Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A company must implement data classification labels in Microsoft Purview to protect sensitive information. Which TWO actions are required to create and publish a sensitivity label?

⚠ Common exam trap

Test-takers frequently confuse the optional configuration steps (like defining scope or auto-labeling) with the mandatory actions required to create and publish a sensitivity label, leading them to select B or E instead of the correct pair C and D.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create the label in the Microsoft Purview compliance portal.

Option C is correct because every sensitivity label must first be created in the Microsoft Purview compliance portal (Solutions > Information protection > Labels), where you define its name, description, and encryption/content-marking settings. Option D is correct because a label only becomes available to users and services after it is published through a label policy, which defines the users/groups and the locations (workloads) where the label is applied. Options A, B, and E are not required: labels are not deployed via Intune configuration profiles, the label scope (SharePoint/OneDrive, Exchange, etc.) is selected inside the label policy rather than being a separate mandatory action, and auto-labeling rules are configured in Microsoft Purview (not Microsoft 365 Defender) and are optional for creating and publishing a label.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the label using Microsoft Intune configuration profiles.

    Why it's wrong here

    Deploying sensitivity labels is not accomplished through Microsoft Intune configuration profiles. Intune is primarily designed for managing device and application settings, as well as deploying applications. Sensitivity labels, which are part of Microsoft Purview Information Protection, are instead managed and published directly from the Microsoft Purview compliance portal, with client-side functionality relying on Microsoft 365 Apps for enterprise or the Azure Information Protection unified labeling client to receive and apply these policies.

  • ✗

    Define the label scope to include SharePoint and OneDrive.

    Why it's wrong here

    While defining the scope of a sensitivity label (e.g., for files and emails, meetings, Teams, or databases) is an integral part of the label's configuration, it occurs *during* the label creation process within the Microsoft Purview compliance portal. It is not a separate, distinct required action that must be performed *after* a label is created or *before* it is published. The question asks for a standalone required action to implement labels, and scope definition is an attribute of the label itself.

  • ✓

    Create the label in the Microsoft Purview compliance portal.

    Why this is correct

    Creating the sensitivity label in the Microsoft Purview compliance portal is the foundational and indispensable first step for implementing data classification. This action involves defining the label's name, description, visual markings, and associated protection settings like encryption or access restrictions. Without this initial creation, no label exists to be published or applied, making it the absolute prerequisite for any data classification initiative using Microsoft Purview Information Protection.

  • ✓

    Publish the label using a label policy.

    Why this is correct

    After a sensitivity label has been successfully created, it must be explicitly published using a sensitivity label policy within the Microsoft Purview compliance portal. Publishing makes the label visible and available for users to apply to their documents and emails, or for services to apply automatically. This policy specifies which users or groups will have access to the label and across which Microsoft 365 services, ensuring targeted deployment and control.

  • ✗

    Configure auto-labeling rules in Microsoft 365 Defender.

    Why it's wrong here

    Configuring auto-labeling rules is an optional, advanced capability designed to automatically apply sensitivity labels based on content inspection, such as detecting specific sensitive information types. While highly beneficial for scaling data governance, it is not a mandatory step for the fundamental implementation of data classification labels. Furthermore, these auto-labeling rules for sensitivity labels are configured within the Microsoft Purview compliance portal, not Microsoft 365 Defender, which focuses on threat protection.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.