Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

Your organization is planning to deploy Microsoft Purview Information Protection to classify and protect sensitive data. You need to design a solution that automatically applies sensitivity labels to documents containing personally identifiable information (PII) when they are uploaded to SharePoint Online. Which configuration should you use?

⚠ Common exam trap

It's easy for candidates to confuse trainable classifiers with sensitive info types; candidates often pick trainable classifiers because they sound like a smart AI solution, but they are designed for broader content categories, not specific PII patterns like SSNs or credit card numbers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create an auto-labeling policy that uses a sensitive info type for PII

Microsoft Purview auto-labeling policies can automatically apply sensitivity labels to documents containing PII when they are uploaded to SharePoint Online. By configuring a policy with a sensitive info type (e.g., U.S. Social Security Number) as the condition, the service scans content at rest and applies the label without user intervention, meeting the requirement for automatic classification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Set a default sensitivity label for the SharePoint site

    Why it's wrong here

    Setting a default sensitivity label on the SharePoint site assigns that label to every document in the site's document libraries, regardless of whether the content contains personal data. Because it does not evaluate the content for PII, documents without PII become labeled, and documents with PII that the default label is not set to protect remain unlabeled with a higher classification. This approach also requires the label to be configured as the default, which only applies to new documents and does not retroactively scan existing files for PII.

  • Use trainable classifiers to identify PII and apply labels

    Why it's wrong here

    Trainable classifiers are designed to recognize content with indirect, subjective patterns by learning from user-provided sample sets, and they require a training period with positive and negative examples to achieve accuracy. For PII such as Social Security numbers or credit card numbers, Microsoft Purview already provides built-in sensitive info types (SITs) that use precise regular expressions and keyword lists for immediate, deterministic detection. Relying on trainable classifiers for PII adds unnecessary delay and tuning, and it may not match the accuracy of a well-defined SIT for these specific data patterns.

  • Create an auto-labeling policy that uses a sensitive info type for PII

    Why this is correct

    Creating an auto-labeling policy in the Microsoft Purview compliance portal lets you define a rule that scans SharePoint sites, OneDrive accounts, and Exchange for content containing sensitive info types (SITs) for PII, such as U.S. SSN, EU debit card number, or U.S. individual taxpayer identification number. When a match is found, the policy automatically applies the configured sensitivity label and can optionally enforce encryption or a visual marking. This is a rule-based, deterministic detection that works immediately on existing and new content, without user intervention, and is the intended mechanism for automatically classifying PII.

  • Configure a manual labeling policy that prompts users to classify documents

    Why it's wrong here

    A manual labeling policy that prompts users to classify documents relies on the user to select the correct sensitivity label, which is both error-prone and incomplete because users may not understand PII definitions or may skip the prompt. This approach does not provide automated detection or enforcement, so unclassified documents with PII remain unlabeled and unprotected. In contrast, the organization's requirement to automatically identify and label PII is satisfied only with an automated policy that scans content for sensitive data types.

About these practice questions

One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.