Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

A compliance officer wants to automatically classify emails containing credit card numbers as 'Highly Confidential' and apply encryption. Which Microsoft Purview feature should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Microsoft Purview Data Loss Prevention (DLP)

Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect sensitive information such as credit card numbers and automatically apply protective actions like encryption. Option A is incorrect because sensitivity labels are classification tools that can be applied manually or automatically via DLP, but the automation of encryption based on content is a DLP capability. Option B is incorrect because retention labels are used for data retention and deletion policies, not for encryption. Option C is incorrect because eDiscovery is used for searching and exporting data for legal or investigative purposes, not for automatic classification and encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Microsoft Purview Sensitivity Labels

    Why it's wrong here

    Microsoft Purview Sensitivity Labels define the classification and protection settings, such as encryption or access restrictions, that can be applied to content. However, they are not the active mechanism that automatically scans email content for specific sensitive information types, like credit card numbers, to trigger that classification. While auto-labeling policies can apply sensitivity labels based on content, the underlying detection and enforcement for preventing data loss is typically orchestrated by DLP policies.

  • Microsoft Purview Retention Labels

    Why it's wrong here

    Microsoft Purview Retention Labels are designed for data governance, focusing on the lifecycle management of information by specifying how long content must be retained or when it should be disposed of. They do not provide functionality for real-time content analysis to detect sensitive data patterns, nor do they apply protective actions such as encryption or access controls to prevent data loss. Their purpose is compliance with retention policies, not proactive content-based protection.

  • Microsoft Purview eDiscovery

    Why it's wrong here

    Microsoft Purview eDiscovery tools are utilized for identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI) in response to legal or investigative requests. This is a reactive, post-event process focused on data retrieval and analysis for litigation or compliance audits. eDiscovery is not a proactive or real-time mechanism for automatically classifying emails based on their content to apply protective measures like encryption or prevent data loss.

  • Microsoft Purview Data Loss Prevention (DLP)

    Why this is correct

    Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information across various locations, including email communications. DLP policies leverage sensitive information types (SITs) to detect specific content patterns, such as credit card numbers, and can then automatically apply actions like blocking the email, notifying users, or applying encryption (often via sensitivity labels) to ensure compliance and prevent unauthorized sharing.

About these practice questions

One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to automatically detect emails in Exchange Online that contain credit card numbers and apply encryption to those emails before they are sent. Which Microsoft Purview solution should the administrator configure?

medium
  • A.Information Protection (sensitivity labels)
  • B.Data Loss Prevention (DLP)
  • C.Data Lifecycle Management
  • D.eDiscovery

Why B: Data Loss Prevention (DLP) in Microsoft Purview is specifically designed to detect sensitive information such as credit card numbers in emails and automatically apply protective actions like encryption. DLP policies can scan Exchange Online messages in transit and enforce rules to encrypt the email before it is sent, which directly meets the requirement.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.