SC-100 Compliance, Governance & Data Security 3 — Questions and Answers
Question 1: An organization is implementing Zero Trust for data. Which Microsoft Purview capability automatically applies sensitivity labels to documents based on content inspection?
- Manual labeling policies
- Auto-labeling policies (Correct answer)
- Default label policies
- Mandatory labeling
Correct answer: Auto-labeling policies
Auto-labeling policies in Microsoft Purview scan content and automatically apply sensitivity labels based on sensitive information types detected.
Question 2: A CISO needs to implement controls ensuring employees cannot forward emails labeled 'Confidential' to external recipients. Which technology enforces this restriction?
- Microsoft Purview Information Protection with Rights Management (Correct answer)
- Exchange transport rules only
- Microsoft Defender for Office 365 Safe Links
- Conditional Access App Control
Correct answer: Microsoft Purview Information Protection with Rights Management
Microsoft Purview Information Protection with Azure Rights Management (RMS) enforces usage restrictions like preventing forwarding, independent of the email client.
Question 3: During a compliance audit, an auditor requests evidence that only authorized personnel accessed sensitive Azure key vaults. Which log source provides this evidence?
- Azure Activity logs
- Azure Key Vault diagnostic logs with audit events (Correct answer)
- Microsoft Entra sign-in logs
- Azure Monitor metrics
Correct answer: Azure Key Vault diagnostic logs with audit events
Azure Key Vault diagnostic logs with audit events record every operation on keys, secrets, and certificates including who accessed them.
Question 4: An organization wants to apply consistent governance policies across multiple Azure subscriptions and management groups. Which resource packages policies, RBAC, and ARM templates together for repeatable deployments?
- Azure Policy initiatives
- Azure Blueprints (Correct answer)
- ARM template specs
- Azure Resource Manager tags
Correct answer: Azure Blueprints
Azure Blueprints package policies, RBAC assignments, and ARM templates into a single artifact for repeatable, compliant environment deployments.
Question 5: A company processes health data subject to HIPAA. Which Azure feature provides a BAA (Business Associate Agreement) and maps controls to HIPAA requirements?
- Azure Security Center regulatory compliance dashboard
- Microsoft Purview Compliance Manager with HIPAA assessment (Correct answer)
- Azure Defender for SQL
- Microsoft Entra ID Protection
Correct answer: Microsoft Purview Compliance Manager with HIPAA assessment
Microsoft Purview Compliance Manager includes HIPAA assessment templates that map controls to requirements, and Microsoft provides a BAA for covered Azure services.
Question 6: A cybersecurity architect must prevent users from downloading files from SharePoint Online onto unmanaged personal devices. Which solution enforces this without blocking access to SharePoint entirely?
- Conditional Access policies with session controls via Microsoft Defender for Cloud Apps (Correct answer)
- Azure AD Multi-Factor Authentication
- Microsoft Purview DLP for endpoints
- SharePoint site-level external sharing settings
Correct answer: Conditional Access policies with session controls via Microsoft Defender for Cloud Apps
Conditional Access with Microsoft Defender for Cloud Apps session controls can allow SharePoint access but block downloads on unmanaged devices.
Question 7: An organization must demonstrate that Azure encryption keys used for customer data are exclusively controlled by the customer and not accessible to Microsoft. Which Azure Key Vault feature achieves this?
- Azure Key Vault Standard tier
- Customer-Managed Keys (CMK) with Azure Key Vault
- Azure Key Vault Managed HSM (Correct answer)
- Azure Dedicated HSM
Correct answer: Azure Key Vault Managed HSM
Azure Key Vault Managed HSM is FIPS 140-2 Level 3 validated and ensures the HSM is dedicated to the customer with no Microsoft access to keys.
An organization is implementing Zero Trust for data.
Which Microsoft Purview capability automatically applies sensitivity labels to documents based on content inspection?