Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your company is implementing Microsoft Purview Information Protection to protect sensitive data. The compliance team requires that when a user applies a 'Highly Confidential' sensitivity label to a document, the document is automatically encrypted and watermarked. Which configuration should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the sensitivity label to apply encryption and dynamic watermarking. Publish the label to users.

The correct option is D: configure the sensitivity label itself to apply encryption and dynamic watermarking, then publish the label to users. In Microsoft Purview Information Protection, encryption and content marking (including watermarks) are protection settings defined on the sensitivity label, so when a user manually applies the 'Highly Confidential' label, those protections are enforced automatically. Publishing the label via a label policy makes it available in Office apps so users can apply it. Option A is wrong because DLP policies act on sharing/transmission conditions rather than applying label-based encryption and watermarks at label time. Option B is wrong because auto-labeling applies labels based on content detection, not when a user manually selects a label. Option C is wrong because Conditional Access governs access to cloud resources, not document encryption or watermarking.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a DLP policy that encrypts and watermarks the document when it is shared externally

    Why it's wrong here

    DLP policies operate on actions such as sharing, not on document state after a label exists; they can block or restrict external sharing but cannot retroactively encrypt or watermark content that has already left the tenant. Watermarking is not an action supported by DLP, and encryption as a DLP action is limited to restricting access via RMS, not applying a sensitivity label's protection settings.

  • ✗

    Create an auto-labeling policy that detects sensitive content and applies the label automatically

    Why it's wrong here

    Auto-labeling policies are designed to detect sensitive data patterns and apply labels autonomously, which directly conflicts with the stated requirement that the user manually applies the label. While auto-labeling is useful for discovery and classification, it would not exercise the user's judgment or provide the controlled, manual decision point that is explicitly requested in the scenario.

  • ✗

    Create a Conditional Access policy that requires the label to be applied to all documents

    Why it's wrong here

    Conditional Access policies control access based on user, device, and location signals at the time of authentication, not content protection actions like encryption or watermarking. They cannot force a label to be applied to a document, nor can they embed visual markings into files; Conditional Access simply grants or blocks access to resources.

  • ✓

    Configure the sensitivity label to apply encryption and dynamic watermarking. Publish the label to users.

    Why this is correct

    A sensitivity label is the correct mechanism because encryption and dynamic watermarking are configured as part of the label's protection settings, and publishing the label makes it available in the Office apps' Sensitivity button. When the user manually applies this label, the label enforces the configured encryption rights and dynamically inserts the user's identity (or other custom text) as a watermark, satisfying the 'user-applied' and 'dynamic watermarking' requirements precisely.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.