Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Which THREE of the following are capabilities of Microsoft Purview Information Protection?

⚠ Common exam trap

SC-900 often tests the boundary between Information Protection (labels, auto-labeling, encryption) and other Purview pillars like Data Lifecycle Management (retention) and Compliance (communication monitoring), causing candidates to over-attribute features to Information Protection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Auto-labeling for sensitive data

Microsoft Purview Information Protection provides auto-labeling for sensitive data (A), which uses trainable classifiers and sensitive information types to automatically apply labels to content in services like SharePoint, OneDrive, and Exchange. It also provides sensitivity labels (C), the core classification mechanism that lets organizations tag and classify data by sensitivity level across Microsoft 365 apps and services. Encryption and rights protection (D) is another core capability, as sensitivity labels can apply Azure Rights Management (Azure RMS) encryption and usage rights so that only authorized users can access protected content. The unmarked options do not belong: communication monitoring (B) is a capability of Microsoft Purview Communication Compliance, and retention policies (E) fall under Microsoft Purview Data Lifecycle Management rather than Information Protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Auto-labeling for sensitive data

    Why this is correct

    Auto-labelling applies sensitivity labels automatically to content matching sensitive information types, satisfying the requirement to classify data at scale without manual intervention. Microsoft Purview Information Protection uses this client-side and service-side mechanism to detect and label items across Exchange, SharePoint, OneDrive and Office apps.

  • ✗

    Communication monitoring

    Why it's wrong here

    Communication monitoring belongs to Microsoft Purview Communication Compliance, which scans Teams, Exchange and Yammer messages for policy breaches. Information Protection classifies and labels data via sensitivity labels, encryption and DLP. It is tempting because both sit under the Purview portal, but the scenario asks specifically about Information Protection capabilities.

  • ✓

    Sensitivity labels

    Why this is correct

    Sensitivity labels classify and protect content by applying encryption, visual markings and access restrictions that travel with the file, satisfying the requirement for persistent protection across locations. They are a core Microsoft Purview Information Protection capability, enabling classification and protection of data at rest and in transit.

  • ✓

    Encryption and rights protection

    Why this is correct

    Encryption and rights protection is a core Microsoft Purview Information Protection capability, satisfying the stem's requirement for data protection controls. Sensitivity labels apply persistent encryption with Azure Rights Management, so protection travels with the file regardless of location. Rights management enforces who can open, edit, copy or print content, even after files leave your tenant.

  • ✗

    Retention policies

    Why it's wrong here

    Retention policies belong to Microsoft Purview Data Lifecycle Management, governing how long content is kept, not to Information Protection, which classifies and encrypts data via sensitivity labels. The option tempts anyone treating Purview as one product, but the two solutions address separate compliance objectives.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SC-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO of the following are capabilities of Microsoft Purview Information Protection?

medium
  • A.Searching for content in eDiscovery
  • B.Preventing data loss via policies
  • C.Setting retention periods for content
  • ✓ D.Applying sensitivity labels to documents and emails
  • ✓ E.Encrypting content with Azure Rights Management

Why D: Microsoft Purview Information Protection (MIP) focuses on classifying, labeling, and protecting sensitive data. Applying sensitivity labels to documents and emails (Option D) is a core MIP capability, as labels enforce protection actions like encryption or visual markings. Encrypting content with Azure Rights Management (Option E) is the underlying technology that MIP uses to apply persistent protection, making it a direct capability of the solution.

Variation 2. A company must implement data classification labels in Microsoft Purview to protect sensitive information. Which TWO actions are required to create and publish a sensitivity label?

medium
  • A.Deploy the label using Microsoft Intune configuration profiles.
  • B.Define the label scope to include SharePoint and OneDrive.
  • ✓ C.Create the label in the Microsoft Purview compliance portal.
  • ✓ D.Publish the label using a label policy.
  • E.Configure auto-labeling rules in Microsoft 365 Defender.

Why C: Option C is correct because every sensitivity label must first be created in the Microsoft Purview compliance portal (Solutions > Information protection > Labels), where you define its name, description, and encryption/content-marking settings. Option D is correct because a label only becomes available to users and services after it is published through a label policy, which defines the users/groups and the locations (workloads) where the label is applied. Options A, B, and E are not required: labels are not deployed via Intune configuration profiles, the label scope (SharePoint/OneDrive, Exchange, etc.) is selected inside the label policy rather than being a separate mandatory action, and auto-labeling rules are configured in Microsoft Purview (not Microsoft 365 Defender) and are optional for creating and publishing a label.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.