SC-100 Compliance, Governance & Data Security 2 — Questions and Answers
Question 1: A company must demonstrate GDPR compliance for EU customer data stored in Azure. Which Microsoft service provides a centralized view of regulatory compliance posture across Azure resources?
- Microsoft Sentinel
- Microsoft Defender for Cloud
- Azure Policy
- Microsoft Purview Compliance Manager (Correct answer)
Correct answer: Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager provides a centralized dashboard for assessing and tracking regulatory compliance posture, including GDPR.
Question 2: An organization needs to prevent accidental sharing of credit card numbers in Microsoft Teams messages. Which Microsoft Purview feature should be implemented?
- Sensitivity labels
- Data Loss Prevention (DLP) policies (Correct answer)
- Retention policies
- Communication compliance
Correct answer: Data Loss Prevention (DLP) policies
DLP policies in Microsoft Purview detect and block sharing of sensitive information like credit card numbers across Microsoft 365 services including Teams.
Question 3: A cybersecurity architect needs to classify Azure resources based on their data sensitivity to enforce access controls. Which Azure feature enables resource classification through tagging for governance?
- Azure Blueprints
- Azure Resource Manager tags
- Microsoft Purview data catalog (Correct answer)
- Azure Policy initiatives
Correct answer: Microsoft Purview data catalog
Microsoft Purview data catalog provides automated data discovery and classification across Azure and on-premises data sources.
Question 4: Under the shared responsibility model in Azure, which security control remains solely the customer's responsibility regardless of the service model (IaaS, PaaS, or SaaS)?
- Physical security of datacenters
- Operating system patching
- Network infrastructure security
- Data classification and accountability (Correct answer)
Correct answer: Data classification and accountability
Data classification and accountability always remains the customer's responsibility across all cloud service models.
Question 5: An organization must retain audit logs for 7 years to meet financial regulatory requirements. Which Azure service should be configured to archive logs cost-effectively for this duration?
- Azure Monitor Log Analytics workspace
- Azure Storage with lifecycle management policies (Correct answer)
- Microsoft Sentinel SIEM
- Azure Event Hub
Correct answer: Azure Storage with lifecycle management policies
Azure Storage with lifecycle management policies can automatically tier data to cool/archive tiers, making long-term log retention cost-effective.
Question 6: A multinational company needs to ensure data residency requirements are met so customer data never leaves specific Azure regions. Which governance mechanism enforces this at scale?
- Azure Active Directory Conditional Access
- Azure Policy with 'Allowed locations' built-in policy (Correct answer)
- Azure Blueprints assignments
- Microsoft Defender for Cloud recommendations
Correct answer: Azure Policy with 'Allowed locations' built-in policy
The 'Allowed locations' Azure Policy restricts the Azure regions where resources can be deployed, enforcing data residency at scale.
Question 7: A security architect is designing controls for Microsoft 365. Which feature allows administrators to create legally defensible holds on mailboxes and SharePoint content for litigation purposes?
- Retention labels with record locking
- Microsoft Purview eDiscovery holds (Correct answer)
- Microsoft Defender for Office 365
- Azure Information Protection
Correct answer: Microsoft Purview eDiscovery holds
Microsoft Purview eDiscovery holds preserve mailbox and SharePoint content in place for litigation or investigation purposes.
A company must demonstrate GDPR compliance for EU customer data stored in Azure.
Which Microsoft service provides a centralized view of regulatory compliance posture across Azure resources?