AZ-301 Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: A multinational company needs to map Azure Policy assignments to specific controls in multiple compliance frameworks simultaneously. Which capability in Azure supports this multi-framework approach?
- Azure Blueprints with multiple artifact assignments
- Azure Policy regulatory compliance built-in initiatives (Correct answer)
- Azure Resource Graph compliance queries
- Microsoft Defender for Cloud recommendations
Correct answer: Azure Policy regulatory compliance built-in initiatives
Azure Policy includes built-in regulatory compliance initiatives (e.g., NIST SP 800-53, PCI DSS, ISO 27001) that map Azure Policy definitions to specific framework controls.
Question 2: Under GDPR, your organization acts as a data processor for EU clients. Which contractual requirement must be in place before you can process personal data on behalf of a client?
- A Non-Disclosure Agreement covering personal data
- A Data Processing Agreement (DPA) meeting Article 28 requirements (Correct answer)
- An EU Standard Contractual Clause for data sharing
- A joint controller agreement under Article 26
Correct answer: A Data Processing Agreement (DPA) meeting Article 28 requirements
GDPR Article 28 requires a Data Processing Agreement between controllers and processors that specifies the subject matter, duration, nature, and purpose of the processing.
Question 3: A company must implement cloud security controls consistent with the CIS Azure Foundations Benchmark. Which Azure service automatically assesses your environment against this benchmark?
- Azure Advisor
- Microsoft Defender for Cloud with CIS benchmark assessment (Correct answer)
- Azure Monitor Workbooks
- Azure Resource Policy compliance
Correct answer: Microsoft Defender for Cloud with CIS benchmark assessment
Microsoft Defender for Cloud includes built-in assessment of your Azure environment against the CIS Azure Foundations Benchmark with remediation guidance.
Question 4: Your organization must demonstrate that audit logs for a compliance audit cannot be tampered with. Which Azure Monitor feature provides cryptographic verification of log integrity?
- Log Analytics workspace data export
- Azure Monitor Logs with immutable storage (Correct answer)
- Diagnostic settings with Log Analytics retention
- Azure Sentinel log ingestion
Correct answer: Azure Monitor Logs with immutable storage
Azure Monitor Logs can be configured with immutable storage in Azure Blob to create tamper-evident, cryptographically verifiable audit logs.
Question 5: A healthcare organization implements Azure for storing electronic health records (EHR). Which HIPAA safeguard category requires implementing access controls, audit controls, and transmission security?
- Physical Safeguards
- Administrative Safeguards
- Technical Safeguards (Correct answer)
- Organizational Safeguards
Correct answer: Technical Safeguards
HIPAA Technical Safeguards require access controls, audit controls, integrity controls, and transmission security for electronic protected health information (ePHI).
Question 6: An organization must comply with NERC CIP standards for industrial control systems connected to Azure. Which security control is uniquely required by NERC CIP that differs from general cloud compliance frameworks?
- Multi-factor authentication for all users
- Electronic Security Perimeter with strict ingress/egress controls for Bulk Electric System assets (Correct answer)
- Encryption of data at rest using AES-256
- Annual penetration testing of internet-facing systems
Correct answer: Electronic Security Perimeter with strict ingress/egress controls for Bulk Electric System assets
NERC CIP requires an Electronic Security Perimeter (ESP) with defined access control to protect Bulk Electric System cyber assets, which is specific to energy sector infrastructure.
Question 7: A global organization must conduct a Transfer Impact Assessment (TIA) before moving personal data from the EU to Azure in the US. What is the primary purpose of this assessment?
- To evaluate Azure's network latency between EU and US regions
- To assess whether US surveillance laws undermine GDPR-level protections for transferred data (Correct answer)
- To calculate the cost impact of cross-border data transfers
- To verify that Azure's encryption standards meet EU requirements
Correct answer: To assess whether US surveillance laws undermine GDPR-level protections for transferred data
A TIA evaluates whether US laws (such as FISA Section 702) could allow government access to personal data in ways that undermine the protections provided by SCCs or other transfer mechanisms under GDPR.
A multinational company needs to map Azure Policy assignments to specific controls in multiple compliance frameworks simultaneously.
Which capability in Azure supports this multi-framework approach?