โ† All AZ-301 Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A defense contractor must comply with CMMC (Cybersecurity Maturity Model Certification) Level 2. Which set of controls does this level primarily align to?

    Answer: NIST SP 800-171 practices

    CMMC Level 2 aligns to the 110 practices in NIST SP 800-171, which protects Controlled Unclassified Information (CUI) in nonfederal systems.

  2. Your organization uses Azure Key Vault to manage encryption keys for FIPS 140-2 compliance. Which Key Vault tier provides HSM-backed keys that meet FIPS 140-2 Level 3 validation?

    Answer: Azure Key Vault Premium tier with HSM-protected keys

    Azure Key Vault Premium tier uses FIPS 140-2 Level 3 validated HSMs to protect keys, meeting requirements for regulated industries.

  3. An organization subject to Sarbanes-Oxley (SOX) needs to implement controls over financial reporting systems in Azure. Which SOX section specifically addresses IT general controls?

    Answer: Section 404 - Management Assessment of Internal Controls

    SOX Section 404 requires management to assess and report on internal controls over financial reporting, including IT general controls in cloud environments.

  4. Under the EU AI Act, which risk category would an AI system deployed on Azure that makes autonomous credit decisions for EU consumers fall into?

    Answer: High risk

    AI systems making credit decisions are explicitly classified as high-risk under the EU AI Act Annex III, requiring conformity assessments and enhanced transparency.

  5. A company must comply with California Consumer Privacy Act (CCPA). Which Azure feature helps implement the consumer right to opt-out of the sale of personal information?

    Answer: Microsoft Purview subject rights request management

    Microsoft Purview's subject rights request management helps organizations respond to consumer privacy requests including CCPA opt-out requests at scale.

  6. Your Azure deployment must comply with ITAR (International Traffic in Arms Regulations). Which control is most critical to implement for ITAR-regulated technical data?

    Answer: Restrict access to US Persons only using Azure Government and strict identity controls

    ITAR requires that access to controlled technical data be restricted to US Persons (citizens, permanent residents, etc.), which requires Azure Government combined with strict identity and access controls.

  7. A financial institution subject to FINRA regulations must retain broker-dealer communications for 3 years. Which Azure configuration ensures this retention while preventing premature deletion?

    Answer: Azure Blob Storage immutable storage with regulatory compliance hold

    Azure Blob immutable storage with regulatory compliance hold prevents deletion or modification, satisfying FINRA's record retention requirements for broker-dealer communications.