SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Purview to manage data governance. You need to create a unified data catalog that automatically classifies and labels data across Azure SQL Database, Amazon S3, and on-premises SQL Server. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview account with scans for all data sources.
The correct option is A: a Microsoft Purview account with scans for all data sources. Microsoft Purview is the unified data governance service that builds a data map and catalog by registering and scanning sources such as Azure SQL Database, Amazon S3, and on-premises SQL Server, then automatically applying built-in and custom classifications and sensitivity labels during those scans. The other options do not fit: Azure Data Catalog is a retired service that lacks automated classification and labeling, Azure Purview (legacy) is the former branding of the same service and not the current configuration, and the Microsoft Information Protection scanner only discovers and labels sensitive files on file shares and on-premises repositories, not cloud databases or S3 buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Purview account with scans for all data sources.
Why this is correct
A Microsoft Purview account is the correct choice because it provides an automated, unified data governance solution that scans and catalogs metadata from all data sources, including on-premises, Azure, AWS, Google Cloud, and SaaS applications. This enables centralized data discovery, classification, lineage, and policy enforcement. Unlike legacy or single-purpose tools, it creates a comprehensive data map for the entire organization.
- ✗
Azure Data Catalog with custom classification.
Why it's wrong here
Azure Data Catalog is an outdated service that has been retired in favor of Microsoft Purview and does not support automated scanning of modern multi-cloud data sources. It relies on manual registration and offers only basic tagging and custom classification, lacking advanced features like automated lineage, sensitivity labels, and integrated policy management. Consequently, it cannot provide the enterprise-wide governance required for the organization's data.
- ✗
Azure Purview (legacy) with multi-cloud scanning.
Why it's wrong here
This option incorrectly refers to the current service as 'Azure Purview (legacy)'; Microsoft Purview is the active and official name, and its multi-cloud scanning capability is fully supported. Labelling it as 'legacy' is inaccurate and obscures the fact that it is the recommended, forward-looking solution. The answer is wrong only because of the outdated naming and the false implication that it is a discontinued product.
- ✗
Microsoft Information Protection scanner on each source.
Why it's wrong here
The Microsoft Information Protection scanner is an agent-based tool that discovers and classifies sensitive data only in on-premises file shares, SharePoint, and SQL Server, not in cloud or SaaS sources. It does not build a unified data catalog or provide data lineage, governance, and compliance features across heterogeneous environments. Relying on it for each source would yield fragmented classification with no centralized management, so it fails to meet the requirement for a comprehensive governance solution.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.