MS-500 Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: Which Microsoft 365 compliance feature helps organizations meet ISO 27001 requirements by mapping security controls to Microsoft service configurations?
- Microsoft Defender XDR
- Microsoft Purview Compliance Manager with ISO 27001 template (Correct answer)
- Azure AD Identity Governance
- Microsoft Intune compliance policies
Correct answer: Microsoft Purview Compliance Manager with ISO 27001 template
Compliance Manager provides an ISO 27001 assessment template that maps controls to Microsoft-managed and customer-managed actions across Microsoft 365 services.
Question 2: A company processes payment card data alongside Microsoft 365 workloads. Which PCI DSS requirement is most directly addressed by enabling Microsoft 365 audit logging?
- Requirement 1: Install and maintain a firewall
- Requirement 10: Track and monitor all access to network resources and cardholder data (Correct answer)
- Requirement 3: Protect stored cardholder data
- Requirement 6: Develop and maintain secure systems
Correct answer: Requirement 10: Track and monitor all access to network resources and cardholder data
PCI DSS Requirement 10 mandates logging and monitoring of all access to network resources and cardholder data, which unified audit logs in Microsoft 365 directly support.
Question 3: Under GDPR's principle of data minimization, which Microsoft Purview feature helps ensure only necessary personal data is retained?
- Sensitivity labels
- Retention policies with automatic deletion (Correct answer)
- Information barriers
- Customer Lockbox
Correct answer: Retention policies with automatic deletion
Retention policies with auto-deletion enforce data minimization by automatically removing personal data after it is no longer needed for its original purpose.
Question 4: Which Microsoft 365 feature enables an organization to demonstrate compliance with the EU-U.S. Data Privacy Framework for transatlantic data transfers?
- Azure AD B2C
- Microsoft Privacy Statement and Data Processing Addendum (DPA) (Correct answer)
- Microsoft Defender for Identity
- Sensitivity label auto-classification
Correct answer: Microsoft Privacy Statement and Data Processing Addendum (DPA)
Microsoft's Data Processing Addendum and adherence to the EU-U.S. Data Privacy Framework provide the contractual and certification basis for lawful transatlantic data transfers.
Question 5: A CISO needs to demonstrate that privileged administrative access to Microsoft 365 is appropriately controlled for a SOX audit. Which feature is most relevant?
- Microsoft Purview eDiscovery
- Azure AD Privileged Identity Management (PIM) with just-in-time access (Correct answer)
- Microsoft Defender for Office 365 Safe Links
- Microsoft 365 Message Encryption
Correct answer: Azure AD Privileged Identity Management (PIM) with just-in-time access
Azure AD PIM provides just-in-time privileged access with approval workflows and audit trails, directly addressing SOX requirements for access controls over financial systems.
Question 6: Which Microsoft tool provides the official documentation of how Microsoft's cloud services comply with regulatory standards, available for customer auditor review?
- Microsoft 365 Admin Center
- Microsoft Service Trust Portal (Correct answer)
- Azure Compliance Dashboard
- Microsoft Purview Hub
Correct answer: Microsoft Service Trust Portal
The Microsoft Service Trust Portal hosts audit reports, compliance guides, and trust documents that customers can share with auditors to demonstrate Microsoft's regulatory compliance.
Question 7: An organization must comply with FedRAMP requirements to use Microsoft 365 for federal government workloads. Which Microsoft 365 offering is FedRAMP High authorized?
- Microsoft 365 Business Premium
- Microsoft 365 Government (GCC High) (Correct answer)
- Microsoft 365 Enterprise E3
- Microsoft 365 Frontline Worker
Correct answer: Microsoft 365 Government (GCC High)
Microsoft 365 Government GCC High is FedRAMP High authorized and designed for U.S. federal agencies and contractors handling controlled unclassified information.
Which Microsoft 365 compliance feature helps organizations meet ISO 27001 requirements by mapping security controls to Microsoft service configurations?