SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Your organization uses Microsoft Purview to label and protect sensitive data. The compliance team wants to automatically apply a 'Confidential' label to documents containing personally identifiable information (PII) stored in SharePoint Online. What should they create?
⚠ Common exam trap
Many exam-takers confuse DLP policies (which detect and block) with auto-labeling policies (which classify and protect), leading candidates to choose A instead of D.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An auto-labeling policy for sensitivity labels
An auto-labeling policy for sensitivity labels in Microsoft Purview can automatically apply a 'Confidential' label to documents containing PII in SharePoint Online. This policy uses pattern-based detection (e.g., regex for PII like Social Security numbers) to classify and protect content at rest, aligning with the compliance team's requirement to label sensitive data automatically.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A DLP policy to detect PII
Why it's wrong here
A Data Loss Prevention (DLP) policy is designed to identify, monitor, and protect sensitive information across various locations. While DLP policies can detect PII and prevent its unauthorized sharing or transmission, their primary function is to enforce protective actions like blocking, auditing, or notifying, rather than automatically applying a sensitivity label that classifies and encrypts the content itself. They focus on preventing data exfiltration or misuse, not on intrinsic data classification for protection.
- ✗
A trainable classifier for PII
Why it's wrong here
A trainable classifier is an advanced machine learning tool within Microsoft Purview that learns to identify specific categories of content by example, such as PII-related documents or specific contract types. While highly effective at identifying relevant content, a trainable classifier itself does not directly apply sensitivity labels or any other policy action. Instead, its output must be integrated with other policies, like auto-labeling policies for sensitivity labels or retention label policies, to trigger specific actions based on the identified content.
- ✗
A retention label policy for PII
Why it's wrong here
A retention label policy is primarily used for data governance, dictating how long specific content should be retained or deleted to meet regulatory, legal, or business records management requirements. Although retention labels can be applied automatically based on content conditions, their purpose is to manage the data lifecycle, not to classify data for protection against unauthorized access or sharing through encryption or access controls. They focus on compliance for data longevity, not data sensitivity protection.
- ✓
An auto-labeling policy for sensitivity labels
Why this is correct
An auto-labeling policy for sensitivity labels is the precise mechanism within Microsoft Purview designed to automatically apply sensitivity labels to content that contains specific sensitive information types, such as PII. These policies scan content in designated locations (e.g., SharePoint, OneDrive, Exchange) and, upon detecting PII, automatically apply the configured sensitivity label. This label then enforces the associated protection actions, including encryption, visual markings, and access restrictions, thereby directly addressing the requirement to label and protect.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
About these practice questions
This SC-900 question is part of Courseiva's 1,250-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.