Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization needs to comply with GDPR. You need to design a data protection strategy using Microsoft Purview. Which THREE capabilities should you include?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data classification and labeling

Data classification and labeling (C) is essential because Microsoft Purview sensitivity labels and trainable classifiers identify and tag personal data, which is the foundation for applying GDPR-mandated protections. Data subject request management (D) directly supports GDPR data subject rights (access, erasure, portability) by using Purview's Data Subject Request case tooling to find and act on personal data across Microsoft 365. Data Loss Prevention policies (E) enforce GDPR's protection and breach-prevention requirements by detecting sensitive information types (such as EU identifiers) and blocking or auditing their improper sharing. Azure Policy (A) governs Azure resource compliance, not the discovery, classification, or protection of personal data in Purview, and eDiscovery (B) is a legal-hold and investigation tool rather than a GDPR data protection control, so neither belongs in this strategy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is wrong for GDPR because it is designed for standard resource governance, not data-protection controls. It enforces rules like allowed resource locations, required tags, or ensuring HTTPS on Azure App Services via initiative definitions, but it has no native ability to inspect personal data content, honor data-subject rights, or remediate a privacy breach. While it can complement a broader compliance posture (e.g., encrypting disks), it does not address GDPR's substantive obligations such as erasure or portability, so it is not a direct GDPR compliance answer.

  • ✗

    eDiscovery

    Why it's wrong here

    eDiscovery is wrong for GDPR because it serves legal discovery and litigation holds, not privacy compliance. Its primary function is to place content on hold, search it for evidence, and export results for court proceedings, using modules like Content Search and eDiscovery (Standard/Premium) in Microsoft 365. Using eDiscovery for GDPR purposes would fail to support key rights like rectification or erasure, and it could create an unnecessary legal hold that conflicts with data deletion obligations, so it is not a suitable GDPR tool.

  • ✓

    Data classification and labeling

    Why this is correct

    Data classification and labeling are correct because GDPR requires you to know what personal data you hold, where it is stored, and how it is processed. Azure Purview Information Protection lets you classify and label files and emails based on sensitivity (e.g., Personal, Highly Confidential), which then enables automated protections like encryption or access restrictions. This labeling is foundational for data minimization, accountability (Article 5), and the ability to efficiently respond to data subject requests, making it a key GDPR enabler.

  • ✓

    Data subject request management

    Why this is correct

    Data subject request management is a direct GDPR requirement (Articles 15-22) covering rights such as access, rectification, erasure, restriction, and data portability. In Microsoft 365, the Data Subject Requests feature in the compliance portal lets you search for a specific person's personal data across Exchange, SharePoint, OneDrive, and Teams, then execute actions like export or delete. This makes it the foundational control for fulfilling individual rights under GDPR, which is why it is correct.

  • ✓

    Data Loss Prevention (DLP) policies

    Why this is correct

    Data Loss Prevention (DLP) policies are a correct GDPR control because they actively prevent the unauthorized sharing of personal data. DLP in Microsoft Purview uses sensitive information types (e.g., EU debit card number, EU passport number) to detect content in emails, documents, and cloud apps, then automatically block actions that exceed allowed policies. This supports GDPR's Article 32 requirement for appropriate technical and organizational measures to protect data confidentiality and mitigate breach risk, directly safeguarding data subjects' privacy.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.