Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization is implementing a data loss prevention (DLP) strategy using Microsoft Purview. The compliance team needs to automatically classify and label sensitive data in Microsoft 365, Azure SQL Database, and Amazon S3. Which Purview feature should you use?
⚠ Common exam trap
A common mix-up: candidates confuse the scanning and classification capabilities of Microsoft Purview Data Map with the labeling and protection features of Microsoft Purview Information Protection, but the Data Map is the service that actually discovers and classifies data across multiple clouds, while Information Protection applies the labels after classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Map
Microsoft Purview Data Map is the correct choice because it provides unified data governance across hybrid and multi-cloud environments, including Microsoft 365, Azure SQL Database, and Amazon S3. It automatically scans, classifies, and labels sensitive data using built-in classifiers and sensitivity labels, enabling consistent DLP policies across these disparate data sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview Data Map
Why this is correct
Microsoft Purview Data Map is the correct choice because it provides automated scanning and classification of sensitive data across hybrid and multi-cloud environments, including on-premises, Azure, and other clouds such as AWS S3. Its data scanners can connect to Azure SQL databases and S3 buckets, inspect schemas and content, and apply classifications that feed into DLP policies. This makes it uniquely capable of discovering and mapping sensitive data at rest in non-Microsoft 365 sources, which is the core requirement here.
- ✗
Microsoft Purview Information Protection
Why it's wrong here
Microsoft Purview Information Protection is designed for Microsoft 365 workloads, specifically applying sensitivity labels to Office documents, emails, and other M365 content. It does not have native scanners to connect to Azure SQL or AWS S3, so it cannot identify sensitive data in those structured database or object storage services. Therefore, while it is useful for labeling files in Exchange, SharePoint, and OneDrive, it falls short of the requirement to cover Azure SQL and S3.
- ✗
Microsoft Purview Records Management
Why it's wrong here
Microsoft Purview Records Management is focused on the lifecycle of records—specifically retention schedules, legal hold, and disposition of content. It does not perform data scanning or classification of databases or cloud storage services; its role is to ensure that records are kept for the required periods and then deleted or archived. Since the problem is about identifying sensitive data before applying DLP controls, records management is irrelevant to the discovery and classification phase.
- ✗
Microsoft Defender for Cloud Apps
Why it's wrong here
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides visibility and control over sanctioned and unsanctioned SaaS applications, such as Microsoft 365, Salesforce, and Google Workspace. It focuses on user behavior, session policies, and app-to-app connectivity, but it does not dig into IaaS data stores like Azure SQL or S3 to inspect or classify stored data. Consequently, it cannot serve as the primary tool for discovering sensitive data in those database and storage assets.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.