Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A company is implementing Microsoft Purview Information Protection. They want to automatically apply a 'Confidential' sensitivity label to emails containing credit card numbers. Which policy should they configure?

⚠ Common exam trap

SC-900 often tests the distinction between policies that apply labels automatically versus those that require manual application or serve other purposes, so candidates must remember that auto-labeling policies are specifically for automatic classification based on content inspection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-labeling policy

An auto-labeling policy in Microsoft Purview Information Protection is designed to automatically apply sensitivity labels to content that matches specific conditions, such as the presence of credit card numbers (a sensitive information type). This policy scans emails and files for sensitive data and applies the appropriate label without user intervention. Retention and DLP policies serve different purposes, and sensitivity label policies publish labels but do not automatically apply them based on content inspection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Auto-labeling policy

    Why this is correct

    Auto-labeling policies in Microsoft Purview scan Exchange, SharePoint and OneDrive content for sensitive information types such as credit card numbers, then apply the Confidential label automatically without user input. This satisfies the requirement for automatic labelling of emails, unlike manual or default labelling policies.

  • ✗

    Retention policy

    Why it's wrong here

    A retention policy governs how long content is kept, deleted or preserved, and applies no sensitivity label. It is tempting because it is also configured in Microsoft Purview against mailbox locations, and would be correct when the requirement is a retention or deletion period rather than classification.

  • ✗

    Sensitivity label policy

    Why it's wrong here

    A sensitivity label policy publishes labels to users and can auto-apply them, but auto-labelling for emails at rest or in transit requires an auto-labelling policy configured with the credit card sensitive information type. It is tempting because it is the label-side control, and would be correct for making labels available to users.

  • ✗

    Data loss prevention (DLP) policy

    Why it's wrong here

    A DLP policy detects sensitive content and blocks or warns on sharing, but does not stamp a sensitivity label onto the email. It is tempting because credit card numbers are a DLP sensitive information type, and DLP is correct when the requirement is to prevent exfiltration rather than classify.

Go deeper

Related to this question

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.