SC-100 Practice Question: Design security solutions for applications and data
Your organization is adopting Microsoft Copilot for Microsoft 365. You need to ensure that Copilot respects the existing sensitivity labels when processing data. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure sensitivity labels in Microsoft Purview Information Protection.
The correct option is B: Configure sensitivity labels in Microsoft Purview Information Protection. Copilot for Microsoft 365 honors the sensitivity labels applied to content, so labels must be defined and published through Microsoft Purview Information Protection (the current unified labeling platform) for Copilot to respect classification and protection settings such as encryption and content marking. DLP policies (A) enforce rules on sharing or handling of sensitive data but do not provide the classification metadata Copilot uses to respect sensitivity. Azure Information Protection (C) is the legacy labeling client/service being retired in favor of Purview Information Protection, so it is not the configuration target. Retention labels (D) govern lifecycle and retention, not sensitivity-based protection, so they do not control how Copilot treats sensitive content.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create Data Loss Prevention (DLP) policies.
Why it's wrong here
Data Loss Prevention (DLP) policies are enforcement mechanisms that inspect content in transit and at rest to block email or sharing that violates rules, but they do not embed classification metadata into documents, so Copilot cannot infer the intended sensitivity level from them. Without sensitivity labels, Copilot lacks the data map it needs to apply least-privilege access. Therefore, DLP alone fails to define sensitivity, making this option incorrect.
- ✓
Configure sensitivity labels in Microsoft Purview Information Protection.
Why this is correct
Sensitivity labels in Microsoft Purview Information Protection apply persistent, tamper-proof metadata to content—such as confidentiality, encryption, and visual markings—which Copilot for Microsoft 365 explicitly consumes to determine whether it may summarize, extract, or generate from the underlying data. Because the labels are honored inside the Microsoft 365 ecosystem, they provide the granular, per-item control needed to govern AI responses. This is the correct answer as it establishes classification at the source.
- ✗
Use Azure Information Protection.
Why it's wrong here
Azure Information Protection (AIP) was the previous standalone classification and labeling solution, but Microsoft has converged that functionality into Microsoft Purview Information Protection and the unified sensitivity label infrastructure, with the AIP client being deprecated for built-in labeling in Microsoft 365 apps. Using AIP today is effectively using an out-of-date tool that lacks the integrated classification pipeline that Copilot requires. Thus, while AIP is conceptually related, it is the wrong implementation for a modern Copilot deployment.
- ✗
Apply retention labels to documents.
Why it's wrong here
Retention labels are lifecycle controls that specify how long content must be kept or when it should be deleted, and they are not intended to convey confidentiality or access rights to AI systems. Copilot does not treat retention labels as a signal for sensitivity; instead, it relies on sensitivity labels, which encode the actual classification of data. Accordingly, applying retention labels without sensitivity labels leaves Copilot unaware of which content is privileged, so this approach is incorrect for the stated requirement.
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.