SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Purview to govern sensitive data. You need to design a solution that automatically detects and protects credit card numbers in emails and documents stored in Microsoft 365. The solution should also provide data loss prevention (DLP) policy tips to users when they try to share such data externally. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention policies
Microsoft Purview Data Loss Prevention policies (option B) are the correct choice because DLP is the service that detects sensitive information types such as credit card numbers in Exchange Online email and SharePoint/OneDrive documents, and it can enforce protection by blocking or restricting external sharing while displaying policy tips to users in supported apps like Outlook and Office. DLP policies natively support the credit card number sensitive information type and the policy tip configuration for user notifications during external sharing attempts. Sensitivity labels with auto-classification (A) apply classification and protection to content but do not provide DLP policy tips or block external sharing in real time. The Microsoft 365 compliance center (C) is just the administrative portal, not a protection mechanism, and Microsoft Information Protection unified labeling (D) is the labeling infrastructure, not the DLP enforcement engine.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Sensitivity labels with auto-classification
Why it's wrong here
Sensitivity labels with auto-classification classify and protect data by applying metadata and encryption, but they do not generate interactive policy tips in real time. Policy tips are a DLP feature that appears in client apps like Outlook and SharePoint when a user attempts a risky action, such as external sharing or sending sensitive content. Auto-classification only helps assign labels based on content inspection, not to provide user feedback during data sharing events, so this option cannot fulfill the described requirement.
- ✓
Microsoft Purview Data Loss Prevention policies
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) policies are the correct feature because they are purpose-built to detect sensitive data in real time and can trigger interactive policy tips in supported Microsoft 365 apps. When a user tries to share an email, document, or message that contains sensitive information, the DLP policy evaluates the content and displays a non-blocking tip or block action, educating the user and enforcing compliance. Unlike classification-only tools, DLP policies directly implement the user-notification workflow described in the question.
- ✗
Microsoft 365 compliance center
Why it's wrong here
The Microsoft 365 compliance center (now part of Microsoft Purview) is the administrative portal where security teams create and manage DLP policies, sensitivity labels, and other compliance settings. It is not a feature that appears in end-user applications, so it cannot display policy tips to users. Users see policy tips within apps such as Outlook or OneDrive, not in the compliance center itself, so selecting this as the feature that provides the real-time tips is incorrect because it is the management plane, not the enforcement plane.
- ✗
Microsoft Information Protection unified labeling
Why it's wrong here
Microsoft Information Protection (MIP) unified labeling provides the framework for sensitivity labels across Microsoft 365 but is strictly a classification and protection mechanism. It allows labels to define encryption, visual markings, and permissions, but it does not include a DLP engine or policy-tip UI. Although DLP policies can use labels as conditions, the interactive tip that appears to users is generated by the DLP engine, not by the labeling system, making this option an incorrect answer for the specific capability required.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.