SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A company is implementing data classification in Microsoft Purview. Which THREE of the following are types of sensitive information that can be detected using built-in sensitive information types?
⚠ Common exam trap
Watch out — candidates often confuse 'sensitive information' with any confidential data, but Microsoft Purview's built-in types are strictly predefined for regulated data (e.g., PII, PCI, medical) and do not include arbitrary organizational secrets like codenames or personal preferences.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Passport numbers
Microsoft Purview ships with numerous built-in sensitive information types (SITs) that use pattern matching, checksums, and keyword evidence to detect common regulated data. Option A (Passport numbers) is correct because Purview includes built-in SITs for passport numbers of multiple countries (for example, U.S. and EU passport formats). Option B (Social security numbers) is correct because the U.S. Social Security Number (SSN) SIT is a core built-in type that matches the 3-2-4 digit pattern with additional validation. Option C (Credit card numbers) is correct because Purview provides built-in SITs for major card brands (Visa, Mastercard, American Express, Discover) that validate the number using the Luhn algorithm. Options D (Favorite color) and E (Project codenames) are not built-in SITs; these are arbitrary, organization-specific data elements that would require custom sensitive information types or trainable classifiers to detect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Passport numbers
Why this is correct
Passport numbers are definitively a built-in sensitive information type (SIT) within Microsoft Purview due to their direct association with an individual's identity and their critical role in international travel and verification processes. Disclosure of passport numbers poses a significant risk of identity theft and fraud, making their protection essential under various data privacy regulations worldwide. Microsoft Purview includes robust definitions to accurately detect and classify these globally recognized identifiers.
- ✓
Social security numbers
Why this is correct
Social Security Numbers (SSNs) are a prime example of a built-in sensitive information type in Microsoft Purview, primarily due to their critical role in identifying individuals within the United States for employment, taxation, and benefits. The unauthorized disclosure of an SSN carries a high risk of identity theft and financial fraud, necessitating stringent protection under numerous US federal and state privacy laws. Purview's built-in SITs are specifically designed to detect these highly regulated identifiers.
- ✓
Credit card numbers
Why this is correct
Credit card numbers (CCNs) are a crucial built-in sensitive information type in Microsoft Purview, recognized globally for their direct link to an individual's financial accounts and purchasing power. Their protection is mandated by industry standards such as the Payment Card Industry Data Security Standard (PCI DSS) and various consumer protection laws. Microsoft Purview's definitions are highly effective at identifying these numerical patterns, which are frequently targeted in data breaches due to their immediate monetary value.
- ✗
Favorite color
Why it's wrong here
"Favorite color" is not considered a sensitive information type by Microsoft Purview because it does not represent personally identifiable information (PII), financial data, or any other category of data that typically requires protection under privacy regulations like GDPR or HIPAA. This attribute is generally public knowledge and does not pose a significant risk if disclosed, thus it lacks the characteristics that would warrant classification as sensitive.
- ✗
Project codenames
Why it's wrong here
Project codenames, while potentially confidential and proprietary to a specific organization, are not recognized as a built-in sensitive information type (SIT) within Microsoft Purview. These unique identifiers lack the universal patterns and regulatory significance that characterize pre-defined SITs like financial or health data. To classify project codenames, an organization would need to create custom sensitive information types using keyword dictionaries, regular expressions, or functions specific to their internal naming conventions.
Go deeper
Related to this question
Learn chapter
Common Attack Types: Phishing, Ransomware, DDoS
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.