SC-900 - Microsoft Compliance Solutions (22% of the exam) - Section 4.3

Describe information protection, data lifecycle management, and data governance in Microsoft Purview.

Describe how data classification and sensitivity labels in Microsoft Purview identify and protect sensitive content, and explain how data loss prevention policies prevent unauthorised sharing of that content. Distinguish records management from retention policies, recognising that records management handles regulatory obligations while retention policies govern the broader lifecycle of content.

data classificationsensitivity labelsdata loss preventionrecords managementretention policies

Practice question for this objective

Free sampleMicrosoft Compliance Solutionsmedium

An administrator wants protection that classifies an item and then keeps controls such as encryption attached to the file even after it leaves the organisation, while separately blocking risky sharing actions in real time. Which TWO Microsoft Purview capabilities together deliver this, one for each requirement? Select TWO.

  • ASensitivity labels, which classify content and embed protection that travels with the file Correct
  • BRetention policies, which decide how long content is kept or when it is deleted
  • CRecords management, which declares items as records and disposes of them on a schedule
  • DData loss prevention, which detects and blocks inappropriate sharing of sensitive items Correct
  • EAudit, which records the user and admin activity for later review
Sensitivity labels embed persistent protection that travels with a file, while data loss prevention detects and blocks inappropriate sharing of sensitive content. The two requirements map to two distinct tools: labels carry encryption with the file, and DLP enforces real-time controls on sharing. Retention and records management handle lifecycle, and audit only records events, so none of those satisfy either stated need.

Why A is correct: Sensitivity labels classify and apply persistent protection such as encryption that stays with the file wherever it goes.

Why B is wrong: Retention governs lifecycle duration, not classification or real-time sharing control, so it answers neither requirement.

Why C is wrong: Records management handles regulatory record declaration and disposal, not portable encryption or sharing blocks.

Why D is correct: DLP policies inspect content and can block or warn on risky sharing in real time across Microsoft 365 locations.

Why E is wrong: Audit logs activity after the fact; it neither protects files nor prevents the sharing action from happening.

See more SC-900 practice questions, answers explained.

Exam traps in Microsoft Compliance Solutions

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-900 bank for this domain.

  • Records management, which marks items as records and then manages their disposition.

    Why it is wrong: Records management governs records and their lifecycle and disposition; it does not monitor user sharing activity to prevent oversharing as DLP does.

  • It classifies content by showing the service many examples to learn a category

    Why it is wrong: Learning a category from examples is a trainable classifier under data classification, not a records management feature.

  • Data loss prevention, which monitors activity and stops sensitive data being overshared.

    Why it is wrong: Data loss prevention prevents inappropriate sharing of sensitive items; it does not declare records or manage their scheduled disposition.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.