SC-900 Practice Question: Describe the concepts of security, compliance, and identity
Which THREE of the following are capabilities of Microsoft Purview Information Protection? (Select three.)
⚠ Common exam trap
SC-900 often tests the boundary between Information Protection (classification, labels, rights management) and other Purview solutions like DLP and eDiscovery, tricking candidates who conflate all Purview capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rights management
Microsoft Purview Information Protection provides rights management (A), which uses Azure Rights Management encryption to protect content both inside and outside the organization, so it is correct. It also delivers data classification (C), automatically identifying and categorizing sensitive content through trainable classifiers and sensitive information types, making it correct. Sensitivity labels (D) are the core capability of Information Protection, allowing users and admins to apply protection settings like encryption and content marking to files and emails, so it is correct. eDiscovery (B) belongs to the Microsoft Purview eDiscovery solution rather than Information Protection, and data loss prevention policies (E) are part of the separate Microsoft Purview Data Loss Prevention workload, so neither belongs to Information Protection's capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rights management
Why this is correct
Rights management in Microsoft Purview Information Protection applies encryption and usage restrictions that travel with the content, enforcing access even after files leave the tenant. This satisfies the stem by naming a core capability that protects data wherever it resides.
- ✗
eDiscovery
Why it's wrong here
eDiscovery handles legal hold, search and case management across Microsoft 365 content, not the labelling, encryption and classification that Microsoft Purview Information Protection delivers. It is tempting because eDiscovery does sit inside the Microsoft Purview portal, and would be the right pick for a question about identifying content for litigation or investigations.
- ✓
Data classification
Why this is correct
Data classification identifies and labels content by sensitivity, forming the foundation for protection policies in Microsoft Purview Information Protection. This satisfies the stem by naming a core capability that enables organisations to categorise data before applying controls.
- ✓
Sensitivity labels
Why this is correct
Sensitivity labels classify and protect content by applying encryption, visual markings, and access restrictions that travel with the file. This satisfies the stem's requirement for a Microsoft Purview Information Protection capability, as labels persist across Microsoft 365 workloads and enforce protection regardless of where data is stored or shared.
- ✗
Data loss prevention policies
Why it's wrong here
Data loss prevention policies belong to Microsoft Purview Data Loss Prevention, a separate solution, not Information Protection. Information Protection covers sensitivity labels, encryption and content marking. DLP tempts because both sit under Microsoft Purview and both classify sensitive data, but the licensing and workload boundaries differ.
Go deeper
Related to this question
Learn chapter
Microsoft Entra Password Protection
Key term
Data classification
Data classification is the process of organizing data into categories based on its sensitivity, value, and criticality to an organization, so that appropriate security controls can be applied.
Key term
Data Loss Prevention
Data Loss Prevention (DLP) is a set of tools and processes that help organizations stop sensitive information from being shared, leaked, or stolen, whether accidentally or on purpose.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.