Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A healthcare organization must comply with HIPAA regulations. They use Microsoft Purview to classify and label patient data. Which Microsoft Purview capability helps them enforce data protection policies automatically?

⚠ Common exam trap

SC-900 often tests the distinction between classification (sensitivity labels) and enforcement (DLP policies)—candidates pick sensitivity labels because they sound like the protection mechanism, but the question asks for automatic enforcement of policies, which is DLP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Data loss prevention (DLP) policies

Data loss prevention (DLP) policies in Microsoft Purview are designed to automatically detect sensitive information (such as HIPAA-regulated data) and enforce protection actions like blocking sharing or applying encryption. DLP uses sensitivity labels and sensitive information types to identify content and then applies policy actions automatically across Exchange, SharePoint, OneDrive, and Teams. This directly enforces data protection policies without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    eDiscovery

    Why it's wrong here

    eDiscovery identifies and collects content for legal or investigative review; it does not evaluate labels and enforce protective actions on data at rest or in transit. It is tempting because it operates across the same Purview data estate, and it would be correct for locating evidence during litigation or regulatory investigation.

  • ✗

    Audit logs

    Why it's wrong here

    Audit logs record user and admin activity for later review; they provide visibility after an event rather than automatically enforcing protection when labelled data is accessed or shared. They are tempting because they cover the same workloads, and they would be correct for compliance reporting and forensic investigation.

  • ✗

    Sensitivity labels

    Why it's wrong here

    Sensitivity labels classify and mark content, but enforcement of protection actions such as encryption or blocking sharing comes from policies built on those labels, not the labels alone. They are tempting because they drive classification, and they would be correct for applying persistent protection to documents and emails.

  • ✓

    Data loss prevention (DLP) policies

    Why this is correct

    DLP policies in Microsoft Purview detect sensitive information types and sensitivity labels, then automatically block sharing, restrict access, or warn users. This enforces HIPAA protection without manual review, satisfying the requirement to apply safeguards automatically across workloads.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.