SC-100 Practice Question: Design security solutions for applications and data
Your organization is designing a solution to protect sensitive data in Microsoft SharePoint Online. You need to ensure that documents containing credit card numbers are automatically encrypted when shared with external users. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An auto-labeling policy for sensitivity labels with encryption
The correct option is C: an auto-labeling policy for sensitivity labels with encryption. In Microsoft Purview, auto-labeling policies scan SharePoint Online content for sensitive information types such as credit card numbers and automatically apply a sensitivity label; when that label is configured with encryption, the document is encrypted and the protection travels with the file even when shared with external users. Option A is wrong because a DLP policy that blocks sharing prevents external sharing rather than encrypting the document, and DLP does not itself apply encryption. Option B is wrong because SharePoint IRM encrypts files at rest in the library and relies on the service to enforce permissions, but it does not automatically classify and encrypt documents based on sensitive content detection. Option D is wrong because a retention policy with a hold only preserves content for compliance and does not encrypt it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Data Loss Prevention (DLP) policy that blocks sharing
Why it's wrong here
A DLP policy that blocks sharing is reactive and controls the movement of data—it can stop a user from sending a file via email or to an external site—but it does not encrypt the content at rest or in transit. The file itself remains unencrypted, and DLP only inspects, logs, and restricts actions when content is detected, so it fails to provide persistent protection if the file is copied, renamed, or accessed locally. It also lacks the rights management capabilities (like 'view-only' or preventing printing) that a sensitivity label provides, and it requires the data to be in motion to trigger a response.
- ✗
Information Rights Management (IRM) for SharePoint
Why it's wrong here
IRM for SharePoint uses Azure Rights Management to enforce permissions (view, edit, copy, print) that are attached to a document or library, but it is not automatically triggered by the presence of sensitive content. You must configure IRM per library or document set, and it does not inspect or classify the data based on patterns like PII, healthcare records, or credit card numbers. Also, IRM protection is only enforced when the document is opened in an Office client; cached copies, synced versions, or search results may not carry the same protection, so it falls short of the 'always protect sensitive content automatically' requirement.
- ✓
An auto-labeling policy for sensitivity labels with encryption
Why this is correct
An auto-labeling policy for sensitivity labels with encryption is correct because it uses sensitive info types or trainable classifiers to scan content and automatically apply a label that triggers Microsoft 365 encryption (AES-256) and rights management. This label persists with the file or email and enforces policies such as view-only, Do Not Forward, watermarking, and conditional access, regardless of where the data is stored or shared. Because the encryption is tied to the label and managed by Microsoft Entra ID RMS, the protection is permanent and follows the data even when it leaves the tenant or is copied to other applications, meeting the core requirement to protect sensitive data automatically.
- ✗
A retention policy with a hold
Why it's wrong here
A retention policy with an eDiscovery hold is designed for legal and regulatory preservation—it prevents deletion and retains versions of documents—but it does not restrict access or encrypt the content. It operates at the administrative lifecycle level, leaving the files fully readable by any user with permissions, and it offers no mechanism to enforce confidentiality or rights management. Holding data without encryption can actually increase risk because the data is preserved in place, unencrypted, and becomes a high-value target for attackers or over-privileged users, so it completely misses the encryption objective.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft 365. You need to ensure that when a user attempts to share a document containing credit card numbers externally, the action is blocked and the user is shown a policy tip. Which DLP rule configuration should you use?
medium- ✓ A.Block the action with a policy tip and allow override
- B.Block the action and send an incident report in email
- C.Audit the action only
- D.Block the action without allowing override
Why A: Option A is correct because configuring the DLP rule to block the action with a policy tip and allow override satisfies both requirements: the external sharing attempt is blocked, and the user sees a policy tip explaining the policy violation while being given the option to override with justification. In Microsoft Purview DLP, the policy tip is delivered through the rule's user notification settings, and the 'allow override' setting ensures the tip includes the override option. Option B blocks the action but only sends an incident report to administrators, so the user would not see a policy tip. Option C only audits the action, meaning the sharing would not be blocked at all. Option D blocks the action without allowing override, which would prevent the user from overriding but does not match the requirement to show a policy tip with override capability.
Variation 2. Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Microsoft 365. You need to create a DLP policy that detects and blocks sharing of credit card numbers in Exchange Online emails. Which TWO components must you configure?
medium- A.Retention label for financial data
- B.Auto-labeling policy
- ✓ C.Action to block sharing
- ✓ D.Sensitive info type for credit card number
- E.Trainable classifier for credit card numbers
Why C: Option D is correct because a DLP policy must reference a sensitive information type (SIT) — in this case the built-in 'Credit Card Number' SIT — so Purview can detect the credit card patterns in Exchange Online email content. Option C is correct because detection alone does nothing; the policy rule must define an action such as 'Block' (or restrict access/encrypt) to prevent the credit card data from being shared via email. Option A is incorrect because retention labels govern data lifecycle and retention, not real-time blocking of sensitive data sharing. Option B is incorrect because auto-labeling policies apply sensitivity labels to content and do not enforce DLP blocking actions. Option E is incorrect because trainable classifiers are used for custom content categories (e.g., resumes, contracts), not for detecting standardized numeric patterns like credit card numbers, which are handled by built-in SITs.
Variation 3. Your organization uses Microsoft Purview Data Loss Prevention (DLP) to protect sensitive data in Exchange Online. The compliance team wants to prevent users from sending emails containing Social Security numbers to external recipients. What should you configure?
medium- ✓ A.Create a DLP policy with the condition 'Content contains sensitive info type' and action 'Block the message'
- B.Configure a retention label for emails
- C.Create a mail flow rule in Exchange admin center
- D.Apply a sensitivity label to all emails
Why A: A DLP policy can detect sensitive info types and block the email. Option B is wrong because retention labels are for data retention, not blocking. Option C is wrong because mail flow rules (transport rules) can do similar but DLP is the recommended approach. Option D is wrong because sensitivity labels are for classification, not blocking.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.