Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

You are a compliance officer for a law firm that uses Microsoft 365 E5 licenses. The firm must comply with GDPR. You need to implement a solution that automatically identifies personal data (e.g., email addresses) in SharePoint Online documents and applies a 'GDPR-Protected' sensitivity label. Additionally, you need to ensure that if a user attempts to share a labeled document externally, they receive a policy tip warning about GDPR compliance, but the share is not blocked. You have Microsoft Purview. What should you configure?

⚠ Common exam trap

SC-900 often tests the misconception that a DLP policy alone can apply sensitivity labels or that a sensitivity label policy can auto-detect personal data, when in fact auto-labeling and DLP are separate Purview workloads that must be combined.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an auto-labeling policy to apply the 'GDPR-Protected' label to documents containing email addresses, and create a DLP policy for labeled documents that shows a policy tip when shared externally.

An auto-labeling policy in Microsoft Purview can use sensitive information types (SITs) such as email addresses to automatically apply the 'GDPR-Protected' sensitivity label to SharePoint Online documents. A DLP policy scoped to documents with that label can then show a policy tip when users attempt external sharing, without blocking the action, satisfying the requirement for a warning only. This combination meets both the auto-classification and the non-blocking policy tip requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an auto-labeling policy to apply the 'GDPR-Protected' label to documents containing email addresses, and create a DLP policy for labeled documents that shows a policy tip when shared externally.

    Why this is correct

    Auto-labeling scans SharePoint content for personal data patterns and applies the label without user input, satisfying GDPR identification. The DLP policy then matches that label and, configured for user override with a policy tip, warns on external sharing while permitting it, meeting the non-blocking requirement.

  • ✗

    Create a retention policy to tag documents containing email addresses.

    Why it's wrong here

    A retention policy governs how long content is kept or deleted; it cannot detect email addresses or apply a sensitivity label. Retention policies are the right choice when the requirement is lifecycle management, such as retaining or removing documents after a defined period.

  • ✗

    Create a sensitivity label policy that publishes the 'GDPR-Protected' label to users and train them to apply it manually.

    Why it's wrong here

    Publishing a label for manual application relies on users classifying documents themselves, so email addresses are not automatically detected and labelled. Manual label policies suit organisations where human judgement determines classification, not automated detection of personal data at scale.

  • ✗

    Create a DLP policy that detects email addresses and shows a policy tip, but do not apply a label.

    Why it's wrong here

    A DLP policy with a policy tip detects email addresses and warns on external sharing, but never applies the 'GDPR-Protected' sensitivity label the scenario requires. DLP alone suits environments needing only detection and user notification, without label-driven classification or protection.

About these practice questions

One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.