Microsoft Purview: Configure Auto-Labeling Policy and Sensitivity Label Encryption for Credit Card Numbers
A company wants to automatically apply a 'Confidential' sensitivity label to any document that contains a credit card number, and also encrypt the document as part of the label. Which two components must be configured to achieve this? (Choose two.)
Quick Answer
The answer is a sensitivity label with encryption configured and an auto-labeling policy. The auto-labeling policy is responsible for automatically detecting credit card numbers within documents and applying the designated label, while the sensitivity label itself must have encryption settings enabled within its protection settings to ensure the document is encrypted upon application. On the SC-900 exam, this tests your understanding of how Microsoft Purview Information Protection combines detection rules with protection actions; a common trap is assuming the auto-labeling policy alone handles encryption, when in fact the label’s encryption must be pre-configured separately. Remember the pairing: the policy detects and applies, the label protects and encrypts—think of it as “policy pulls the trigger, label loads the bullet.”
⚠ Common exam trap
Watch out — candidates often confuse DLP policies with auto-labeling policies, thinking DLP can apply labels and encryption, but DLP only detects and acts on content (e.g., block or notify) and does not apply sensitivity labels.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A sensitivity label with encryption settings
Option A is correct because the requirement to encrypt the document as part of the label can only be fulfilled by a sensitivity label that has encryption (Azure Rights Management) configured in its protection settings. Option C is correct because automatically applying that label to any document containing a credit card number requires an auto-labeling policy (client-side or service-side) that uses a sensitive information type such as Credit Card Number to trigger the label. Option B is incorrect because a DLP policy detects and can block or warn about sensitive content, but it does not apply sensitivity labels or encrypt documents. Option D is incorrect because the data classification dashboard is only a reporting/monitoring view of classified content and performs no labeling or encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A sensitivity label with encryption settings
Why this is correct
A sensitivity label with encryption settings supplies the protective action: Azure Information Protection encryption is applied when the label is assigned. This satisfies the stem's requirement to encrypt the document as part of the label, while auto-application to credit card content is handled separately by the other required component.
- ✗
A DLP policy that detects sensitive info
Why it's wrong here
A DLP policy detects credit card numbers and can raise alerts or trigger actions, but it does not itself apply a sensitivity label or encrypt documents. It is tempting because DLP identifies the sensitive info, yet auto-labelling requires an auto-labelling policy in Microsoft Purview plus a label with encryption enabled.
When this WOULD be correct
A company wants to block emails containing credit card numbers from being sent externally. Which component should be configured? (A DLP policy that detects sensitive info and enforces action.)
- ✓
An auto-labeling policy
Why this is correct
An auto-labelling policy in Microsoft Purview scans content for sensitive information types, such as credit card numbers, and applies the 'Confidential' label automatically without user intervention. This satisfies the stem's requirement to detect credit card data and label documents automatically, while the label itself supplies the encryption.
- ✗
A data classification dashboard
Why it's wrong here
The data classification dashboard only reports how content is classified; it neither detects credit card numbers nor applies labels or encryption. It is tempting because it surfaces sensitive-data findings, but achieving auto-labelling needs a DLP detection rule plus a sensitivity label configured with encryption.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The SC-900 exam frequently reuses these exact scenarios with slightly different constraints.
✓A sensitivity label with encryption settingsCorrect answer▾
Why this is correct
A sensitivity label with encryption settings supplies the protective action: Azure Information Protection encryption is applied when the label is assigned. This satisfies the stem's requirement to encrypt the document as part of the label, while auto-application to credit card content is handled separately by the other required component.
✗A DLP policy that detects sensitive infoWrong answer — click to see why▾
Why this is wrong here
A DLP policy detects sensitive info but does not automatically apply sensitivity labels or encryption; it only triggers alerts or blocks actions. The question requires automatic labeling and encryption, which is handled by auto-labeling policies and sensitivity labels, not DLP.
★ When this WOULD be the correct answer
A company wants to block emails containing credit card numbers from being sent externally. Which component should be configured? (A DLP policy that detects sensitive info and enforces action.)
Why candidates choose this
Candidates may confuse DLP's detection of sensitive data with the ability to automatically apply labels, as both involve sensitive info types and can be triggered by content matching.
Analysis generated from the official SC-900blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Management Groups and Subscription Governance
Key term
Sensitivity label
A sensitivity label is a metadata tag applied to digital content that classifies the content's level of confidentiality and governs how it can be shared, protected, and accessed.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to automatically apply a 'Confidential' sensitivity label to all documents containing credit card numbers. Which Microsoft Purview feature should be used to create the auto-labeling policy?
easy- A.Microsoft Purview Data Loss Prevention
- B.Microsoft Purview Communication Compliance
- C.Microsoft Purview Data Lifecycle Management
- ✓ D.Microsoft Purview Auto-labeling policies
Why D: Microsoft Purview Auto-labeling policies are specifically designed to automatically apply sensitivity labels to documents and emails based on conditions such as the presence of sensitive information types (e.g., credit card numbers). This feature uses exact data match or pattern-based detection to label content at rest or in transit, fulfilling the requirement without manual intervention.
Variation 2. An organization needs to automatically apply a 'Confidential' label to documents that contain EU personal data, and also encrypt those documents. Which Microsoft Purview feature should they configure?
medium- A.Data Loss Prevention (DLP) policy
- B.Retention label policy
- C.Data classification service
- ✓ D.Auto-labeling policy
Why D: Auto-labeling policies can be configured to automatically apply sensitivity labels based on sensitive info types like EU personal data. Sensitivity labels support encryption. Data classification is a prerequisite, but auto-labeling is the feature that applies the label automatically.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.