SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A compliance officer wants to automatically classify emails containing credit card numbers as 'Highly Confidential' and apply encryption. Which Microsoft Purview feature should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Purview Data Loss Prevention (DLP)
Microsoft Purview Data Loss Prevention (DLP) policies are designed to detect sensitive information such as credit card numbers and automatically apply protective actions like encryption. Option A is incorrect because sensitivity labels are classification tools that can be applied manually or automatically via DLP, but the automation of encryption based on content is a DLP capability. Option B is incorrect because retention labels are used for data retention and deletion policies, not for encryption. Option C is incorrect because eDiscovery is used for searching and exporting data for legal or investigative purposes, not for automatic classification and encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Purview Sensitivity Labels
Why it's wrong here
Microsoft Purview Sensitivity Labels define the classification and protection settings, such as encryption or access restrictions, that can be applied to content. However, they are not the active mechanism that automatically scans email content for specific sensitive information types, like credit card numbers, to trigger that classification. While auto-labeling policies can apply sensitivity labels based on content, the underlying detection and enforcement for preventing data loss is typically orchestrated by DLP policies.
- ✗
Microsoft Purview Retention Labels
Why it's wrong here
Microsoft Purview Retention Labels are designed for data governance, focusing on the lifecycle management of information by specifying how long content must be retained or when it should be disposed of. They do not provide functionality for real-time content analysis to detect sensitive data patterns, nor do they apply protective actions such as encryption or access controls to prevent data loss. Their purpose is compliance with retention policies, not proactive content-based protection.
- ✗
Microsoft Purview eDiscovery
Why it's wrong here
Microsoft Purview eDiscovery tools are utilized for identifying, preserving, collecting, processing, reviewing, and analyzing electronically stored information (ESI) in response to legal or investigative requests. This is a reactive, post-event process focused on data retrieval and analysis for litigation or compliance audits. eDiscovery is not a proactive or real-time mechanism for automatically classifying emails based on their content to apply protective measures like encryption or prevent data loss.
- ✓
Microsoft Purview Data Loss Prevention (DLP)
Why this is correct
Microsoft Purview Data Loss Prevention (DLP) policies are specifically engineered to identify, monitor, and protect sensitive information across various locations, including email communications. DLP policies leverage sensitive information types (SITs) to detect specific content patterns, such as credit card numbers, and can then automatically apply actions like blocking the email, notifying users, or applying encryption (often via sensitivity labels) to ensure compliance and prevent unauthorized sharing.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Data retention
Data retention is the practice of keeping data for a specific period to meet legal, business, or compliance needs, and then securely disposing of it.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to automatically detect emails in Exchange Online that contain credit card numbers and apply encryption to those emails before they are sent. Which Microsoft Purview solution should the administrator configure?
medium- A.Information Protection (sensitivity labels)
- ✓ B.Data Loss Prevention (DLP)
- C.Data Lifecycle Management
- D.eDiscovery
Why B: Data Loss Prevention (DLP) in Microsoft Purview is specifically designed to detect sensitive information such as credit card numbers in emails and automatically apply protective actions like encryption. DLP policies can scan Exchange Online messages in transit and enforce rules to encrypt the email before it is sent, which directly meets the requirement.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.