SC-100 Practice Question: Design security solutions for applications and data
You are designing a data classification strategy for Microsoft Purview. The compliance team requires that documents containing personally identifiable information (PII) like credit card numbers are automatically labeled and encrypted when stored in Microsoft SharePoint Online. The solution must use built-in sensitive information types. What should you include in the design?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a sensitivity label with auto-labeling for credit card numbers and enable encryption
Option A is correct because Microsoft Purview sensitivity labels support auto-labeling policies that can use built-in sensitive information types (SITs) such as Credit Card Number, and the label itself can enforce encryption via the label's encryption settings when applied to documents in SharePoint Online. This directly satisfies the requirement to automatically label and encrypt PII-containing documents using built-in SITs. Option B is incorrect because retention labels govern retention/deletion, not encryption, and DLP policies do not apply retention labels. Option C is incorrect because trainable classifiers are for custom content patterns, not built-in PII SITs like credit card numbers. Option D is incorrect because manual labeling does not meet the automatic labeling requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a sensitivity label with auto-labeling for credit card numbers and enable encryption
Why this is correct
This is correct because a sensitivity label can be configured with auto-labeling rules and encryption so that when an item in SharePoint Online, OneDrive, or Exchange contains a credit card number (detected by the built-in Credit Card Number sensitive information type), the label is applied automatically and the file or email is protected with Azure Rights Management encryption. The auto-labeling policy can run as a simulation first to evaluate matches, then be enforced, ensuring both classification and protection happen without user action. This architecture directly satisfies a requirement for automatic classification and encryption.
- ✗
Create a retention label and apply it automatically via a data loss prevention (DLP) policy
Why it's wrong here
Retention labels are lifecycle controls that determine how long content must be kept and whether a disposition review is required; they do not encrypt data or restrict access. Additionally, a DLP policy is designed to use rules to detect and manage the transmission of sensitive data (e.g., block sharing), but it does not natively auto-apply retention labels — retention labels are auto-applied via retention label auto-apply policies that use KQL queries or sensitive info types. Neither component meets the stated need to automatically encrypt documents containing credit card numbers.
- ✗
Use a trainable classifier to detect PII and apply a sensitivity label
Why it's wrong here
Trainable classifiers are machine-learning models that must be trained on custom examples of the content you want to identify, making them suited for subjective document types (e.g., contracts or resumes) rather than predictable data patterns. Credit card numbers have a well-known structure and are detected by Microsoft 365's built-in sensitive information types (SITs) with predefined regular expressions and checksums. An auto-labeling policy for credit card data should reference the Credit Card Number SIT, not a trainable classifier, which would require extra training steps and does not provide deterministic accuracy for this entity.
- ✗
Configure a manual sensitivity label policy for users to apply
Why it's wrong here
Publishing a sensitivity label policy to users enables manual labeling through the Office apps, but the label will only be applied if each user remembers to select the label and chooses the correct one. In an automatic data classification strategy, relying on users introduces inconsistency and security gaps, especially for regulated data like credit card numbers. While manual labeling is useful for context-aware decisions, it fails the explicit requirement for automatic classification and encryption of all matching content.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.