SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization needs to meet compliance requirements for GDPR. You need to design a solution that uses Microsoft Purview to classify and protect personal data. Which TWO capabilities should you include?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Subject Requests (DSR) tool
The Data Subject Requests (DSR) tool (A) is correct because GDPR grants individuals rights over their personal data (access, rectification, erasure, portability), and the Microsoft Purview DSR tool provides a workflow to discover, review, and respond to these requests across Microsoft 365 data sources. Data Classification and labeling (B) is correct because GDPR requires identifying and protecting personal data, and Purview's sensitive information types, trainable classifiers, and sensitivity labels let you automatically classify and apply protection such as encryption and access restrictions. eDiscovery (Premium) (C) is not the right fit because it is designed for legal investigations and litigation hold workflows, not for fulfilling GDPR data subject rights or building a classification/protection scheme. Insider Risk Management (D) addresses detecting and mitigating risky user behavior, which supports security but does not directly satisfy GDPR classification, protection, or DSR obligations. Communication Compliance (E) focuses on monitoring communications for policy violations such as harassment or regulatory breaches, which is unrelated to classifying and protecting personal data for GDPR compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data Subject Requests (DSR) tool
Why this is correct
The DSR tool in Microsoft Purview is the correct choice because it operationalizes GDPR Article 15-21 individual rights: access, rectification, erasure, restriction, processing objection, and portability. It lets administrators search across Exchange, SharePoint, OneDrive, and Teams for a data subject's content, then generate a downloadable report for review and action, including the ability to close out the request in a auditable manner. It is specifically designed for these privacy obligations, not for general content discovery.
- ✓
Data Classification and labeling
Why this is correct
Data Classification and labeling, implemented via Microsoft Information Protection (MIP) and Purview Data Map, is correct because GDPR requires you to know what personal data you hold and where it resides. By classifying content based on sensitivity and personal data type (e.g., EU citizen ID, financial data), you can apply protective labels and retention policies, and you can locate and prioritize data for DSR fulfillment. This proactive discovery and labeling is a foundational step for any GDPR compliance posture.
- ✗
eDiscovery (Premium)
Why it's wrong here
eDiscovery (Premium) is incorrect because it is engineered for legal investigation and litigation, not GDPR compliance. While it can preserve, hold, search, and collect content in-place for a legal matter, it lacks the purpose-built DSR workflow, such as the ability to handle deletion requests with the required response timelines and audit trails. Its keyword and query-based search may find some data about an individual, but it does not classify personal data or enforce GDPR rights across an enterprise.
- ✗
Insider Risk Management
Why it's wrong here
Insider Risk Management is incorrect for GDPR compliance because its function is to detect, score, and investigate potentially malicious user activities such as unauthorized data exfiltration, IP theft, or policy violations. It looks at user behavior and risk indicators inside the organization, not at the existence or handling of personal data belonging to data subjects. GDPR obligations like DSR responsiveness and data minimization are not addressed by this security-focused tool.
- ✗
Communication Compliance
Why it's wrong here
Communication Compliance is not a GDPR compliance requirement because it is designed to monitor communications (email, Teams, Yammer, third-party platforms) for policy issues like inappropriate content, harassment, or regulatory recordkeeping breaches. It can detect keywords or sensitive-information types, but its output is a workflow for supervisory review and remediation of policy violations, not a mechanism for honoring data subject rights or managing personal data inventories. There is no capability for filing, tracking, or completing GDPR data subject requests within Communication Compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-100
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Your organization needs to comply with GDPR. You need to design a data protection strategy using Microsoft Purview. Which THREE capabilities should you include?
easy- A.Azure Policy
- B.eDiscovery
- ✓ C.Data classification and labeling
- ✓ D.Data subject request management
- ✓ E.Data Loss Prevention (DLP) policies
Why C: Data classification and labeling (C) is essential because Microsoft Purview sensitivity labels and trainable classifiers identify and tag personal data, which is the foundation for applying GDPR-mandated protections. Data subject request management (D) directly supports GDPR data subject rights (access, erasure, portability) by using Purview's Data Subject Request case tooling to find and act on personal data across Microsoft 365. Data Loss Prevention policies (E) enforce GDPR's protection and breach-prevention requirements by detecting sensitive information types (such as EU identifiers) and blocking or auditing their improper sharing. Azure Policy (A) governs Azure resource compliance, not the discovery, classification, or protection of personal data in Purview, and eDiscovery (B) is a legal-hold and investigation tool rather than a GDPR data protection control, so neither belongs in this strategy.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.