Courseiva

SC-100 Practice Question: Design security solutions for applications and data

You are designing a data security solution for a Microsoft 365 tenant that contains highly confidential files. You need to ensure that these files are encrypted and can only be accessed by authorized users, even if the files are downloaded and stored on a personal device. Which technology should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection with encryption and usage rights

Microsoft Purview Information Protection with encryption and usage rights (option B) is correct because it applies persistent protection to the file itself via sensitivity labels, so the encryption and usage restrictions travel with the document even after it is downloaded to a personal device, and only authorized users with the granted rights can open it. Office 365 Message Encryption (A) only protects email messages in transit and does not persist on files stored locally. BitLocker (C) encrypts the whole drive at the OS level, so protection is lost once the file leaves that device. Azure Information Protection (D) is the legacy predecessor now superseded by Purview Information Protection, making B the current, appropriate choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Office 365 Message Encryption

    Why it's wrong here

    Office 365 Message Encryption is scoped to the transport layer of Exchange Online: it encrypts email messages sent to external recipients, and attachments are encrypted as part of the message envelope. It does not, however, apply persistent, file-level protection; once the recipient downloads and saves an attachment, the file is decrypted and can be freely shared, copied, or exfiltrated. For authoring, storing, or collaborating on sensitive files in SharePoint or OneDrive, OME offers no protection at all, so it cannot meet a file-centric data security requirement.

  • ✓

    Microsoft Purview Information Protection with encryption and usage rights

    Why this is correct

    Microsoft Purview Information Protection with encryption and usage rights is the current, unified file-protection service in Microsoft 365. It lets you apply labels that encrypt files (Word, Excel, PowerPoint, PDF) and attach usage rights—such as View, Edit, Copy, Print, and Forward—that are enforced by Azure Rights Management. These rights are embedded in the file metadata and travel with the file wherever it goes, so even if a user downloads a document to a USB stick or emails it to a third party, access is still governed by the policy. This persistent protection, combined with user-friendly labeling and DLP integration, makes it the correct answer for protecting data at rest and in motion within and outside the tenant.

  • ✗

    BitLocker Drive Encryption

    Why it's wrong here

    BitLocker Drive Encryption operates at the block level, encrypting the entire system or data volume on a Windows device to protect against offline attacks (such as booting from another OS). It does not understand file formats, ownership, or user authorization; once Windows is running, any authenticated user with file access can open, copy, or send unencrypted data because the volume is transparently decrypted. It also has no concept of usage rights or revocation, and it does not follow the data if the file is copied to another machine or shared via cloud. Thus, while BitLocker is essential for endpoint security, it is not a file-level data classification or protection solution.

  • ✗

    Azure Information Protection

    Why it's wrong here

    Azure Information Protection (AIP) was the earlier brand and standalone client for what is now Microsoft Purview Information Protection. While AIP also used encryption and rights management under the hood, its client has been deprecated in favor of the built-in unified labeling architecture in Microsoft 365 apps, and the service has been fully rebranded into the Purview compliance portfolio. Choosing 'Azure Information Protection' would refer to a legacy product that requires the AIP client for full functionality and that Microsoft no longer actively develops for new features, making it less correct than the current, fully integrated Purview service. In an exam or architecture context, the up-to-date service name is the decisive factor.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.