SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
An organization uses Microsoft Purview Information Protection to classify and protect data. Which TWO methods can be used to apply sensitivity labels automatically?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Auto-labeling policies in Microsoft 365 compliance center
Auto-labeling policies can apply labels based on conditions. Client-side labeling via the Azure Information Protection unified labeling client also supports automatic classification. Manual labeling is not automatic. Labeling in Microsoft 365 Apps is default but not automatic. PowerShell cannot directly apply labels automatically without scripts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Auto-labeling policies in Microsoft 365 compliance center
Why this is correct
Auto-labeling policies in the Microsoft 365 compliance center provide a powerful, server-side mechanism for automatically applying sensitivity labels to content at rest and in transit. These policies scan data stored in locations like SharePoint Online, OneDrive for Business, and Exchange Online, identifying sensitive information based on defined conditions such as sensitive information types, keywords, or trainable classifiers. Once a match is found, the policy automatically applies the configured label without requiring any user intervention, ensuring consistent data protection across the organization.
- ✓
Client-side automatic classification via the unified labeling client
Why this is correct
Client-side automatic classification, facilitated by the unified labeling client integrated into Microsoft 365 Apps (e.g., Word, Excel, Outlook), enables real-time content scanning as users create or edit documents and emails. This client-side intelligence can detect sensitive information as it's being typed or added, then recommend a sensitivity label to the user or even automatically apply it based on policy configurations. This proactive approach helps users classify data correctly at the point of creation, enhancing immediate data protection.
- ✗
Default labeling policy for Microsoft 365 Apps
Why it's wrong here
A default labeling policy for Microsoft 365 Apps is designed to set a pre-selected sensitivity label for new documents or emails by default, acting as a baseline. However, this mechanism does not perform content-aware scanning or classification; it merely applies a pre-configured label without analyzing the actual content for sensitive information. Therefore, it is not considered an automatic classification method, as it lacks the intelligence to dynamically determine a label based on the data's sensitivity.
- ✗
Manual labeling by end users
Why it's wrong here
Manual labeling by end users involves individuals actively selecting and applying a sensitivity label to their documents or emails based on their judgment of the content's sensitivity. This method explicitly requires direct user interaction and a conscious decision to choose a specific label from the available options. Since it relies entirely on human action rather than system-driven content analysis, it fundamentally contradicts the concept of automatic classification.
- ✗
PowerShell scripts to apply labels on export
Why it's wrong here
While PowerShell scripts can be used to automate many administrative tasks, including applying sensitivity labels, they are not a built-in, native automatic classification feature within Microsoft Purview Information Protection. Applying labels via a custom script, especially 'on export,' typically involves a separate process that is triggered by an event or schedule, rather than Purview's inherent content-aware scanning and classification capabilities. This approach requires custom development and management, distinguishing it from the integrated auto-labeling policies.
Go deeper
Related to this question
Learn chapter
Microsoft Entra ID
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
Information protection
Information protection refers to the policies, procedures, and technologies used to safeguard data from unauthorized access, disclosure, alteration, or destruction.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE Microsoft Purview solutions support data classification and labeling? (Choose THREE.)
hard- ✓ A.Information Protection
- B.Insider Risk Management
- ✓ C.Data Lifecycle Management
- D.Communication Compliance
- ✓ E.Data Loss Prevention
Why A: Microsoft Purview Information Protection handles classification and labeling of data. Data Loss Prevention uses labels to enforce policies. Data Lifecycle Management uses labels for retention and deletion. Communication Compliance monitors communications but does not directly classify or label data. Insider Risk Management identifies risky activities but does not classify data.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.