SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
A company must ensure that sensitive data in SharePoint Online is automatically classified and protected. They want to use built-in Microsoft Purview capabilities. Which feature should they implement?
⚠ Common exam trap
Candidates might confuse the primary purpose of DLP (preventing data loss by blocking specific actions) with the comprehensive classification and persistent protection offered by sensitivity labels. While DLP detects sensitive content and enforces policy actions, sensitivity labels (especially with auto-labeling) explicitly classify the data and apply persistent protection that travels with the content, directly addressing 'automatically classified and protected'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitivity labels
Sensitivity labels in Microsoft Purview can be configured with auto-labeling policies to automatically detect sensitive information (e.g., credit card numbers, PII) in SharePoint Online content. Once detected, the policy automatically applies the appropriate sensitivity label, which then enforces predefined protection actions such as encryption, access restrictions, and visual markings. This directly fulfills the requirement for automatic classification and protection of sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Audit logs
Why it's wrong here
Audit logs record user and administrator activities across Microsoft 365 services, including SharePoint Online, providing a detailed trail of actions like file access, modifications, and sharing events. While crucial for forensic investigations, compliance reporting, and identifying potential security incidents post-factum, audit logs are a reactive tool. They document what happened but do not automatically intervene or prevent sensitive data from being exfiltrated or inappropriately shared in real-time.
- ✓
Sensitivity labels
Why this is correct
Sensitivity labels allow organizations to classify data based on its sensitivity level and apply corresponding protective actions, such as encryption, watermarking, or access restrictions. While auto-labeling can be configured to automatically apply these labels based on content, the labels themselves primarily define how data should be protected and who can access it. They do not inherently provide the active, policy-driven enforcement mechanism to prevent data loss or inappropriate sharing across organizational boundaries, which is the domain of DLP.
- ✗
Data Loss Prevention policies
Why it's wrong here
Data Loss Prevention (DLP) policies are specifically designed to identify, monitor, and automatically protect sensitive information by preventing its unauthorized sharing or exfiltration. In SharePoint Online, DLP policies scan content for sensitive information types (e.g., credit card numbers, national ID numbers) and enforce rules to block sharing, encrypt files, or notify administrators when data attempts to leave the organization or is shared inappropriately, thereby ensuring proactive data protection.
- ✗
Retention policies
Why it's wrong here
Retention policies are primarily used for managing the lifecycle of data within an organization, ensuring that content is preserved for a specified period to meet regulatory, legal, or business requirements, and then disposed of appropriately. While they prevent the premature deletion of data, they do not actively scan for sensitive content to prevent its unauthorized sharing, exfiltration, or misuse. Their focus is on data longevity and compliance, not real-time protection against data loss.
Go deeper
Related to this question
Learn chapter
Entra Internet Access and Private Access
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.