SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions
Tailspin Toys is a toy manufacturer with headquarters in the US and subsidiaries in Europe and Asia. You are the compliance administrator. The company must comply with the EU General Data Protection Regulation (GDPR). Requirements: 1) Personal data of EU residents must be retained only for as long as necessary (max 5 years after last interaction). 2) If a user tries to share personal data outside the EU, the action must be blocked. 3) Users must be able to manually mark documents as 'GDPR High Risk' which will encrypt them and add a watermark 'GDPR PROTECTED'. 4) All access to personal data must be audited. You have Microsoft Purview with E5 compliance licenses. What is the most efficient solution?
⚠ Common exam trap
SC-900 often tests the difference between retention policies and retention labels, and the distinction between auto-labeling and manual sensitivity labeling, causing candidates to choose a solution that uses a retention policy instead of a retention label or a single label for both automatic and manual scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an auto-labeling policy to apply a 'Personal Data' sensitivity label; create a retention label 'GDPR Retention' to auto-apply to personal data and retain for 5 years; create a DLP policy to block sharing of labeled personal data outside EU; create a separate sensitivity label 'GDPR High Risk' for manual application with encryption and watermark; enable audit logging
It uses the full Microsoft Purview toolset appropriately: an auto-labeling policy applies a 'Personal Data' sensitivity label to identify and classify personal data at scale; a retention label 'GDPR Retention' is auto-applied to that labeled content to enforce the 5-year retention requirement; a DLP policy blocks sharing of labeled personal data outside the EU; a separate sensitivity label 'GDPR High Risk' is manually applied by users to encrypt and watermark documents; and audit logging is enabled. This combination meets all four requirements with minimal manual effort and leverages E5 compliance features like auto-labeling and DLP with sensitivity labels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a retention policy to delete all content after 5 years; create a DLP policy to block sharing of personal data outside EU; create a sensitivity label for manual application with encryption and watermark; enable audit logging
Why it's wrong here
Retention policy applies to all content, not just personal data; also deletion of all content after 5 years may not be appropriate for non-personal data.
- ✓
Create an auto-labeling policy to apply a 'Personal Data' sensitivity label; create a retention label 'GDPR Retention' to auto-apply to personal data and retain for 5 years; create a DLP policy to block sharing of labeled personal data outside EU; create a separate sensitivity label 'GDPR High Risk' for manual application with encryption and watermark; enable audit logging
Why this is correct
Auto-labeling applies sensitivity label; retention label retains personal data for 5 years; DLP blocks cross-border sharing; manual label provides encryption and watermark; audit logging tracks access.
- ✗
Use a retention policy to delete personal data after 5 years; create a DLP policy to block cross-border sharing; use a sensitivity label with auto-labeling for personal data; enable audit logging
Why it's wrong here
Retention policy cannot specifically target personal data; also manual label for high risk is missing.
- ✗
Create a DLP policy to block sharing of personal data outside EU; use a retention label for 5 years; use a single sensitivity label for both automatic and manual scenarios; enable audit logging
Why it's wrong here
A single sensitivity label cannot be both auto-applied and manually applied with different settings; needs separate labels.
Go deeper
Related to this question
Learn chapter
eDiscovery and Audit
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Data protection
Data protection refers to the practices and technologies used to safeguard personal and sensitive information from unauthorized access, loss, or corruption.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.