Courseiva

SC-900 Practice Question: Describe the capabilities of Microsoft security solutions

Your organization is deploying Microsoft Purview. You need to automatically apply a sensitivity label to documents that contain passport numbers. Which TWO components must you configure?

⚠ Common exam trap

Many exam-takers confuse a DLP policy with an auto-labeling policy, not realizing that DLP policies enforce protective actions (like blocking) while auto-labeling policies apply sensitivity labels based on content detection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Sensitive information type for passport numbers

A sensitive information type (SIT) for passport numbers defines the pattern and validation logic that Microsoft Purview uses to detect passport numbers in content. An auto-labeling policy then applies the specified sensitivity label automatically when the SIT is matched, enabling automated classification and protection without user intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Sensitive information type for passport numbers

    Why this is correct

    A Sensitive Information Type (SIT) for passport numbers is crucial because it defines the specific pattern, keywords, and proximity rules required to accurately identify passport numbers within content. This detection mechanism is a fundamental prerequisite for any automated process that aims to classify and protect documents containing such sensitive personal data. Without a defined SIT, Microsoft Purview would be unable to reliably locate and flag passport numbers for subsequent labeling actions.

  • Retention label

    Why it's wrong here

    A retention label is designed to manage the lifecycle of information, dictating how long content should be kept or when it should be deleted to meet regulatory or organizational requirements. Unlike sensitivity labels, which classify data based on its inherent sensitivity and apply protective actions, retention labels do not assess or apply protection based on the content's confidential nature. Therefore, a retention label would not be used to identify or apply sensitivity-based protection to documents containing passport numbers.

  • Data loss prevention (DLP) policy

    Why it's wrong here

    A Data Loss Prevention (DLP) policy primarily focuses on preventing the unauthorized sharing, transfer, or exfiltration of sensitive information outside defined boundaries. While DLP policies can detect sensitive information types and *act* upon content that has a sensitivity label, their core function is to enforce protective actions like blocking, auditing, or notifying, rather than automatically *applying* sensitivity labels to documents. DLP policies operate on content *after* it has been created or is in transit, not as a primary mechanism for initial content classification and labeling.

  • Auto-labeling policy

    Why this is correct

    An auto-labeling policy is the direct mechanism within Microsoft Purview Information Protection that automatically applies sensitivity labels to content based on specific conditions. These conditions frequently include the detection of sensitive information types, such as passport numbers, or other criteria like keywords or properties. By configuring an auto-labeling policy to detect the passport number SIT, organizations can ensure that documents containing this sensitive data are consistently and automatically classified with the appropriate sensitivity label, thereby enforcing associated protective actions.

  • Trainable classifier

    Why it's wrong here

    A trainable classifier is an advanced machine learning tool used to identify types of content based on examples, rather than precise pattern matching. It is effective for classifying subjective or complex content categories, such as "resumes," "contracts," or "financial statements," where exact patterns are difficult to define. However, for highly structured and specific data like passport numbers, which follow a predictable pattern, a trainable classifier is less suitable and less efficient than a precise Sensitive Information Type.

About these practice questions

This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.