

    Trainable classifiers use machine-learning models that must be built and refined by providing positive and negative example sets, then testing the model's accuracy before deploying it. While they are useful for content that is difficult to detect with regex patterns, such as resumes or legal contracts, they are overkill for common PII like passport or Social Security numbers. They are not the simplest automatic method for PII because the training and iteration cycles require significant effort to achieve reliable results.

  • ✗

    Manual labeling

    Why it's wrong here

    Manual labeling depends on end users to select the appropriate sensitivity label for every document or email based on their own interpretation of the content. This approach is entirely human-driven, which means it cannot guarantee complete or consistent coverage, and it is naturally susceptible to oversight, misclassification, and policy fatigue. For a strategy aimed at automatically classifying PII at scale, manual labeling fails because it introduces user action as a dependency.

  • ✗

    Data Loss Prevention (DLP) policies

    Why it's wrong here

    Data Loss Prevention (DLP) policies in Microsoft Purview react to sensitive data matches by blocking, restricting, or auditing activities—they enforce protective rules rather than assigning metadata like sensitivity labels. While DLP uses many of the same sensitive information types as auto-labeling, its actions do not change the label on the content itself. Auto-labeling policies are the dedicated vehicle for automatically stamping files and emails with classification labels.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.