Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataHard

A global enterprise is designing a new customer relationship management (CRM) application that will process and store highly sensitive customer data, including financial and health information. The company has a strict data classification policy that requires all sensitive documents and emails generated by the CRM to be automatically labeled, encrypted, and have access restricted based on user roles and the sensitivity of the content. This protection needs to persist even when documents are shared externally. Which Microsoft technology should the security architect leverage to meet these comprehensive data protection requirements?

  1. AMicrosoft Information Protection (MIP) sensitivity labels
  2. BAzure Data Lake Storage Gen2 ACLs
  3. CAzure Policy
  4. DAzure Defender for Cloud Apps
Show answer & explanation

Correct answer: A. Microsoft Information Protection (MIP) sensitivity labels

Microsoft Information Protection (MIP) sensitivity labels allow organizations to classify and protect sensitive data across various applications and services. These labels can automatically apply encryption, visual markings, and access restrictions that persist with the data, even when shared externally, directly addressing the requirements for persistent, role-based protection.

Why the other options are wrong

  • B. Azure Data Lake Storage Gen2 ACLs manage access to files and folders within Data Lake Storage but do not provide content-aware classification, encryption, or persistent protection when documents are moved or shared.
  • C. Azure Policy helps enforce organizational standards and assess compliance for Azure resources but does not directly apply persistent protection to sensitive content within documents and emails.
  • D. Azure Defender for Cloud Apps (now Microsoft Defender for Cloud Apps) is a Cloud Access Security Broker (CASB) that provides visibility and control over cloud apps, but it doesn't directly apply persistent data labeling, encryption, and access control to documents.

Microsoft Information Protection (MIP) Sensitivity Labels

Microsoft Information Protection (MIP) sensitivity labels enable organizations to classify and protect their sensitive data across various Microsoft services and applications, and even third-party apps. These labels apply encryption, visual markings, and access restrictions that persist with the content.

  • Persistent protection that travels with the data.
  • Automated or manual classification and labeling.
  • Supports encryption and access restrictions based on label.
  • Integrates across Microsoft 365, Azure, and other platforms.

Memory trick: MIP labels are like smart tags that protect your data wherever it goes.

More Design security for applications and data questions