Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft compliance solutions

Which TWO of the following are examples of sensitive information types in Microsoft Purview? (Select TWO.)

⚠ Common exam trap

Many exam-takers confuse 'sensitive information' with any internal or confidential data, but Microsoft Purview only recognizes specific, pattern-based data types like passport numbers and credit card numbers, not generic labels like project code names or employee names.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Passport number

In Microsoft Purview, sensitive information types (SITs) are pattern-based classifiers that detect specific data such as personally identifiable information or financial data. Option A (Passport number) is correct because passport numbers are a built-in SIT category used to identify government-issued identity data across many countries. Option E (Credit card number) is correct because credit card numbers are a classic built-in SIT, detected via patterns like the Luhn check plus keyword corroboration (e.g., 'credit card'). Option B (Public holiday list) is not sensitive data and has no SIT pattern. Option C (Employee name) is not a standalone SIT because a name alone lacks a reliable pattern and is typically only used as supporting evidence in other SITs. Option D (Internal project code name) is business-confidential but not a predefined sensitive information type, since SITs target specific data formats rather than arbitrary internal labels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Passport number

    Why this is correct

    A passport number is considered sensitive information because it is a unique government-issued identifier directly linked to an individual's identity, nationality, and travel history. Unauthorized disclosure could lead to severe consequences such as identity theft, fraud, or impersonation. Microsoft Purview includes "Passport Number" as a predefined sensitive information type (SIT), utilizing pattern matching, keywords, and proximity to detect and protect this critical personal data across an organization's digital estate, aligning with global privacy regulations.

  • ✗

    Public holiday list

    Why it's wrong here

    A public holiday list is generally not considered sensitive information because it contains publicly available data with no direct link to an individual's personal identity, financial status, or confidential organizational operations. Its disclosure does not pose a risk of identity theft, financial harm, or competitive disadvantage to an organization or individual. Therefore, Microsoft Purview's predefined sensitive information types are not designed to detect such public domain content, as it lacks the inherent risk profile of sensitive personal or proprietary data.

  • ✗

    Employee name

    Why it's wrong here

    While an individual employee's name is personal data, it is not typically classified as a predefined sensitive information type on its own within the context of data loss prevention (DLP) policies. A name alone does not inherently carry a high risk of identity theft or significant personal harm upon disclosure. However, when combined with other identifiers like a social security number, financial details, or health records, an employee's name becomes a critical component of sensitive personal identifiable information (PII) that requires protection.

  • ✗

    Internal project code name

    Why it's wrong here

    An internal project code name, while potentially confidential business information, is not classified as a predefined sensitive information type by Microsoft Purview. Its sensitivity is typically related to intellectual property, competitive advantage, or strategic business secrecy, rather than personal data protection or regulatory compliance requirements like GDPR or HIPAA. Organizations can define custom sensitive information types using keywords or regular expressions to detect such proprietary business data if its unauthorized disclosure poses a specific organizational risk.

  • ✓

    Credit card number

    Why this is correct

    A credit card number is unequivocally sensitive information due to its direct link to an individual's financial accounts and purchasing power. Unauthorized access or disclosure can immediately lead to financial fraud, identity theft, and significant monetary loss for the cardholder. Microsoft Purview explicitly includes "Credit Card Number" as a predefined sensitive information type, crucial for compliance with regulations like PCI DSS, and employs robust detection methods including checksum validation and proximity to keywords to ensure accurate identification and protection.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.