Courseiva

SC-100 Practice Question: Design security solutions for applications and data

Your organization uses Microsoft Purview to protect sensitive data. You need to implement a solution that automatically detects and protects personally identifiable information (PII) in Microsoft 365. Which THREE should be part of your solution? (Choose THREE.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Purview Information Protection scanner

Sensitivity labels in Microsoft Purview Information Protection (E) are the core classification mechanism that lets you tag content containing PII so protection (encryption, marking, access restrictions) travels with the data across Microsoft 365 workloads. Microsoft Purview Data Loss Prevention (DLP) policies (D) automatically detect PII using sensitive information types and then block, warn, or audit risky sharing in Exchange Online, SharePoint, OneDrive, Teams, and endpoint locations. The Microsoft Purview Information Protection scanner (C) extends that same labeling and protection to on-premises file shares and SharePoint Server repositories, which is required for a complete PII detection and protection solution. Azure Policy (A) governs Azure resource compliance and cannot classify or protect PII in Microsoft 365 content, and Microsoft Defender for Cloud (B) is a cloud security posture and workload protection service, not a data classification or DLP tool for Microsoft 365 PII.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is an Azure governance service that evaluates and enforces compliance of Azure resource configurations (such as allowed regions, VM SKUs, and tagging) at the control plane. It operates at the infrastructure level and cannot inspect the content of documents or emails, so it lacks the data-plane scanning and classification capabilities required to detect PII like national IDs or apply sensitivity labels to data. While Azure Policy can enforce protective measures across subscriptions, it does not scan data content, making it inapplicable to this scenario.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud focuses on securing cloud infrastructure across multicloud and hybrid environments, not on classifying or applying sensitivity labels to PII within Microsoft 365 content. It is tempting because its name suggests broad protection capabilities, and it would be correct for detecting threats to virtual machines or storage accounts, but it lacks the data classification and auto-labelling engines that Purview Information Protection provides for documents and emails.

  • ✓

    Microsoft Purview Information Protection scanner

    Why this is correct

    The Microsoft Purview Information Protection scanner is a forensic data-discovery engine that runs on Windows Server and scans on-premises repositories, including file shares, SharePoint Server, and SQL Server, for sensitive content. Using built-in or custom sensitive information types, it detects PII such as passport numbers, addresses, and bank details, and can automatically apply sensitivity labels via the same label administration used across Microsoft 365. It supports both discover-and-report and enforce modes, and its results feed into analytics and DLP policy evaluation. This makes it a correct choice because it directly scans content and applies protection at the data source.

  • ✓

    Microsoft Purview Data Loss Prevention (DLP) policies

    Why this is correct

    Microsoft Purview DLP policies take a content-aware approach to protecting PII by inspecting data in transit and at rest across multiple workloads, including Exchange Online, SharePoint, OneDrive, Teams, and Windows endpoints. Unlike a pure classifier, DLP policies implement enforcement actions: when a sensitive information type or suspicious activity is matched, they can block sharing, quarantine content, restrict external access, or trigger policy tips and incident reports. They rely on sensitive information types or sensitivity labels as detection conditions, and their granular rule conditions can tailor protection to specific users or domains. Therefore, DLP policies satisfy the requirement by both detecting PII and enforcing protection measures.

  • ✓

    Sensitivity labels in Microsoft Purview Information Protection

    Why this is correct

    Sensitivity labels are persistent metadata tags that classify and protect content wherever it travels, with capabilities for encryption, watermarking, and conditional access restrictions. When a label is applied, it embeds rights management information that follows the document or email, enabling organizations to enforce policies such as read-only or do-not-forward even after the content leaves the organization. Labels can be assigned automatically through DLP policies, autolabeling, or end-user manual selection, and they integrate with the scanner and DLP to extend protection. Because labels provide both the classification and the protective enforcement layer, they are a correct answer for protecting PII.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.