Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Purview to comply with regulatory requirements. Which TWO features should you use to manage data retention and deletion?

⚠ Common exam trap

Many candidates confuse sensitivity labels (which handle classification and protection) with retention labels (which handle retention and deletion), leading them to incorrectly select sensitivity labels as a retention feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data lifecycle management policies (retention policies).

Data lifecycle management policies (retention policies) (A) are correct because they let you centrally define how long content is kept and when it is deleted across Exchange, SharePoint, OneDrive, Teams, and other workloads, satisfying regulatory retention and deletion requirements. Records management (retention labels and disposition) (C) is also correct because it uses retention labels with file plan descriptors, event-based retention, and disposition review to declare items as records and control their deletion with proof of disposition. Sensitivity labels (B) are for classification and protection (encryption, marking, access control), not for retention or deletion timing. Data Loss Prevention (D) policies detect and block risky sharing of sensitive data but do not govern retention periods or deletion. Trainable classifiers (E) identify content types to support classification and labeling, but they do not themselves manage retention or deletion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Data lifecycle management policies (retention policies).

    Why this is correct

    Data lifecycle management policies in Microsoft Purview (formerly Microsoft 365 compliance retention policies) let you automatically retain and then delete content across Exchange, SharePoint, OneDrive, and Teams based on age, event, or location. These policies are organization-wide or scoped via adaptive scopes, and they run continuously without user intervention, providing a primary mechanism to meet regulatory retention requirements. They manage the entire lifecycle from retention to expiration, making them the correct choice for broad compliance mandates.

  • ✗

    Sensitivity labels.

    Why it's wrong here

    Sensitivity labels are a classification and protection mechanism that can encrypt, mark, and restrict access to content, but they do not control retention or deletion. A sensitivity label cannot schedule a retention period or trigger disposition, so it does not directly satisfy regulatory lifecycle obligations. While a sensitivity label can be paired with a retention label through auto-labeling, the actual retention action is performed by the retention label, not the sensitivity label.

  • ✓

    Records management (retention labels and disposition).

    Why this is correct

    Records management uses retention labels to mark content as a record and enforce immutable retention periods, disposition reviews, and event-based triggers. This is a granular, item-level solution that ensures documents declared as records remain tamper-proof until the required regulatory period ends. It is indeed a correct approach for compliance because it provides formal records declaration and lifecycle management, though it is often augmented by broader data lifecycle management policies that cover non-record content.

  • ✗

    Data Loss Prevention (DLP) policies.

    Why it's wrong here

    Data Loss Prevention (DLP) policies protect sensitive information by scanning content and applying protective actions like blocking, warning, or encrypting data in transit and at rest. DLP does not schedule retention, deletion, or disposition, nor does it maintain content for a compliance period. Therefore, DLP is not a mechanism for lifecycle management; it only prevents unauthorized exfiltration or leakage, which is a distinct security control.

  • ✗

    Trainable classifiers.

    Why it's wrong here

    Trainable classifiers are machine-learning models that identify content based on patterns and examples you provide, such as resumes or contracts. They are often used to auto-apply retention labels or retention policies, but the classifiers themselves do not enforce lifecycle rules. They serve only as a detection trigger; without a separate retention rule, classified content will not be retained or deleted, so they cannot be the primary tool for regulatory compliance.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.