Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Purview and needs to automatically apply a retention label to all documents containing personally identifiable information (PII) in SharePoint Online. What should you configure?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-labeling policy

An auto-labeling policy in Microsoft Purview is the correct choice because it can automatically apply a retention label to SharePoint Online content when items match specified sensitive information types such as PII, without user intervention. Auto-labeling policies are designed specifically for automatic retention label application at scale across locations like SharePoint, OneDrive, and Exchange. A DLP policy is used to detect and prevent sharing or leakage of sensitive data, not to apply retention labels. A service-side sensitivity label applies encryption/marking for sensitivity, not retention, and a trainable classifier identifies content categories but does not by itself apply retention labels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Auto-labeling policy

    Why this is correct

    In Microsoft Purview, an auto-labeling policy applies retention labels automatically to SharePoint Online documents based on sensitive information types, such as PII, using content pattern detection. This satisfies the stem’s constraint of automatic application without user intervention, unlike manual or default label policies, which require user action or static inheritance.

  • ✗

    Data loss prevention (DLP) policy

    Why it's wrong here

    A DLP policy in Microsoft Purview is a security control that detects sensitive information like PII during events such as sharing or exfiltration, and takes actions to block, alert, or restrict access. However, a DLP policy's native actions do not include assigning retention labels to files; retention labels are managed by retention/records management policies, not by DLP rules. Even though DLP also uses sensitive information types for pattern matching, it is designed to prevent data loss, not to classify content for lifecycle retention, making it unsuitable for this requirement.

  • ✗

    Service-side sensitivity label

    Why it's wrong here

    A service-side sensitivity label (also known as a default label) is configured on a container such as a SharePoint site or OneDrive library and is automatically inherited by all new files created in that container. This inheritance is based on the container's pre-configured label, not on an analysis of each file's content, so it would apply the label uniformly to everything, not selectively to documents containing PII. Moreover, sensitivity labels are distinct from retention labels; sensitivity labels control protection/classification, while a retention label is required for lifecycle management. Thus, this option does not meet the requirement of content-based automatic retention labeling.

  • ✗

    Trainable classifier

    Why it's wrong here

    Trainable classifiers are unsuitable for automatically identifying personally identifiable information (PII) because PII detection primarily relies on sensitive information types (SITs), which use pattern matching for known data types. Trainable classifiers are designed to identify custom content types based on examples, such as specific project documents or HR forms, where no pre-defined patterns exist. They are tempting as they can be integrated with auto-apply retention policies, but their purpose is for classifying unstructured data that does not contain standard PII patterns, making them the correct choice for organisation-specific content classification.

About these practice questions

One of 605 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.