SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Exhibit
{
"LabelName": "Confidential-Finance",
"Settings": {
"Encryption": {
"Enabled": true,
"ProtectionType": "UserDefined"
},
"Marking": {
"Header": "CONFIDENTIAL",
"Footer": "Confidential - Finance"
}
}
}Refer to the exhibit. A sensitivity label is configured as shown. Which statement about the label's behavior is accurate?
⚠ Common exam trap
Test-takers frequently confuse 'user-defined permissions' with 'no encryption' or 'automatic encryption with a template,' failing to recognize that the exhibit's configuration explicitly enables user-controlled encryption rather than disabling it or using a fixed template.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
When applied, users can choose who can access the document and what permissions they have.
The exhibit shows a sensitivity label configured with 'Let users assign permissions' under 'User-defined permissions' in Azure Information Protection. This setting allows end users to define custom permissions (e.g., who can read, edit, or forward) when applying the label, rather than using a fixed template or automatic encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
When applied, users can choose who can access the document and what permissions they have.
Why this is correct
This option is correct because a sensitivity label configured with 'UserDefined' protection empowers the user applying the label to specify who can access the document and precisely what permissions they possess. Instead of a fixed set of rights, the user can dynamically assign granular access controls, such as view-only, edit, or co-author, to specific individuals or groups at the point of content creation or modification. This provides flexible and context-aware data protection.
- ✗
The label disables encryption and only adds a header and footer.
Why it's wrong here
This statement is incorrect because the exhibit indicates that encryption is enabled for the sensitivity label, not disabled. While sensitivity labels can apply visual markings like headers and footers, these are typically applied in conjunction with, and not as a replacement for, robust data protection mechanisms such as encryption. The label's primary function includes safeguarding content through encryption and access restrictions.
- ✗
The label automatically encrypts the document with a predefined template.
Why it's wrong here
This option is incorrect because the label's protection type is 'UserDefined,' meaning the user determines the permissions, rather than automatically applying a predefined template. While the label does enable encryption, the specific access rights are not pulled from a fixed, pre-configured template. Instead, the individual applying the label actively selects the recipients and their corresponding permissions.
- ✗
The label does not apply any protection; it only adds visual markings.
Why it's wrong here
This statement is incorrect because the sensitivity label is configured to enable encryption, which constitutes a significant form of protection beyond mere visual markings. While visual markings like headers, footers, or watermarks are indeed applied, they serve as a visible indicator of the label's classification and protection, not as the sole protective measure. The label actively encrypts the content and restricts access based on the defined permissions.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Identity Protection
Key term
Sensitivity label
A sensitivity label is a metadata tag applied to digital content that classifies the content's level of confidentiality and governs how it can be shared, protected, and accessed.
Key term
Information protection
Information protection refers to the policies, procedures, and technologies used to safeguard data from unauthorized access, disclosure, alteration, or destruction.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.