Combining Retention Labels, Sensitivity Labels, and Conditional Access for PII
Your organization, Contoso Ltd., is a multinational company with offices in the US, EU, and Asia. You are the compliance administrator. The legal team requires that all documents containing personally identifiable information (PII) of EU citizens be retained for 10 years after the last modification. Additionally, any document classified as 'Highly Confidential' must be encrypted and have a custom header 'CONFIDENTIAL - DO NOT FORWARD' when shared externally. You also need to ensure that only users in the EU region can access documents containing EU PII. You have Microsoft Purview with the necessary licenses. You need to design a compliance solution that meets these requirements with minimal administrative overhead. What should you do?
Quick Answer
The correct answer is to create a retention label for 10-year retention based on PII content, a sensitivity label for 'Highly Confidential' with encryption and a custom header, and a conditional access policy in Microsoft Entra ID to restrict access to EU users. This solution works because Microsoft Purview separates retention and sensitivity into distinct label types—retention labels manage data lifecycle and legal holds based on content like PII, while sensitivity labels enforce protection actions such as encryption and headers. The conditional access policy then adds a location-based gate, ensuring only EU users can access documents labeled as 'Highly Confidential', directly addressing the regional access requirement. On the SC-900 exam, this scenario tests your understanding that retention labels and sensitivity labels serve different purposes and must be combined with conditional access for full compliance; a common trap is trying to use a single label or relying solely on DLP, which cannot enforce geographic access control. Memory tip: think "Retain, Protect, Restrict"—retention labels for how long, sensitivity labels for how to protect, and conditional access for who can see it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a retention label for 10-year retention based on PII content; create a sensitivity label 'Highly Confidential' with encryption and header; create a sensitivity label for EU PII with an authentication context, and configure a conditional access policy in Microsoft Entra ID to restrict access to that authentication context to EU users
Option B correctly uses a retention label to retain documents containing EU PII for 10 years after last modification and a sensitivity label to encrypt and add the required header to 'Highly Confidential' documents. For the EU PII location restriction, the correct approach is to apply an EU PII sensitivity label configured with an authentication context, then enforce a Conditional Access policy in Microsoft Entra ID that permits access only from EU locations. This meets all stated requirements with minimal administrative overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Data Loss Prevention (DLP) policy to block external sharing of PII; create a retention policy for 10 years on all content; use sensitivity labels for encryption
Why it's wrong here
DLP does not restrict access based on region; retention policy applies to all content, not just PII.
- ✓
Create a retention label for 10-year retention based on PII content; create a sensitivity label 'Highly Confidential' with encryption and header; create a sensitivity label for EU PII with an authentication context, and configure a conditional access policy in Microsoft Entra ID to restrict access to that authentication context to EU users
Why this is correct
Retention label retains for 10 years; sensitivity label provides encryption and header; conditional access restricts by region.
- ✗
Use a single unified label that combines retention and sensitivity settings; then configure an auto-labeling policy to apply it; use a device compliance policy to restrict access
Why it's wrong here
Unified labels do not exist; retention and sensitivity are separate. Device compliance does not restrict by region.
- ✗
Create a retention policy for 10 years on all content; use sensitivity labels with encryption; then configure a DLP policy to add the header when shared externally
Why it's wrong here
Retention policy applies to all content, not just PII; DLP can add headers but does not enforce regional access.
Go deeper
Related to this question
Learn chapter
Communication Compliance
Key term
Retention label
A retention label is a tag applied to emails, documents, or files in Microsoft 365 that tells the system how long to keep the item and what to do with it when the time is up.
Key term
Conditional access
Conditional access is a security framework that evaluates signals like user location, device health, and risk level to grant or block access to resources in real time.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Tailspin Toys is a toy manufacturer with headquarters in the US and subsidiaries in Europe and Asia. You are the compliance administrator. The company must comply with the EU General Data Protection Regulation (GDPR). Requirements: 1) Personal data of EU residents must be retained only for as long as necessary (max 5 years after last interaction). 2) If a user tries to share personal data outside the EU, the action must be blocked. 3) Users must be able to manually mark documents as 'GDPR High Risk' which will encrypt them and add a watermark 'GDPR PROTECTED'. 4) All access to personal data must be audited. You have Microsoft Purview with E5 compliance licenses. What is the most efficient solution?
hard- A.Use a retention policy to delete all content after 5 years; create a DLP policy to block sharing of personal data outside EU; create a sensitivity label for manual application with encryption and watermark; enable audit logging
- ✓ B.Create an auto-labeling policy to apply a 'Personal Data' sensitivity label; create a retention label 'GDPR Retention' to auto-apply to personal data and retain for 5 years; create a DLP policy to block sharing of labeled personal data outside EU; create a separate sensitivity label 'GDPR High Risk' for manual application with encryption and watermark; enable audit logging
- C.Use a retention policy to delete personal data after 5 years; create a DLP policy to block cross-border sharing; use a sensitivity label with auto-labeling for personal data; enable audit logging
- D.Create a DLP policy to block sharing of personal data outside EU; use a retention label for 5 years; use a single sensitivity label for both automatic and manual scenarios; enable audit logging
Why B: Option B is correct because it uses the full Microsoft Purview toolset appropriately: an auto-labeling policy applies a 'Personal Data' sensitivity label to identify and classify personal data at scale; a retention label 'GDPR Retention' is auto-applied to that labeled content to enforce the 5-year retention requirement; a DLP policy blocks sharing of labeled personal data outside the EU; a separate sensitivity label 'GDPR High Risk' is manually applied by users to encrypt and watermark documents; and audit logging is enabled. This combination meets all four requirements with minimal manual effort and leverages E5 compliance features like auto-labeling and DLP with sensitivity labels.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.