MS-100 Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Your organization must comply with HIPAA. Which Microsoft 365 feature allows you to automatically detect and protect documents containing Protected Health Information (PHI)?
- Azure Information Protection labels applied manually
- Data Loss Prevention policies with HIPAA template (Correct answer)
- Microsoft Defender for Cloud Apps session policies
- Conditional Access policies with device compliance
Correct answer: Data Loss Prevention policies with HIPAA template
DLP policies using the HIPAA template automatically detect PHI patterns and apply protection actions such as blocking sharing or alerting administrators.
Question 2: Under GDPR, a data subject requests erasure of their personal data. Which Microsoft 365 Compliance Center tool is used to locate and delete that data across Microsoft 365 services?
- eDiscovery (Premium) export
- Content Search with purge action
- Data Subject Request (DSR) tool in Privacy (Correct answer)
- Compliance Manager assessment
Correct answer: Data Subject Request (DSR) tool in Privacy
The DSR tool in the Microsoft Purview Privacy portal guides administrators through locating, reviewing, and deleting personal data in response to GDPR erasure requests.
Question 3: An organization subject to FedRAMP wants to store Microsoft 365 data exclusively within US datacenters. Which offering satisfies this requirement?
- Microsoft 365 E5 with Compliance add-on
- Microsoft 365 Government (GCC High) (Correct answer)
- Microsoft 365 Business Premium with Data Residency
- Microsoft 365 E3 with Advanced Compliance
Correct answer: Microsoft 365 Government (GCC High)
Microsoft 365 GCC High is designed for US federal agencies and contractors requiring FedRAMP High authorization with data stored only in US datacenters.
Question 4: Which Microsoft Purview feature provides a risk score and recommended actions to help an organization measure its compliance posture against regulatory standards?
- Audit (Standard)
- Compliance Manager (Correct answer)
- Insider Risk Management
- Communication Compliance
Correct answer: Compliance Manager
Compliance Manager provides a compliance score based on completed improvement actions mapped to regulatory frameworks like ISO 27001, GDPR, and NIST.
Question 5: A company using Microsoft 365 must meet CCPA requirements. Which action is required when a California consumer submits a 'Do Not Sell My Personal Information' request?
- Delete all data immediately using Content Search purge
- Process the request via the DSR workflow and restrict data sharing (Correct answer)
- Apply a sensitivity label to all personal data documents
- Enable Information Barriers to prevent data flow
Correct answer: Process the request via the DSR workflow and restrict data sharing
CCPA opt-out requests are handled through the Data Subject Request workflow, which allows organizations to restrict or stop the sale/sharing of personal information.
Question 6: Under SOC 2 Type II requirements, an auditor requests evidence that Microsoft 365 admin activity is being logged. Which feature provides this audit trail?
- Microsoft Secure Score recommendations
- Unified Audit Log in Microsoft Purview (Correct answer)
- Microsoft Defender for Identity alerts
- Azure AD Sign-in logs only
Correct answer: Unified Audit Log in Microsoft Purview
The Unified Audit Log captures admin and user activity across Microsoft 365 services and can be exported to satisfy SOC 2 Type II audit evidence requirements.
Question 7: An organization must retain all Exchange Online emails for seven years per SEC Rule 17a-4. Which Microsoft 365 feature enforces immutable retention to satisfy this requirement?
- Litigation Hold with a custom duration
- Retention policy with Preservation Lock enabled (Correct answer)
- In-Place Archive with auto-expanding archiving
- eDiscovery hold on all mailboxes
Correct answer: Retention policy with Preservation Lock enabled
Preservation Lock on a retention policy makes it immutable and prevents administrators from shortening or deleting the policy, satisfying SEC 17a-4 WORM requirements.
Your organization must comply with HIPAA.
Which Microsoft 365 feature allows you to automatically detect and protect documents containing Protected Health Information (PHI)?