AZ-301 Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: A defense contractor must comply with CMMC (Cybersecurity Maturity Model Certification) Level 2. Which set of controls does this level primarily align to?
- NIST SP 800-53 High baseline
- NIST SP 800-171 practices (Correct answer)
- CIS Controls v8 Level 2
- ISO 27001 Annex A controls
Correct answer: NIST SP 800-171 practices
CMMC Level 2 aligns to the 110 practices in NIST SP 800-171, which protects Controlled Unclassified Information (CUI) in nonfederal systems.
Question 2: Your organization uses Azure Key Vault to manage encryption keys for FIPS 140-2 compliance. Which Key Vault tier provides HSM-backed keys that meet FIPS 140-2 Level 3 validation?
- Azure Key Vault Standard tier
- Azure Key Vault Premium tier with HSM-protected keys (Correct answer)
- Azure Dedicated HSM service only
- Azure Key Vault with customer-managed keys
Correct answer: Azure Key Vault Premium tier with HSM-protected keys
Azure Key Vault Premium tier uses FIPS 140-2 Level 3 validated HSMs to protect keys, meeting requirements for regulated industries.
Question 3: An organization subject to Sarbanes-Oxley (SOX) needs to implement controls over financial reporting systems in Azure. Which SOX section specifically addresses IT general controls?
- Section 302 - Corporate Responsibility for Financial Reports
- Section 404 - Management Assessment of Internal Controls (Correct answer)
- Section 409 - Real-Time Issuer Disclosures
- Section 802 - Criminal Penalties for Document Alteration
Correct answer: Section 404 - Management Assessment of Internal Controls
SOX Section 404 requires management to assess and report on internal controls over financial reporting, including IT general controls in cloud environments.
Question 4: Under the EU AI Act, which risk category would an AI system deployed on Azure that makes autonomous credit decisions for EU consumers fall into?
- Minimal risk
- Limited risk
- High risk (Correct answer)
- Unacceptable risk
Correct answer: High risk
AI systems making credit decisions are explicitly classified as high-risk under the EU AI Act Annex III, requiring conformity assessments and enhanced transparency.
Question 5: A company must comply with California Consumer Privacy Act (CCPA). Which Azure feature helps implement the consumer right to opt-out of the sale of personal information?
- Azure Active Directory B2C consent management
- Microsoft Purview subject rights request management (Correct answer)
- Azure Policy data classification tags
- Azure Monitor audit logs
Correct answer: Microsoft Purview subject rights request management
Microsoft Purview's subject rights request management helps organizations respond to consumer privacy requests including CCPA opt-out requests at scale.
Question 6: Your Azure deployment must comply with ITAR (International Traffic in Arms Regulations). Which control is most critical to implement for ITAR-regulated technical data?
- Enable Azure DDoS Protection Standard
- Restrict access to US Persons only using Azure Government and strict identity controls (Correct answer)
- Implement Azure Firewall with IDPS signatures
- Enable Microsoft Defender for Cloud at Standard tier
Correct answer: Restrict access to US Persons only using Azure Government and strict identity controls
ITAR requires that access to controlled technical data be restricted to US Persons (citizens, permanent residents, etc.), which requires Azure Government combined with strict identity and access controls.
Question 7: A financial institution subject to FINRA regulations must retain broker-dealer communications for 3 years. Which Azure configuration ensures this retention while preventing premature deletion?
- Azure Backup with geo-redundant storage
- Azure Blob Storage immutable storage with regulatory compliance hold (Correct answer)
- Azure Archive tier with soft delete enabled
- Azure Data Lake with ACLs restricting delete permissions
Correct answer: Azure Blob Storage immutable storage with regulatory compliance hold
Azure Blob immutable storage with regulatory compliance hold prevents deletion or modification, satisfying FINRA's record retention requirements for broker-dealer communications.
A defense contractor must comply with CMMC (Cybersecurity Maturity Model Certification) Level 2.
Which set of controls does this level primarily align to?