Microsoft Cybersecurity Architect (SC-100)Design security for applications and dataMedium
A multinational corporation is developing a new customer relationship management (CRM) application that will collect and process customer data across various regions. The application must comply with local data privacy regulations, such as GDPR in Europe and CCPA in California. The security architect needs to implement a data classification and labeling strategy that automatically identifies sensitive data, applies appropriate protection, and enforces access policies based on the data's sensitivity and regulatory requirements. Which Azure service combination provides the most comprehensive solution?
- AAzure Purview for data discovery and cataloging, integrated with Azure Synapse Analytics.
- BAzure Data Factory for data ingestion and Azure Blob Storage lifecycle management.
- CMicrosoft Defender for Cloud for vulnerability management and network security groups.
- DAzure Information Protection (AIP) with sensitivity labels and Azure Policy.
Show answer & explanationAnswer & explanation
Correct answer: D. Azure Information Protection (AIP) with sensitivity labels and Azure Policy.
Azure Information Protection (AIP) enables data classification and labeling, applying sensitivity labels that can enforce encryption, access restrictions, and visual markings. Azure Policy can then enforce rules based on these labels and other data attributes.
Why the other options are wrong
- A. Azure Purview is excellent for data governance, discovery, and cataloging. While it helps identify sensitive data, it doesn't directly apply protection (encryption, access control) or enforce policies in the same way AIP does. Synapse Analytics is for data warehousing and analytics.
- B. Azure Data Factory is for data integration and ETL processes. Blob Storage lifecycle management is for cost optimization and basic retention, not granular data classification or protection policies based on sensitivity.
- C. Microsoft Defender for Cloud focuses on cloud security posture management, threat protection, and vulnerability assessments, not direct data classification, labeling, and protection at the data level.
Azure Information Protection (AIP) Sensitivity Labels
Labels that can be applied to documents and emails to classify them according to their sensitivity, and then apply protection policies such as encryption, access restrictions, and visual markings.
- Supports manual, recommended, or automatic labeling.
- Integrates with Microsoft 365 services and other Azure services.
- Helps enforce data governance and regulatory compliance.
Memory trick: AIP Labels and Policies for Sensitive Data.