SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A healthcare organization must comply with HIPAA regulations. They use Microsoft Purview to classify and label patient data. Which Microsoft Purview capability helps them enforce data protection policies automatically?
⚠ Common exam trap
SC-900 often tests the distinction between classification (sensitivity labels) and enforcement (DLP policies)—candidates pick sensitivity labels because they sound like the protection mechanism, but the question asks for automatic enforcement of policies, which is DLP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data loss prevention (DLP) policies
Data loss prevention (DLP) policies in Microsoft Purview are designed to automatically detect sensitive information (such as HIPAA-regulated data) and enforce protection actions like blocking sharing or applying encryption. DLP uses sensitivity labels and sensitive information types to identify content and then applies policy actions automatically across Exchange, SharePoint, OneDrive, and Teams. This directly enforces data protection policies without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
eDiscovery
Why it's wrong here
eDiscovery identifies and collects content for legal or investigative review; it does not evaluate labels and enforce protective actions on data at rest or in transit. It is tempting because it operates across the same Purview data estate, and it would be correct for locating evidence during litigation or regulatory investigation.
- ✗
Audit logs
Why it's wrong here
Audit logs record user and admin activity for later review; they provide visibility after an event rather than automatically enforcing protection when labelled data is accessed or shared. They are tempting because they cover the same workloads, and they would be correct for compliance reporting and forensic investigation.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels classify and mark content, but enforcement of protection actions such as encryption or blocking sharing comes from policies built on those labels, not the labels alone. They are tempting because they drive classification, and they would be correct for applying persistent protection to documents and emails.
- ✓
Data loss prevention (DLP) policies
Why this is correct
DLP policies in Microsoft Purview detect sensitive information types and sensitivity labels, then automatically block sharing, restrict access, or warn users. This enforces HIPAA protection without manual review, satisfying the requirement to apply safeguards automatically across workloads.
Go deeper
Related to this question
Learn chapter
DLP Policies for Microsoft Teams
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.