SC-900 Microsoft Security, Compliance, and Identity Fundamentals Microsoft Purview Information Protection 5 — Questions and Answers
Question 1: Which Microsoft Purview Information Protection feature allows an organization to define its own sensitive data patterns using regular expressions and keyword lists?
- Trainable classifiers
- Custom sensitive information types (SITs) (Correct answer)
- Activity Explorer
- Information barriers
Correct answer: Custom sensitive information types (SITs)
Custom sensitive information types let organizations define their own patterns using regex, keyword lists, and confidence levels to detect proprietary or unique sensitive data.
Question 2: What happens to a file's sensitivity label when it is moved from a labeled SharePoint site to an unlabeled SharePoint site?
- The file's label is automatically upgraded to match the destination site
- The file retains its original sensitivity label regardless of the destination (Correct answer)
- The file's label is automatically removed to match the unlabeled destination
- The file is blocked from being moved to the unlabeled site
Correct answer: The file retains its original sensitivity label regardless of the destination
Sensitivity labels applied to files travel with the content, so the file retains its label even when moved to a location with a different or no label.
Question 3: In Microsoft Purview, what does 'encryption at rest' versus 'encryption in use' mean for sensitivity-labeled content?
- At-rest encryption protects stored files; in-use encryption is not supported by Microsoft Purview labels
- At-rest encryption protects files when stored; sensitivity labels provide persistent encryption that also protects content while it is being actively used or shared (Correct answer)
- They refer to the same encryption mechanism applied at different billing tiers
- In-use encryption applies only to database fields, not documents
Correct answer: At-rest encryption protects files when stored; sensitivity labels provide persistent encryption that also protects content while it is being actively used or shared
Microsoft Purview sensitivity label encryption persists beyond storage — it protects the content while it is open, shared, or transmitted, not only when stored.
Question 4: Which Microsoft Purview Information Protection license tier is required to use automatic sensitivity labeling policies in SharePoint and OneDrive?
- Microsoft 365 Business Basic
- Microsoft 365 E3
- Microsoft 365 E5 or equivalent compliance add-on (Correct answer)
- Microsoft 365 F1
Correct answer: Microsoft 365 E5 or equivalent compliance add-on
Auto-labeling policies for SharePoint and OneDrive require Microsoft 365 E5 or the Microsoft 365 E5 Compliance add-on license.
Question 5: A document labeled 'Highly Confidential' is attached to an email. The email has no label applied. What label does the email receive under default Microsoft Purview behavior?
- The email inherits the attachment's 'Highly Confidential' label (Correct answer)
- The email retains no label unless the user manually applies one
- The email is blocked from being sent until a label is applied
- The email is automatically labeled 'Confidential' as a default
Correct answer: The email inherits the attachment's 'Highly Confidential' label
By default, Outlook recommends or applies the highest sensitivity label found among the email's attachments to ensure the email body is protected at the appropriate level.
Question 6: What is the role of Microsoft Purview Information Protection SDK for third-party applications?
- It allows third-party apps to send telemetry data to Microsoft Purview dashboards
- It enables third-party applications to read, apply, and enforce Microsoft Purview sensitivity labels on content they manage (Correct answer)
- It provides APIs for third parties to create new sensitivity label types
- It authenticates third-party apps using sensitivity label credentials
Correct answer: It enables third-party applications to read, apply, and enforce Microsoft Purview sensitivity labels on content they manage
The Microsoft Purview Information Protection SDK allows ISVs and developers to integrate label reading, application, and enforcement into their own applications.
Question 7: Which scenario best illustrates the use of Microsoft Purview Information Protection with Microsoft Defender for Cloud Apps?
- Blocking all cloud app usage for users who have not completed compliance training
- Automatically applying sensitivity labels to files stored in third-party cloud storage apps like Box or Dropbox through Defender for Cloud Apps integration (Correct answer)
- Requiring users to re-authenticate before accessing cloud apps that contain labeled content
- Scanning on-premises file servers for sensitive data using Defender agent
Correct answer: Automatically applying sensitivity labels to files stored in third-party cloud storage apps like Box or Dropbox through Defender for Cloud Apps integration
Microsoft Defender for Cloud Apps integrates with Microsoft Purview Information Protection to extend labeling and protection to files in third-party SaaS applications like Box, Salesforce, and Dropbox.
Which Microsoft Purview Information Protection feature allows an organization to define its own sensitive data patterns using regular expressions and keyword lists?