nerdexam
Microsoft

AZ-500 · Question #25

You have an Azure subscription named Sub1 that is associated to an Azure Active Directory (Azure AD) tenant named contoso.com. You are assigned the Global administrator role for the tenant. You are…

The correct answer is A. Create a custom sensitive information type. Explanation Creating a custom sensitive information type must come first because sensitivity labels in Microsoft Purview (formerly part of Security Center) rely on sensitive information types as the underlying classification patterns that define what the label detects - you…

Submitted by sofia.br· Mar 6, 2026Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Question

You have an Azure subscription named Sub1 that is associated to an Azure Active Directory (Azure AD) tenant named contoso.com. You are assigned the Global administrator role for the tenant. You are responsible for managing Azure Security Center settings. You need to create a custom sensitivity label. What should you do first?

Options

  • ACreate a custom sensitive information type.
  • BElevate access for global administrators in Azure AD.
  • CUpgrade the pricing tier of the Security Center to Standard.
  • DEnable integration with Microsoft Cloud App Security.

How the community answered

(22 responses)
  • A
    82% (18)
  • B
    9% (2)
  • C
    5% (1)
  • D
    5% (1)

Explanation

Explanation

Creating a custom sensitive information type must come first because sensitivity labels in Microsoft Purview (formerly part of Security Center) rely on sensitive information types as the underlying classification patterns that define what the label detects - you cannot build a meaningful custom sensitivity label without first defining the data patterns it will recognize.

Why the distractors are wrong:

  • Option B (Elevate access for Global Administrators) is unnecessary because as a Global Administrator, you already have sufficient privileges to create sensitivity labels without needing to elevate access through the Azure AD root management group.
  • Option C (Upgrade to Standard pricing tier) relates to threat protection and advanced security features, not to the creation of sensitivity labels, which is handled through the compliance/information protection stack.
  • Option D (Enable Microsoft Cloud App Security integration) helps apply or enforce sensitivity labels across cloud apps, but it is not a prerequisite for creating the label itself.

Memory Tip

Think of it like building a house: the sensitive information type is the foundation (what you're looking for), and the sensitivity label is the house built on top of it. You must always lay the foundation before building - so type before label, every time.

Topics

#Sensitivity Labels#Data Classification#Microsoft Purview#Sensitive Information Types (SITs)

Community Discussion

No community discussion yet for this question.

Full AZ-500 Practice