Courseiva

SC-100 Practice Question: Design security operations, identity, and compliance capabilities

Your organization uses Microsoft Purview to protect sensitive data. You need to create a sensitivity label that automatically encrypts documents containing credit card numbers when they are shared externally. Which configuration should you use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an auto-labeling policy that applies a label with encryption for external sharing

Auto-labeling in Purview can be configured to apply a sensitivity label based on sensitive info types like credit card numbers. The label should have encryption enabled for external sharing. The other options describe different scenarios: manual labeling, default labeling, or classification without encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a trainable classifier to detect credit cards

    Why it's wrong here

    A trainable classifier in Microsoft Purview is a machine-learning model that recognizes content patterns, such as credit card numbers, but it is purely a detection mechanism. By itself, it cannot apply a sensitivity label or trigger encryption; it only identifies content that can be used as a condition in other policies. To protect the detected data, you must pair the classifier with an auto-labeling policy that takes the action of applying an encrypted label. Thus, while this is a valid detection method, it does not meet the requirement for automatic protection on its own.

  • ✓

    Create an auto-labeling policy that applies a label with encryption for external sharing

    Why this is correct

    An auto-labeling policy in Microsoft Purview can automatically detect credit card numbers using sensitive information types or classifiers and then apply a sensitivity label that is configured with encryption. By specifying that the label be applied only when content is shared externally, the policy ensures that documents containing credit card data are encrypted upon external sharing, while internal collaboration remains unaffected. This satisfies the requirement for automatic, content-aware protection without user intervention, making it the correct solution.

  • ✗

    Create a default label policy for SharePoint

    Why it's wrong here

    A default label policy for SharePoint assigns a specified sensitivity label to every document in a site or library, regardless of its content. Because it does not evaluate whether credit card numbers are present, it either over-encrypts all documents (if the label has encryption) or leaves sensitive data unprotected (if the label lacks encryption). This static approach fails to target only documents that contain credit card information, and it does not react to external sharing events. Therefore, it cannot fulfill the requirement for content-based, automatic protection.

  • ✗

    Create a manual sensitivity label that users apply

    Why it's wrong here

    Manual sensitivity labeling depends entirely on users to recognize and classify documents containing credit card numbers. This approach is inherently error-prone and inconsistent, as users may forget to apply a label, misinterpret the content, or apply an incorrect label without encryption. Even if a manual label includes encryption, it is not automatically triggered by external sharing, and enforcement relies on user compliance. Consequently, manual labeling does not provide the automatic, reliable protection required for sensitive credit card data.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.