SC-100 Practice Question: Design security solutions for applications and data
Your organization stores sensitive customer data in Azure Blob Storage. You need to implement data classification and labeling using Microsoft Purview. Which resource should you use to automatically scan and classify the data?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Map
Microsoft Purview Data Map is the correct choice because it is the foundational service that performs automated scanning, data discovery, and classification of data sources such as Azure Blob Storage, populating the catalog with sensitivity labels and classifications. It uses scan rule sets and classification rules to detect sensitive data types across registered sources. Azure Policy is a governance service for enforcing resource compliance, not for scanning and classifying data content. Microsoft Purview Information Protection applies sensitivity labels to files and emails but does not itself scan and classify data at rest in Blob Storage. Microsoft Purview Data Loss Prevention enforces policies to prevent data exfiltration, not to discover and classify stored data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is an Azure-native governance service that evaluates and enforces compliance rules against resource properties, such as allowed locations, SKUs, or tags, during create/update and continuously over the resource hierarchy. It does not inspect the content of blobs nor apply data classification labels; it works at the control plane and resource configuration level, not the data plane. Therefore, it cannot automatically discover or classify sensitive customer data stored in Azure Blob Storage, making it unsuitable for this requirement.
- ✓
Microsoft Purview Data Map
Why this is correct
Microsoft Purview Data Map is the correct choice because it performs automated metadata scanning and classification of assets across data sources, including Azure Blob Storage. It uses built-in system classification rules and custom classification rules to inspect actual data content (e.g., regex, keywords) and applies classifications like "Person's Name" or "Credit Card Number" to the schema and data. These classifications are then used in the Data Catalog, enabling sensitivity reporting and integration with information protection for labeling. It does not enforce access control or policy, but it is specifically designed for data discovery and classification at scale.
- ✗
Microsoft Purview Information Protection
Why it's wrong here
Microsoft Purview Information Protection (formerly Azure Information Protection) focuses on applying sensitivity labels and protection policies to documents and emails either manually by users or via recommended/automatic labeling rules based on patterns or custom conditions. While it can classify and protect data, it requires the data to be already scanned or labeled, and its automatic labeling typically works on files at rest on endpoints or in Microsoft 365, not by scanning Azure Blob Storage assets directly. For a central, automated scan-and-classify of blobs without user intervention, Data Map's scanning capabilities are the appropriate mechanism, not Information Protection alone.
- ✗
Microsoft Purview Data Loss Prevention
Why it's wrong here
Microsoft Purview Data Loss Prevention (DLP) is designed to detect and prevent the unintentional sharing, transfer, or exfiltration of sensitive data across services such as Exchange Online, SharePoint, OneDrive, Teams, and endpoints. DLP policies match sensitive information types in transit or in use and enforce actions like blocking or alerting, but they do not perform background scanning and classification of all assets in Azure Blob Storage for cataloging. The requirement is to automatically scan and classify stored data, which is Data Map's role; DLP is a reactive control, not a discovery/classification engine.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.