Regulatory Frameworks & Compliance Flashcards
7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
A US federal agency is deploying workloads to Azure and requires FedRAMP High authorization. Which Azure environment is specifically designed to meet this requirement?
Answer: Azure Government
Azure Government is a physically isolated cloud specifically designed and authorized for US federal government workloads at FedRAMP High impact level.
Under the NIST Cybersecurity Framework, your organization needs to implement controls in the 'Identify' function. Which Azure service best helps you discover and classify sensitive data assets?
Answer: Microsoft Purview Data Map
Microsoft Purview Data Map scans and classifies data assets across your Azure environment, supporting the NIST CSF 'Identify' function's asset management requirements.
A healthcare organization needs to implement the minimum necessary standard under HIPAA. Which Azure feature enforces least-privilege access to PHI stored in Azure Storage?
Answer: Azure RBAC with custom roles scoped to specific containers
HIPAA's minimum necessary standard is implemented through Azure RBAC custom roles that grant only the specific permissions required for each user's job function.
Your organization must retain financial records for 7 years to comply with SEC regulations. Which Azure feature prevents deletion or modification of records during the retention period?
Answer: Azure Blob Storage immutable storage with time-based retention policies
Azure Blob immutable storage with WORM (Write Once, Read Many) time-based retention policies prevents records from being deleted or modified for SEC-required retention periods.
Which compliance framework specifically addresses the security of payment card data and requires quarterly network scans by an Approved Scanning Vendor (ASV)?
Answer: PCI DSS
PCI DSS requires quarterly external vulnerability scans performed by an ASV as part of its ongoing security requirements for cardholder data environments.
A company wants to demonstrate continuous compliance rather than point-in-time audits. Which Azure feature provides a real-time compliance score across multiple regulatory frameworks?
Answer: Microsoft Compliance Manager compliance score
Microsoft Compliance Manager provides a continuous compliance score that reflects your organization's current posture across multiple regulatory frameworks in real time.
Under GDPR Article 35, when is a Data Protection Impact Assessment (DPIA) required before processing personal data in Azure?
Answer: When processing is likely to result in high risk to individuals' rights and freedoms
GDPR Article 35 requires a DPIA when processing is likely to result in high risk to the rights and freedoms of natural persons, particularly for systematic profiling or sensitive data.