SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Purview. You need to design a solution that discovers and classifies sensitive data across Microsoft 365 services. Which two services should you include in your data map? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SharePoint Online
SharePoint Online (B) is correct because it is a core Microsoft 365 workload whose sites, document libraries, and files are scanned by Microsoft Purview's data map via the sensitive information types and trainable classifiers, enabling discovery and classification of sensitive data at rest. OneDrive for Business (D) is also correct because each user's personal Microsoft 365 storage is crawled by the same Purview data map, so documents containing sensitive data are identified and labeled consistently with SharePoint. Power BI (A), Azure SQL Database (C), and Azure Blob Storage (E) are not the intended Microsoft 365 services for this scenario: Power BI is a business analytics service, while Azure SQL Database and Azure Blob Storage are Azure (non-Microsoft 365) data sources that would be covered by separate Purview connectors or Azure-native classification rather than the Microsoft 365 service data map.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Power BI
Why it's wrong here
Power BI is a Microsoft 365 service, but its content is stored in the Power BI service as reports, dashboards, and semantic models, not as documents in SharePoint or OneDrive libraries. Microsoft Purview's M365 compliance classification engine scans document libraries and file streams, not Power BI datasets, so this option does not represent a primary sensitive-data source for the scenario described. Safe Links and DLP for Power BI exist but are not the same as native document classification.
- ✓
SharePoint Online
Why this is correct
SharePoint Online is the primary collaborative document repository in Microsoft 365 where organizations store most sensitive files, including contracts, policies, and confidential records. Microsoft Purview natively indexes SharePoint Online sites and document libraries, allowing sensitivity labels, trainable classifiers, and data loss prevention (DLP) policies to identify and protect sensitive content. Because SharePoint is central to M365 file storage and classification, it is the correct source to include in a Purview data classification design.
- ✗
Azure SQL Database
Why it's wrong here
Azure SQL Database is an Azure platform-as-a-service relational database, not a Microsoft 365 workload, and therefore it is outside the scope of Microsoft Purview's M365 compliance features that inspect SharePoint and OneDrive content. Sensitive data in Azure SQL can be managed through Azure Purview (Data Map) for cataloging and column-level classification, but that is a distinct governance capability from M365 document classification. This wrong answer confuses unstructured file classification in Microsoft 365 with structured data governance in Azure.
- ✓
OneDrive for Business
Why this is correct
OneDrive for Business is the personal file repository for individual users in Microsoft 365, commonly containing sensitive user-generated files such as resumes, drafts, and personal records. Microsoft Purview scans OneDrive for Business alongside SharePoint Online, applying the same sensitivity labels, retention policies, and DLP rules to user-owned files. This makes OneDrive an essential source in a classification design that aims to cover the full M365 document landscape.
- ✗
Azure Blob Storage
Why it's wrong here
Azure Blob Storage is a scalable object storage service in Azure, not a Microsoft 365 workload, and M365 Purview compliance classification does not directly scan blobs as it does SharePoint Online or OneDrive for Business. Blob data can be governed with Azure Purview (Data Map) using catalog connections and custom scanning, but this is a different toolset and administrative boundary. This option is wrong because the question focuses on Microsoft 365 sensitive-data sources, and Blob Storage is an infrastructure-level data store without native M365 compliance integration.
Quick reference
Azure Blob Storage Tier Comparison
| Tier | Storage Cost | Retrieval Cost | Latency | Use Case |
|---|---|---|---|---|
| Hot | Highest | Lowest | Immediate | Active data, frequent reads |
| Cool | Lower | Higher | Immediate | Data accessed < once / month |
| Cold | Lower still | Higher | Immediate | Data accessed < once / quarter |
| Archive | Lowest | Highest + rehydration delay | Hours | Long-term compliance retention |
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.