SC-900 Practice Question: Describe the concepts of security, compliance, and identity
You are a compliance officer for a law firm that uses Microsoft 365 E5 licenses. The firm must comply with GDPR. You need to implement a solution that automatically identifies personal data (e.g., email addresses) in SharePoint Online documents and applies a 'GDPR-Protected' sensitivity label. Additionally, you need to ensure that if a user attempts to share a labeled document externally, they receive a policy tip warning about GDPR compliance, but the share is not blocked. You have Microsoft Purview. What should you configure?
⚠ Common exam trap
SC-900 often tests the misconception that a DLP policy alone can apply sensitivity labels or that a sensitivity label policy can auto-detect personal data, when in fact auto-labeling and DLP are separate Purview workloads that must be combined.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an auto-labeling policy to apply the 'GDPR-Protected' label to documents containing email addresses, and create a DLP policy for labeled documents that shows a policy tip when shared externally.
An auto-labeling policy in Microsoft Purview can use sensitive information types (SITs) such as email addresses to automatically apply the 'GDPR-Protected' sensitivity label to SharePoint Online documents. A DLP policy scoped to documents with that label can then show a policy tip when users attempt external sharing, without blocking the action, satisfying the requirement for a warning only. This combination meets both the auto-classification and the non-blocking policy tip requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an auto-labeling policy to apply the 'GDPR-Protected' label to documents containing email addresses, and create a DLP policy for labeled documents that shows a policy tip when shared externally.
Why this is correct
Auto-labeling scans SharePoint content for personal data patterns and applies the label without user input, satisfying GDPR identification. The DLP policy then matches that label and, configured for user override with a policy tip, warns on external sharing while permitting it, meeting the non-blocking requirement.
- ✗
Create a retention policy to tag documents containing email addresses.
Why it's wrong here
A retention policy governs how long content is kept or deleted; it cannot detect email addresses or apply a sensitivity label. Retention policies are the right choice when the requirement is lifecycle management, such as retaining or removing documents after a defined period.
- ✗
Create a sensitivity label policy that publishes the 'GDPR-Protected' label to users and train them to apply it manually.
Why it's wrong here
Publishing a label for manual application relies on users classifying documents themselves, so email addresses are not automatically detected and labelled. Manual label policies suit organisations where human judgement determines classification, not automated detection of personal data at scale.
- ✗
Create a DLP policy that detects email addresses and shows a policy tip, but do not apply a label.
Why it's wrong here
A DLP policy with a policy tip detects email addresses and warns on external sharing, but never applies the 'GDPR-Protected' sensitivity label the scenario requires. DLP alone suits environments needing only detection and user notification, without label-driven classification or protection.
Go deeper
Related to this question
Learn chapter
Azure Policy and Initiatives
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
Sensitivity label
A sensitivity label is a metadata tag applied to digital content that classifies the content's level of confidentiality and governs how it can be shared, protected, and accessed.
About these practice questions
One of 1,279 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.