Two Microsoft Purview Features for Automatic Data Classification
Which TWO Microsoft Purview features can be used to automatically classify and protect sensitive data in documents?
Quick Answer
The answer is Sensitive information types and Trainable classifiers. Sensitive information types rely on predefined or custom regex patterns—such as credit card numbers or Social Security numbers—to detect specific data formats, while Trainable classifiers use machine learning to intelligently identify sensitive content based on context and patterns, even when no fixed pattern exists. On the SC-900 exam, this question tests your understanding of how Microsoft Purview’s automatic classification features work together to protect data in documents, often appearing as a “select two” item where common traps include confusing Trainable classifiers with simple keyword lists or assuming Data Loss Prevention policies alone handle classification. Remember the memory tip: “Patterns and Patterns” – Sensitive information types match fixed patterns, Trainable classifiers learn behavioral patterns.
⚠ Common exam trap
Microsoft often tests the misconception that Data loss prevention policies (A) perform automatic classification, when in fact they enforce actions based on pre-existing classifications or sensitive information types, not the classification itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trainable classifiers
Sensitive information types (E) are the built-in or custom pattern-based definitions in Microsoft Purview that automatically detect and classify sensitive data such as credit card numbers, national ID numbers, or health records, making them a core automatic classification mechanism. Trainable classifiers (C) use machine learning to automatically identify and classify sensitive content by category (for example, source code, resumes, or contracts) when pattern matching alone is insufficient. Together, these two features feed the classification engine that can then trigger protection such as encryption or DLP. Data loss prevention policies (A) act on already-classified sensitive data to prevent sharing, but they are a protection/enforcement mechanism rather than a classification feature. eDiscovery (Premium) (B) is used for identifying, collecting, and reviewing content for legal cases, not for automatic classification and protection. Retention labels (D) govern how long content is kept or deleted, which is a lifecycle function, not automatic classification of sensitive data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data loss prevention policies
Why it's wrong here
Data loss prevention policies detect sensitive information and block or warn on sharing, but they do not classify documents or apply protection such as encryption. Sensitivity labels do both. DLP tempts because it uses the same sensitive information types, yet its enforcement point is egress, not labelling.
- ✗
eDiscovery (Premium)
Why it's wrong here
eDiscovery (Premium) supports legal hold, review sets and case workflows for litigation; it does not apply sensitivity labels or auto-classify content. It is tempting because it surfaces sensitive items during investigations, but that is reactive discovery, not the automated classification and protection the stem requires.
- ✓
Trainable classifiers
Why this is correct
Trainable classifiers use machine learning to identify content by example rather than fixed patterns, automatically classifying documents that fit a trained category. This satisfies the stem's requirement for automatic classification and protection of sensitive data in documents.
- ✗
Retention labels
Why it's wrong here
Retention labels govern how long content is kept and when it is deleted; they neither detect sensitive information types nor apply encryption. Sensitivity labels perform classification and protection. Retention labels tempt because they also apply automatically, but their axis is lifecycle retention, not data classification.
- ✓
Sensitive information types
Why this is correct
Sensitive information types detect specific data patterns, such as credit card or national insurance numbers, enabling automatic classification of documents. This satisfies the stem's requirement for automatic classification and protection of sensitive data in documents.
Go deeper
Related to this question
Learn chapter
Data Residency, Sovereignty, and Privacy
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
eDiscovery
eDiscovery is the process of identifying, collecting, and producing electronic information for legal cases or investigations.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO Microsoft Purview solutions can be used to automatically classify sensitive data at rest?
easy- ✓ A.Data Lifecycle Management
- B.Communication Compliance
- C.eDiscovery
- D.Auditing
- ✓ E.Information Protection
Why A: Data Lifecycle Management (DLM) automatically classifies sensitive data at rest by applying retention labels based on sensitive content detection, such as credit card numbers or social security numbers, using trainable classifiers or exact data match. Information Protection (IP) extends this by enabling automatic labeling of documents and emails based on sensitive information types, ensuring data is classified and protected while stored in SharePoint, OneDrive, or Exchange Online.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.