Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your company uses Microsoft Purview to manage data governance. You need to create a data classification rule that scans Azure Data Lake Storage for personally identifiable information (PII) such as email addresses. The rule must also apply a sensitivity label automatically. Which approach should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a custom scan rule in Microsoft Purview and configure auto-labeling.

The correct option is B: create a custom scan rule in Microsoft Purview and configure auto-labeling. Microsoft Purview is the data governance service that supports scanning Azure Data Lake Storage with custom classification rules (using regex or dictionaries) to detect PII such as email addresses, and its auto-labeling policies can then apply sensitivity labels automatically to matching content. Option A is wrong because Azure Policy enforces resource configuration and compliance, not content-level PII detection or sensitivity labeling. Option C is wrong because Power Automate is a workflow automation tool and does not provide Purview's built-in classification scanning for Data Lake Storage. Option D is wrong because Microsoft Defender for Cloud focuses on security posture and threat protection, not data classification or sensitivity labeling.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an Azure Policy to detect and label PII.

    Why it's wrong here

    Azure Policy is an infrastructure governance engine that enforces rules on Azure resource configuration, such as permitted SKUs, RBAC locks, or required tags, via policy definitions and remediation tasks. It cannot inspect the actual content of files, blobs, or database fields, so it is incapable of detecting PII or assigning Office/Microsoft Purview sensitivity labels. Its scope is the control plane, not the data plane.

  • ✓

    Create a custom scan rule in Microsoft Purview and configure auto-labeling.

    Why this is correct

    Microsoft Purview provides native scanning that discovers data assets across on-premises and cloud sources, and you can define custom classification rules using regex or keyword patterns to identify PII such as SSNs or credit card numbers. Once the scan classifies content, Purview's auto-labeling automatically applies Microsoft 365 sensitivity labels to the assets based on the custom rule's classifier, enabling consistent data governance and protection. This directly matches the requirement to detect and label PII.

  • ✗

    Use a Power Automate flow to scan files and apply labels.

    Why it's wrong here

    Power Automate is a workflow orchestration service for automating business processes, such as sending notifications or moving files on events, and it can call REST APIs for custom logic. However, it lacks a built-in content scanner and classification engine; a flow would have to fetch each item and run custom code to detect PII, which is inefficient and unreliable at enterprise scale compared to Purview's purpose-built scanning and labeling pipeline.

  • ✗

    Use Microsoft Defender for Cloud to scan for PII.

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection solution that evaluates resource security configurations, missing updates, and compliance with regulatory standards. Although it can leverage Microsoft Defender for SQL's sensitive data discovery to identify some database columns with potential PII, it does not scan arbitrary files, does not attach Purview sensitivity labels, and its data discovery is not a general-purpose classification engine. Therefore it cannot serve as the tool to detect and label PII across the organization.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.