SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
A user receives a sensitivity label that automatically marks the email as 'Confidential' and prevents forwarding. The label was applied without user intervention. Which mechanism most likely applied the label?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto-classification via DLP policy
Auto-classification via DLP policy can automatically apply sensitivity labels based on sensitive content, such as credit card numbers, enabling the label to be applied without user intervention. Option A is incorrect because the Azure Information Protection file policy applies to files in Windows File Explorer, not emails. Option C is incorrect because a default label applies to all unlabeled emails but does not use content detection. Option D is incorrect because manual labeling requires the user to select the label.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Information Protection file policy
Why it's wrong here
Azure Information Protection (AIP) file policies, now integrated into Microsoft Purview Information Protection, are primarily designed for scanning, discovering, and applying sensitivity labels to files residing on on-premises network shares, SharePoint Server libraries, and other local repositories. While powerful for data at rest in traditional environments, these policies do not typically provide real-time, automatic content-based labeling for items like emails or documents being created or sent within cloud services such as Exchange Online or SharePoint Online, which the scenario implies.
- ✓
Auto-classification via DLP policy
Why this is correct
Auto-classification via a Data Loss Prevention (DLP) policy is the correct mechanism for this scenario. Microsoft Purview DLP policies can be configured to detect specific sensitive information types (SITs) or trainable classifiers within content, such as emails, documents, or Teams messages. Upon detection, the DLP policy can automatically apply a pre-defined sensitivity label to the item, ensuring consistent protection based on the content's sensitivity without requiring any manual user action.
- ✗
Default label configured in Microsoft 365
Why it's wrong here
A default sensitivity label configured in Microsoft 365 is designed to provide a baseline level of protection by automatically applying a specific label to all new documents or emails created by users, or to existing unlabeled items. However, this application is not based on the content of the item itself; it's a blanket application. The scenario indicates the label "automatically marks" due to content, which is beyond the capability of a simple default label that doesn't perform content analysis.
- ✗
Manual labeling by the user
Why it's wrong here
Manual labeling by the user requires explicit action from the individual creating or modifying the content to select and apply a sensitivity label. Users typically interact with labeling clients integrated into applications like Word, Excel, PowerPoint, or Outlook to choose the appropriate label. The question explicitly states that the label "automatically marks" the content, which directly contradicts the requirement for user intervention inherent in any manual labeling process.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Identity Protection
Key term
Information protection
Information protection refers to the policies, procedures, and technologies used to safeguard data from unauthorized access, disclosure, alteration, or destruction.
Key term
DLP policy
A DLP policy is a set of rules that an organization uses to prevent sensitive data from being lost, stolen, or accidentally exposed, whether it is in use, in motion, or at rest.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.