Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Exhibit

{
  "name": "GDPR-Data-Classification",
  "type": "Microsoft.Purview/classificationRules",
  "properties": {
    "classificationName": "EU GDPR",
    "ruleStatus": "Enabled",
    "action": "ApplyLabel",
    "labelId": "d9f8b5c2-..."
  }
}

Refer to the exhibit. You are reviewing a Microsoft Purview classification rule. The rule is enabled and set to apply a sensitivity label. However, you notice that documents containing EU personal data are not being labeled automatically. What is the most likely cause?

⚠ Common exam trap

Microsoft often tests the misconception that enabling a rule and setting a label is sufficient for automatic labeling, when in fact a sensitive data detection condition is mandatory for the rule to trigger.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The rule does not include a condition to detect sensitive data

The rule is enabled and applies a sensitivity label, but documents containing EU personal data are not being labeled automatically. For automatic labeling to occur, the classification rule must include a condition that detects sensitive data types (e.g., EU passport numbers or GDPR-defined personal data). Without such a condition, the rule has no trigger to identify the content and apply the label, even if the rule is active and scoped correctly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The label ID is invalid

    Why it's wrong here

    In Microsoft Purview, a label ID is a unique identifier assigned to a sensitivity label, essential for linking a policy to the specific protection it should apply. The exhibit clearly indicates that a label ID is present within the rule configuration, which is a necessary component for the rule's potential operation. There is no visual information or error message provided in the exhibit to suggest that this specific ID is malformed, refers to a non-existent label, or is otherwise invalid, making this claim an unsupported assumption.

  • The rule does not include a condition to detect sensitive data

    Why this is correct

    For an auto-labeling policy or rule to effectively identify and apply a sensitivity label to content, it must incorporate specific conditions that define what constitutes sensitive data. These conditions typically involve detecting specific sensitive information types (SITs), keywords, or patterns within documents or emails. Without any defined conditions, the rule lacks the necessary criteria to evaluate content, rendering it incapable of matching or labeling any data, regardless of other policy settings.

  • The rule status is Disabled

    Why it's wrong here

    The exhibit explicitly shows that the rule's operational status is set to "Enabled." A disabled rule would be clearly indicated as such and would not actively scan content or attempt to apply labels, effectively pausing its function. Since the rule is enabled, its current activation state is not the underlying cause of any potential issue with sensitive data detection or label application, making this option factually incorrect based on the provided information.

  • The rule is not scoped to SharePoint Online

    Why it's wrong here

    While the scope of an auto-labeling policy is critical for targeting specific locations like SharePoint Online, the exhibit does not provide any details regarding the rule's configured scope. Therefore, asserting that the rule is not scoped to SharePoint Online is an unsupported assumption without further information. Even if the scope were an issue, the primary and most fundamental problem preventing *any* data detection or labeling would still be the absence of conditions to identify sensitive content, making this a secondary or unproven concern.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.