Courseiva

SC-100 Practice Question: Design security solutions for applications and data

You are designing a data classification strategy for Microsoft Purview. The compliance team requires that documents containing personally identifiable information (PII) like credit card numbers are automatically labeled and encrypted when stored in Microsoft SharePoint Online. The solution must use built-in sensitive information types. What should you include in the design?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a sensitivity label with auto-labeling for credit card numbers and enable encryption

Option A is correct because Microsoft Purview sensitivity labels support auto-labeling policies that can use built-in sensitive information types (SITs) such as Credit Card Number, and the label itself can enforce encryption via the label's encryption settings when applied to documents in SharePoint Online. This directly satisfies the requirement to automatically label and encrypt PII-containing documents using built-in SITs. Option B is incorrect because retention labels govern retention/deletion, not encryption, and DLP policies do not apply retention labels. Option C is incorrect because trainable classifiers are for custom content patterns, not built-in PII SITs like credit card numbers. Option D is incorrect because manual labeling does not meet the automatic labeling requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create a sensitivity label with auto-labeling for credit card numbers and enable encryption

    Why this is correct

    This is correct because a sensitivity label can be configured with auto-labeling rules and encryption so that when an item in SharePoint Online, OneDrive, or Exchange contains a credit card number (detected by the built-in Credit Card Number sensitive information type), the label is applied automatically and the file or email is protected with Azure Rights Management encryption. The auto-labeling policy can run as a simulation first to evaluate matches, then be enforced, ensuring both classification and protection happen without user action. This architecture directly satisfies a requirement for automatic classification and encryption.

  • ✗

    Create a retention label and apply it automatically via a data loss prevention (DLP) policy

    Why it's wrong here

    Retention labels are lifecycle controls that determine how long content must be kept and whether a disposition review is required; they do not encrypt data or restrict access. Additionally, a DLP policy is designed to use rules to detect and manage the transmission of sensitive data (e.g., block sharing), but it does not natively auto-apply retention labels — retention labels are auto-applied via retention label auto-apply policies that use KQL queries or sensitive info types. Neither component meets the stated need to automatically encrypt documents containing credit card numbers.

  • ✗

    Use a trainable classifier to detect PII and apply a sensitivity label

    Why it's wrong here

    Trainable classifiers are machine-learning models that must be trained on custom examples of the content you want to identify, making them suited for subjective document types (e.g., contracts or resumes) rather than predictable data patterns. Credit card numbers have a well-known structure and are detected by Microsoft 365's built-in sensitive information types (SITs) with predefined regular expressions and checksums. An auto-labeling policy for credit card data should reference the Credit Card Number SIT, not a trainable classifier, which would require extra training steps and does not provide deterministic accuracy for this entity.

  • ✗

    Configure a manual sensitivity label policy for users to apply

    Why it's wrong here

    Publishing a sensitivity label policy to users enables manual labeling through the Office apps, but the label will only be applied if each user remembers to select the label and chooses the correct one. In an automatic data classification strategy, relying on users introduces inconsistency and security gaps, especially for regulated data like credit card numbers. While manual labeling is useful for context-aware decisions, it fails the explicit requirement for automatic classification and encryption of all matching content.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.