SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your company uses Microsoft Purview to govern data across on-premises and cloud sources. You need to classify sensitive data such as credit card numbers and social security numbers automatically. What should you create?
⚠ Common exam trap
SC-900 often tests the confusion between detection (SITs) and enforcement (DLP policies/labels), causing candidates to pick DLP when the question asks what to create for classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sensitive information types
Sensitive information types (SITs) in Microsoft Purview are pattern-based classifiers that detect specific data formats such as credit card numbers, SSNs, and passport numbers using regex, checksums, and keyword proximity. They are the foundational building block used by DLP policies, sensitivity labels, and auto-labeling to identify sensitive content. Creating a SIT is the correct step to enable automatic classification of regulated data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data loss prevention policies
Why it's wrong here
Data loss prevention (DLP) policies are designed to identify, monitor, and protect sensitive information across an organization's data estate. While DLP policies leverage the results of data classification (often using Sensitive Information Types and sensitivity labels), their primary function is to enforce protective actions, such as blocking sharing or encrypting files, rather than to automatically classify the data in the first place. They are a consequence of classification, not the classification mechanism itself.
- ✗
Sensitivity labels
Why it's wrong here
Sensitivity labels are used to classify and protect data by applying visual markings, encryption, or other protective actions directly to content. While labels can be automatically applied to documents or emails based on the detection of sensitive information, the labels themselves do not perform the underlying automatic classification or pattern matching. Instead, they are the outcome of a classification process, providing the means to enforce protection based on that classification.
- ✓
Sensitive information types
Why this is correct
Sensitive information types (SITs) are the fundamental building blocks in Microsoft Purview for automatically identifying sensitive data. They define specific patterns, keywords, regular expressions, and proximity rules that the system uses to detect particular types of sensitive information, such as credit card numbers, national identification numbers, or medical record numbers. This automatic pattern matching is precisely how Purview discovers and classifies data at scale, making SITs the direct answer to automatic classification.
- ✗
Retention labels
Why it's wrong here
Retention labels are specifically designed to manage the lifecycle of data by defining how long content should be kept or when it should be deleted. While they can be applied automatically based on content properties or sensitivity labels, their purpose is solely to enforce retention and deletion policies. Retention labels do not perform the initial automatic identification or classification of sensitive data based on its content patterns; they manage the data after it has been created or classified.
Go deeper
Related to this question
Learn chapter
Azure NSG and Application Security Groups
Key term
Microsoft Purview
Microsoft Purview is a unified data governance and compliance service that helps organizations discover, manage, and protect their data across on-premises, cloud, and hybrid environments.
Key term
DLP
Data Loss Prevention — security technology that detects and prevents unauthorised transmission of sensitive data outside an organisation.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.