MS-500 Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: A healthcare organization must ensure Microsoft 365 data handling meets HIPAA requirements. Which Microsoft 365 compliance feature provides a Business Associate Agreement (BAA)?
- Azure AD Conditional Access
- Microsoft 365 HIPAA BAA available through the Service Trust Portal (Correct answer)
- Microsoft Purview Audit
- Microsoft Defender for Office 365
Correct answer: Microsoft 365 HIPAA BAA available through the Service Trust Portal
Microsoft provides a HIPAA BAA for covered entities and business associates through the Service Trust Portal, covering eligible Microsoft 365 services.
Question 2: Under GDPR, which Microsoft 365 tool allows an organization to respond to a Data Subject Request (DSR) to export a user's personal data?
- Microsoft Defender for Endpoint
- Microsoft Purview Content Search (Correct answer)
- Azure AD Identity Protection
- Microsoft 365 Compliance Score
Correct answer: Microsoft Purview Content Search
Microsoft Purview Content Search enables administrators to find and export content associated with a specific user to fulfill GDPR Data Subject Requests.
Question 3: A company subject to SOC 2 Type II audits needs evidence that access reviews are performed regularly. Which Microsoft 365 feature best supports this?
- Microsoft Purview Information Barriers
- Azure AD Access Reviews (Correct answer)
- Microsoft Secure Score
- Sensitivity label policies
Correct answer: Azure AD Access Reviews
Azure AD Access Reviews enable organizations to regularly review and certify user access to groups and applications, providing audit evidence for SOC 2 Type II.
Question 4: Which regulation specifically mandates that organizations notify affected individuals within 72 hours of discovering a personal data breach?
- HIPAA
- GDPR (Correct answer)
- CCPA
- PCI DSS
Correct answer: GDPR
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 5: An organization needs to demonstrate compliance with NIST 800-53 controls within Microsoft 365. Which tool provides pre-built NIST assessments?
- Microsoft Defender for Cloud Apps
- Microsoft Purview Compliance Manager (Correct answer)
- Azure Security Center
- Microsoft 365 Secure Score
Correct answer: Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager includes pre-built assessment templates for NIST 800-53 that map controls to Microsoft 365 configuration actions.
Question 6: Under the California Consumer Privacy Act (CCPA), what right do California residents have that organizations must fulfill using Microsoft 365 tools?
- Right to encryption of all stored data
- Right to know what personal information is collected and to request deletion (Correct answer)
- Right to multi-factor authentication
- Right to audit all administrator actions
Correct answer: Right to know what personal information is collected and to request deletion
CCPA grants California residents the right to know what personal data is collected about them and to request its deletion, which can be fulfilled using Microsoft Purview DSR tools.
Question 7: A financial services firm must comply with SEC Rule 17a-4 for immutable record retention. Which Microsoft 365 feature satisfies this requirement?
- Microsoft Purview Retention Labels with Preservation Lock (Correct answer)
- Azure AD Privileged Identity Management
- Microsoft Teams channel archiving
- SharePoint versioning
Correct answer: Microsoft Purview Retention Labels with Preservation Lock
Preservation Lock on Microsoft Purview retention policies ensures records cannot be deleted or modified before the retention period expires, satisfying SEC Rule 17a-4 WORM requirements.
A healthcare organization must ensure Microsoft 365 data handling meets HIPAA requirements.
Which Microsoft 365 compliance feature provides a Business Associate Agreement (BAA)?