How to auto-delete credit card content after 12 months in Microsoft 365?

Answer Correct answer: C, D — create a retention label with a 12-month retention period and an auto-labeling policy for the retention label using the built-in credit card SIT.

You have a Microsoft 365 E5 subscription. You need to ensure that any message or document containing a credit card number is deleted automatically 12 months after it was created. The solution must minimize administrative effort. Which two components should you create? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.

  1. a sensitivity label
  2. an auto-labeling policy for a sensitivity label
  3. a retention label Correct Answer
  4. an auto-labeling policy for a retention label Correct Answer
  5. a sensitive information type (SIT)

Community Votes

CD
100%

100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests retention vs sensitivity labels and auto-labeling policies; the trap is choosing a sensitivity label or creating a new SIT instead of using the built-in credit card SIT.

Microsoft 365 E5 requires a retention label and an auto-labeling policy for the retention label to delete any message or document containing a credit card number 12 months after creation. The correct SC-400 answer is C and D, leveraging the built-in credit card sensitive information type.

Selecting a sensitivity label plus an auto-labeling policy for a sensitivity label (A, B), because sensitivity labels classify and protect content but do not enforce automatic deletion after a retention period.

Community Discussion (4 comments)

ChrisBaird 👍 1 Selected: CD
There is a built-in SIT for credit card information. The question says least admin effort. No need to build a new SIT. This needs a retention label and a retention label policy.
Ruslan23 👍 2 Selected: CD
C: A retention label allow you to set the retention period for the data, so 12 months but you could do it manually. D: An auto-labeling policy allow you to automatically apply the retention label to "any message or document" as mentioned in the question that has the credit card number match.
CheMetto 👍 2 Selected: CD
CD for me too. You already own a SIT for that info, so you don't need to create a new one. So you create an auto-labeling policy, you apply based on sit Credit card number, and you autoapply the retention label previously created.
emartiy 👍 4 Selected: CD
I think we need a retention label to specify how long an email or item needs to be retained based on creation time. And then apply this label automatically to the emails and files based on the SIT which check if content match credit card.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A retention label (C) is the only Microsoft 365 component that defines a retention period and an action such as delete after 12 months from creation. An auto-labeling policy for a retention label (D) then automatically applies that label to any message or document that matches the built-in credit card sensitive information type, so no manual labeling is needed. Together they satisfy both the automatic deletion requirement and the least administrative effort directive because the credit card SIT already exists in Microsoft 365. The label must be a retention label, not a sensitivity label, because only retention labels control item lifecycle and deletion.

Why the Other Options Are Wrong

A sensitivity label (A) classifies and can encrypt or mark content, but it does not delete items after a defined period, so it cannot satisfy the 12-month deletion requirement. An auto-labeling policy for a sensitivity label (B) would only apply classification, not retention or deletion, and would leave credit card messages and documents in place indefinitely. A sensitive information type (E) is used for detection, but Microsoft 365 already includes a built-in credit card SIT; creating a new one adds administrative effort without changing the deletion outcome. The question asks for components to create, and E is unnecessary because the built-in SIT is available.

Community Comment Notes

Learners overwhelmingly chose CD, and their reasoning matches the official behavior. As emartiy noted, you need a retention label to specify how long an item is retained based on creation time and then "apply this label automatically to the emails and files based on the SIT" that matches credit card numbers. Ruslan23 summarized that "A retention label allow you to set the retention period" while the auto-labeling policy applies it to "any message or document" with a credit card match. CheMetto emphasized that "you already own a SIT for that info" so there is no need to create a new one. ChrisBaird similarly highlighted that "There is a built-in SIT for credit card information" and that least admin effort points to using it rather than building a custom SIT.

Official Reference

Exam Strategy

Focus on the verb deleted—retention labels are the only component that enforces deletion; auto-labeling policies for retention labels apply them at scale without manual effort. Remember that the built-in credit card SIT exists, so do not waste exam time creating a new sensitive information type.

Frequently Asked Questions

Why is a sensitivity label not the right choice for automatic deletion?

Sensitivity labels classify, encrypt, and mark content but do not set a retention or deletion period; only retention labels can automatically delete items 12 months after creation.

Do I need to create a new sensitive information type for credit card numbers?

No. Microsoft 365 includes a built-in credit card SIT, and using it minimizes administrative effort; you only need a retention label and an auto-labeling policy for it.

Related Analysis

← Back to SC-400 Study Guide