Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization stores sensitive customer data in Azure Blob Storage. You need to implement data classification and labeling using Microsoft Purview. Which resource should you use to automatically scan and classify the data?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Data Map

Microsoft Purview Data Map is the correct choice because it is the foundational service that performs automated scanning, data discovery, and classification of data sources such as Azure Blob Storage, populating the catalog with sensitivity labels and classifications. It uses scan rule sets and classification rules to detect sensitive data types across registered sources. Azure Policy is a governance service for enforcing resource compliance, not for scanning and classifying data content. Microsoft Purview Information Protection applies sensitivity labels to files and emails but does not itself scan and classify data at rest in Blob Storage. Microsoft Purview Data Loss Prevention enforces policies to prevent data exfiltration, not to discover and classify stored data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is an Azure-native governance service that evaluates and enforces compliance rules against resource properties, such as allowed locations, SKUs, or tags, during create/update and continuously over the resource hierarchy. It does not inspect the content of blobs nor apply data classification labels; it works at the control plane and resource configuration level, not the data plane. Therefore, it cannot automatically discover or classify sensitive customer data stored in Azure Blob Storage, making it unsuitable for this requirement.

  • ✓

    Microsoft Purview Data Map

    Why this is correct

    Microsoft Purview Data Map is the correct choice because it performs automated metadata scanning and classification of assets across data sources, including Azure Blob Storage. It uses built-in system classification rules and custom classification rules to inspect actual data content (e.g., regex, keywords) and applies classifications like "Person's Name" or "Credit Card Number" to the schema and data. These classifications are then used in the Data Catalog, enabling sensitivity reporting and integration with information protection for labeling. It does not enforce access control or policy, but it is specifically designed for data discovery and classification at scale.

  • ✗

    Microsoft Purview Information Protection

    Why it's wrong here

    Microsoft Purview Information Protection (formerly Azure Information Protection) focuses on applying sensitivity labels and protection policies to documents and emails either manually by users or via recommended/automatic labeling rules based on patterns or custom conditions. While it can classify and protect data, it requires the data to be already scanned or labeled, and its automatic labeling typically works on files at rest on endpoints or in Microsoft 365, not by scanning Azure Blob Storage assets directly. For a central, automated scan-and-classify of blobs without user intervention, Data Map's scanning capabilities are the appropriate mechanism, not Information Protection alone.

  • ✗

    Microsoft Purview Data Loss Prevention

    Why it's wrong here

    Microsoft Purview Data Loss Prevention (DLP) is designed to detect and prevent the unintentional sharing, transfer, or exfiltration of sensitive data across services such as Exchange Online, SharePoint, OneDrive, Teams, and endpoints. DLP policies match sensitive information types in transit or in use and enforce actions like blocking or alerting, but they do not perform background scanning and classification of all assets in Azure Blob Storage for cataloging. The requirement is to automatically scan and classify stored data, which is Data Map's role; DLP is a reactive control, not a discovery/classification engine.

Quick reference

Azure Blob Storage Tier Comparison

TierStorage CostRetrieval CostLatencyUse Case
HotHighestLowestImmediateActive data, frequent reads
CoolLowerHigherImmediateData accessed < once / month
ColdLower stillHigherImmediateData accessed < once / quarter
ArchiveLowestHighest + rehydration delayHoursLong-term compliance retention

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.