SC-900 Practice Question: Describe the concepts of security, compliance, and identity
You are a compliance officer for a law firm that uses Microsoft 365 E5 licenses. The firm must comply with GDPR. You need to implement a solution that automatically identifies personal data (e.g., email addresses) in SharePoint Online documents and applies a 'GDPR-Protected' sensitivity label. Additionally, you need to ensure that if a user attempts to share a labeled document externally, they receive a policy tip warning about GDPR compliance, but the share is not blocked. You have Microsoft Purview. What should you configure?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an auto-labeling policy to apply the 'GDPR-Protected' label to documents containing email addresses, and create a DLP policy for labeled documents that shows a policy tip when shared externally.
An auto-labeling policy can automatically detect personal data (e.g., email addresses) and apply the 'GDPR-Protected' sensitivity label. Then, a separate DLP policy configured for labeled documents can show a policy tip when users attempt to share them externally, warning about GDPR compliance without blocking the share. Option B is incorrect because a retention policy does not apply sensitivity labels or provide DLP policy tips. Option C is incorrect; publishing a sensitivity label only allows manual application by users, not automatic labeling, and it does not include DLP policy tips. Option D is incorrect because without applying the label, the DLP policy would not target only the labeled documents as required, and the policy tip would not be associated with the specific 'GDPR-Protected' label context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an auto-labeling policy to apply the 'GDPR-Protected' label to documents containing email addresses, and create a DLP policy for labeled documents that shows a policy tip when shared externally.
Why this is correct
Auto-labeling applies the label automatically, and DLP provides the policy tip.
- ✗
Create a retention policy to tag documents containing email addresses.
Why it's wrong here
Retention policies do not apply sensitivity labels.
- ✗
Create a sensitivity label policy that publishes the 'GDPR-Protected' label to users and train them to apply it manually.
Why it's wrong here
Manual application is not automatic and may be missed.
- ✗
Create a DLP policy that detects email addresses and shows a policy tip, but do not apply a label.
Why it's wrong here
DLP can show policy tips but does not apply labels.
Go deeper
Related to this question
Learn chapter
Compliance Concepts
Key term
Microsoft 365
Microsoft 365 is a subscription-based cloud service from Microsoft that combines productivity tools like Office apps with security, device management, and online storage.
Key term
User
A user is any person, system, or device that interacts with an IT service, resource, or identity system, typically authenticated through credentials and authorized to perform specific actions.
About these practice questions
One of 1,250 original SC-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.