SC-100 Practice Question: Design security solutions for applications and data
You are designing a secure data classification strategy for documents in Microsoft 365. The compliance officer wants to automatically apply a 'Confidential' label to documents containing credit card numbers. Which Microsoft Purview feature should you use?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto-labeling policies
Auto-labeling policies (option A) are the correct choice because they are the Microsoft Purview feature designed to automatically apply sensitivity labels to content that matches specified conditions, such as documents containing credit card numbers detected via sensitive information types. This directly satisfies the compliance officer's requirement to apply a 'Confidential' label automatically without user intervention. Data loss prevention policies (B) can detect and block or warn about sensitive content but do not apply sensitivity labels. Trainable classifiers (C) can identify content categories by example, but they are used as conditions within labeling or DLP, not as the labeling mechanism itself. Manual labeling (D) requires users to apply labels themselves, which does not meet the automation requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Auto-labeling policies
Why this is correct
Auto-labeling policies in Microsoft Purview can automatically assign sensitivity labels to files and emails when their content matches built-in sensitive info types, such as credit card numbers, at a specified confidence or instance count. These policies run service-side on Exchange, SharePoint, and OneDrive, meaning content is evaluated by the service without requiring a user to open or interact with it. A policy simulation mode lets you test which items would be labeled before enforcing the rule, and once applied, the label can trigger protective actions like encryption. This directly meets the requirement of automatically applying labels based on predefined sensitive data patterns.
- ✗
Data loss prevention policies
Why it's wrong here
Data loss prevention (DLP) policies focus on detecting and restricting risky access, transfer, or sharing of sensitive information, so an admin might configure a rule to block external emailing of a credit card number or to block upload to a third-party site. While DLP rules can use sensitivity labels as conditions and can even trigger protective actions like encryption for email, they do not write or update a sensitivity label onto the document's metadata. Thus, a DLP policy would stop the leak but would not create the persistent classification attribute that the design needs. The core protection is event-based enforcement, not an automated labeling mechanism.
- ✗
Trainable classifiers
Why it's wrong here
Trainable classifiers are machine-learning models that infer meaning from context, sample content, and user feedback, making them appropriate for unstructured content like contracts, resumes, or industrial training materials. For a highly deterministic pattern such as a credit card number, the sensitive info type engine already provides regex-based detection with confidence scoring and checksums, so training an ML model would be redundant and less precise. Even if a trainable classifier is used inside an auto-labeling policy as a condition, the classifier itself only identifies content — it never performs the labeling action. Choosing a trainable classifier as the sole mechanism would not guarantee the reliable, predefined match the requirement specifies.
- ✗
Manual labeling
Why it's wrong here
Manual labeling relies on a user actively choosing a sensitivity label from the Office ribbon, Outlook, or the Purview portal, or accepting a recommended label prompt, so classification only happens when the user remembers to act. This approach is inherently inconsistent because a busy user may skip the prompt, misclassify based on subjective judgment, or label items after they have already been shared. The question asks for an automated design that labels content based on sensitive info types like credit card numbers, and manual labeling does not inspect or evaluate the content at rest or in transit unless the user triggers it. It also provides no centralized enforcement or simulation, making it unsuitable for a secure data classification strategy.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are designing a data classification strategy for Microsoft Purview. The compliance team requires that documents containing personally identifiable information (PII) like credit card numbers are automatically labeled and encrypted when stored in Microsoft SharePoint Online. The solution must use built-in sensitive information types. What should you include in the design?
hard- ✓ A.Create a sensitivity label with auto-labeling for credit card numbers and enable encryption
- B.Create a retention label and apply it automatically via a data loss prevention (DLP) policy
- C.Use a trainable classifier to detect PII and apply a sensitivity label
- D.Configure a manual sensitivity label policy for users to apply
Why A: Option A is correct because Microsoft Purview sensitivity labels support auto-labeling policies that can use built-in sensitive information types (SITs) such as Credit Card Number, and the label itself can enforce encryption via the label's encryption settings when applied to documents in SharePoint Online. This directly satisfies the requirement to automatically label and encrypt PII-containing documents using built-in SITs. Option B is incorrect because retention labels govern retention/deletion, not encryption, and DLP policies do not apply retention labels. Option C is incorrect because trainable classifiers are for custom content patterns, not built-in PII SITs like credit card numbers. Option D is incorrect because manual labeling does not meet the automatic labeling requirement.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.