Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the concepts of security, compliance, and identityHard

A large organization with a complex IT environment needs to ensure that sensitive data stored in various cloud services and on-premises systems is classified, labeled, and protected according to its sensitivity level. This includes applying encryption, access restrictions, and visual markings based on content. Which security concept specifically addresses these requirements?

  1. AData Loss Prevention (DLP)
  2. BData Retention
  3. CInformation Protection
  4. DData Governance
Show answer & explanation

Correct answer: C. Information Protection

Information Protection, particularly in Microsoft's context (e.g., Azure Information Protection), focuses on classifying, labeling, and applying protection (encryption, access controls, visual markings) directly to sensitive data itself, regardless of where it's stored or who accesses it.

Why the other options are wrong

  • A. DLP primarily focuses on preventing sensitive data from leaving the organization's control, not on classifying and protecting data at rest or in use with labels and encryption.
  • B. Data Retention deals with how long data is kept, not its classification or protection methods.
  • D. Data Governance is a broader concept covering policies and processes for managing data assets, with information protection as a component.

Information Protection

Information Protection is the practice of protecting sensitive information from unauthorized access, use, disclosure, disruption, modification, or destruction, often involving classification, labeling, and rights management directly applied to the data.

  • Classifies data by sensitivity.
  • Applies labels and visual markings.
  • Enforces encryption and access controls directly on the data.

Memory trick: Label, Protect, Control: Information's journey.

More Describe the concepts of security, compliance, and identity questions