SC-100 Compliance, Governance & Data Security 5 — Questions and Answers
Question 1: A cybersecurity architect must ensure that sensitive documents labeled 'Top Secret' can only be opened by users on compliant, Intune-managed devices. Which combination of technologies achieves this?
- Sensitivity labels with RMS protection + Conditional Access device compliance policy (Correct answer)
- DLP policies + Azure AD MFA
- Azure Information Protection scanner + Defender for Endpoint
- Retention labels + SharePoint external sharing controls
Correct answer: Sensitivity labels with RMS protection + Conditional Access device compliance policy
Sensitivity labels with RMS protection define who can access content, and Conditional Access policies with device compliance requirements restrict access to managed devices.
Question 2: An insider threat investigation reveals an employee copied 10,000 files to a USB drive. Which Microsoft solution could have detected and blocked this data exfiltration in real time?
- Microsoft Purview Communication Compliance
- Microsoft Purview Endpoint DLP (Correct answer)
- Microsoft Defender for Identity
- Azure Sentinel UEBA
Correct answer: Microsoft Purview Endpoint DLP
Microsoft Purview Endpoint DLP monitors and can block sensitive data from being copied to removable storage devices on Windows endpoints.
Question 3: A compliance officer needs to prove that a document was unaltered since it was originally saved. Which Microsoft Purview feature locks a labeled record so it cannot be modified or deleted?
- Sensitivity label with encryption
- Retention label declared as a regulatory record (Correct answer)
- eDiscovery hold
- Immutable storage in Azure Blob
Correct answer: Retention label declared as a regulatory record
Retention labels declared as regulatory records lock the content, preventing modification or deletion for the full retention period.
Question 4: An organization wants to use Microsoft Defender for Cloud to assess compliance with the Azure CIS Benchmark. What must be done before the assessment appears in the regulatory compliance dashboard?
- Deploy Azure Blueprints with CIS template
- Assign the CIS standard in the Defender for Cloud environment settings (Correct answer)
- Enable Azure Policy guest configuration
- Configure Microsoft Sentinel data connectors
Correct answer: Assign the CIS standard in the Defender for Cloud environment settings
The CIS Benchmark (or any regulatory standard) must be explicitly assigned in Defender for Cloud environment settings to appear in the compliance dashboard.
Question 5: A security architect is designing a solution to detect when employees send emails that contain confidential competitor analysis documents externally. Which Microsoft 365 capability provides this detection with policy-based alerting?
- Microsoft Purview DLP with sensitive information types and email conditions (Correct answer)
- Microsoft Defender for Office 365 anti-phishing policies
- Exchange Online Protection (EOP) spam filtering
- Microsoft Entra ID Conditional Access
Correct answer: Microsoft Purview DLP with sensitive information types and email conditions
Microsoft Purview DLP policies can detect sensitive information types in emails and trigger alerts or blocks when sent to external recipients.
Question 6: An organization must implement data minimization per GDPR principles for customer data in Azure SQL Database. Which approach best supports this architectural requirement?
- Enable Azure Defender for SQL
- Implement dynamic data masking and column-level encryption for non-essential data access (Correct answer)
- Enable Transparent Data Encryption (TDE)
- Configure Azure SQL firewall rules
Correct answer: Implement dynamic data masking and column-level encryption for non-essential data access
Dynamic data masking restricts non-privileged users from seeing full sensitive data, and column-level encryption limits data exposure, supporting GDPR data minimization principles.
Question 7: A governance team wants quarterly reviews of all external users who have been granted access to Microsoft Teams and SharePoint. Which Microsoft Entra ID feature automates this review process?
- Microsoft Entra ID Protection risk policies
- Microsoft Entra Access Reviews (Correct answer)
- Azure AD Privileged Identity Management (PIM)
- Conditional Access guest user policies
Correct answer: Microsoft Entra Access Reviews
Microsoft Entra Access Reviews enable scheduled, automated reviews of group memberships and access rights, including external/guest users.
A cybersecurity architect must ensure that sensitive documents labeled 'Top Secret' can only be opened by users on compliant, Intune-managed devices.
Which combination of technologies achieves this?