SC-100 Compliance, Governance & Data Security 4 — Questions and Answers
Question 1: A security team needs to identify where sensitive data (PII, financial) is stored across Azure SQL databases, Azure Blob Storage, and on-premises SQL servers. Which service provides unified data discovery across these sources?
- Azure Security Center
- Microsoft Purview (formerly Azure Purview) data map (Correct answer)
- Microsoft Defender for SQL
- Azure Monitor
Correct answer: Microsoft Purview (formerly Azure Purview) data map
Microsoft Purview's data map scans and classifies sensitive data across multi-cloud and on-premises data sources in a unified catalog.
Question 2: An organization's compliance requirement mandates that all administrative actions on production Azure resources be reviewed and approved before execution. Which service supports just-in-time privileged access with approval workflows?
- Azure Active Directory Privileged Identity Management (PIM) (Correct answer)
- Azure Role-Based Access Control (RBAC)
- Microsoft Entra Access Reviews
- Conditional Access policies
Correct answer: Azure Active Directory Privileged Identity Management (PIM)
Azure AD Privileged Identity Management (PIM) enables just-in-time role activation with required approval workflows for elevated access.
Question 3: A company must ensure that all Azure resources are tagged with cost center and environment tags before deployment. Which Azure governance tool enforces this requirement at resource creation time?
- Azure Advisor recommendations
- Azure Policy with 'Require a tag' effect in Deny mode (Correct answer)
- Azure Cost Management budgets
- Azure Blueprints assignments only
Correct answer: Azure Policy with 'Require a tag' effect in Deny mode
Azure Policy with a 'Require a tag' policy in Deny effect blocks resource creation if the required tags are absent.
Question 4: During an incident response, a security architect needs to preserve the contents of a suspect employee's Microsoft 365 mailbox to prevent evidence tampering. What is the most targeted action?
- Apply a Microsoft Purview retention policy to all mailboxes
- Place the specific mailbox on Litigation Hold (Correct answer)
- Enable mailbox auditing tenant-wide
- Export the mailbox via eDiscovery content search
Correct answer: Place the specific mailbox on Litigation Hold
Litigation Hold preserves all mailbox content for a specific user, preventing deletion or modification while allowing the user to continue working.
Question 5: An architect is designing data sovereignty controls for a financial institution. Which Azure policy assignment scope provides the broadest coverage with a single assignment across all subscriptions in a tenant?
- Resource group scope
- Subscription scope
- Management group (root tenant) scope (Correct answer)
- Individual resource scope
Correct answer: Management group (root tenant) scope
Assigning Azure Policy at the root management group scope applies the policy to all subscriptions and resources within the entire Azure tenant.
Question 6: A company wants to automatically remediate non-compliant Azure resources (e.g., add missing encryption) without manual intervention. Which Azure Policy feature enables this?
- Policy initiative assignments
- DeployIfNotExists policy effect with managed identity (Correct answer)
- Audit policy effect with alerts
- Azure Blueprints auto-remediation
Correct answer: DeployIfNotExists policy effect with managed identity
The DeployIfNotExists policy effect with an assigned managed identity automatically deploys remediation resources when non-compliance is detected.
Question 7: An organization needs to meet NIST SP 800-53 controls for a US federal contract. Which Microsoft Purview Compliance Manager feature maps existing Microsoft controls to NIST requirements automatically?
- Custom assessments
- Pre-built regulatory assessments with Microsoft-managed controls (Correct answer)
- Compliance score improvement actions only
- Microsoft Secure Score integration
Correct answer: Pre-built regulatory assessments with Microsoft-managed controls
Compliance Manager's pre-built regulatory assessments include Microsoft-managed control mappings for NIST SP 800-53, showing which controls Microsoft already implements.
A security team needs to identify where sensitive data (PII, financial) is stored across Azure SQL databases, Azure Blob Storage, and on-premises SQL servers.
Which service provides unified data discovery across these sources?