SC-100 Practice Question: Design security solutions for applications and data
Your organization uses Microsoft Purview to protect sensitive data. You need to implement a solution that automatically detects and protects personally identifiable information (PII) in Microsoft 365. Which THREE should be part of your solution? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Information Protection scanner
Sensitivity labels in Microsoft Purview Information Protection (E) are the core classification mechanism that lets you tag content containing PII so protection (encryption, marking, access restrictions) travels with the data across Microsoft 365 workloads. Microsoft Purview Data Loss Prevention (DLP) policies (D) automatically detect PII using sensitive information types and then block, warn, or audit risky sharing in Exchange Online, SharePoint, OneDrive, Teams, and endpoint locations. The Microsoft Purview Information Protection scanner (C) extends that same labeling and protection to on-premises file shares and SharePoint Server repositories, which is required for a complete PII detection and protection solution. Azure Policy (A) governs Azure resource compliance and cannot classify or protect PII in Microsoft 365 content, and Microsoft Defender for Cloud (B) is a cloud security posture and workload protection service, not a data classification or DLP tool for Microsoft 365 PII.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy is an Azure governance service that evaluates and enforces compliance of Azure resource configurations (such as allowed regions, VM SKUs, and tagging) at the control plane. It operates at the infrastructure level and cannot inspect the content of documents or emails, so it lacks the data-plane scanning and classification capabilities required to detect PII like national IDs or apply sensitivity labels to data. While Azure Policy can enforce protective measures across subscriptions, it does not scan data content, making it inapplicable to this scenario.
- ✗
Microsoft Defender for Cloud
Why it's wrong here
Microsoft Defender for Cloud focuses on securing cloud infrastructure across multicloud and hybrid environments, not on classifying or applying sensitivity labels to PII within Microsoft 365 content. It is tempting because its name suggests broad protection capabilities, and it would be correct for detecting threats to virtual machines or storage accounts, but it lacks the data classification and auto-labelling engines that Purview Information Protection provides for documents and emails.
- ✓
Microsoft Purview Information Protection scanner
Why this is correct
The Microsoft Purview Information Protection scanner is a forensic data-discovery engine that runs on Windows Server and scans on-premises repositories, including file shares, SharePoint Server, and SQL Server, for sensitive content. Using built-in or custom sensitive information types, it detects PII such as passport numbers, addresses, and bank details, and can automatically apply sensitivity labels via the same label administration used across Microsoft 365. It supports both discover-and-report and enforce modes, and its results feed into analytics and DLP policy evaluation. This makes it a correct choice because it directly scans content and applies protection at the data source.
- ✓
Microsoft Purview Data Loss Prevention (DLP) policies
Why this is correct
Microsoft Purview DLP policies take a content-aware approach to protecting PII by inspecting data in transit and at rest across multiple workloads, including Exchange Online, SharePoint, OneDrive, Teams, and Windows endpoints. Unlike a pure classifier, DLP policies implement enforcement actions: when a sensitive information type or suspicious activity is matched, they can block sharing, quarantine content, restrict external access, or trigger policy tips and incident reports. They rely on sensitive information types or sensitivity labels as detection conditions, and their granular rule conditions can tailor protection to specific users or domains. Therefore, DLP policies satisfy the requirement by both detecting PII and enforcing protection measures.
- ✓
Sensitivity labels in Microsoft Purview Information Protection
Why this is correct
Sensitivity labels are persistent metadata tags that classify and protect content wherever it travels, with capabilities for encryption, watermarking, and conditional access restrictions. When a label is applied, it embeds rights management information that follows the document or email, enabling organizations to enforce policies such as read-only or do-not-forward even after the content leaves the organization. Labels can be assigned automatically through DLP policies, autolabeling, or end-user manual selection, and they integrate with the scanner and DLP to extend protection. Because labels provide both the classification and the protective enforcement layer, they are a correct answer for protecting PII.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.