SC-200 Compliance & Regulatory Frameworks 2 — Questions and Answers
Question 1: A security analyst needs to demonstrate that the organization's Azure environment meets HIPAA requirements. Which Microsoft Purview feature provides a consolidated view of compliance posture against HIPAA controls?
- Microsoft Defender for Cloud regulatory compliance dashboard
- Microsoft Purview Compliance Manager (Correct answer)
- Azure Policy compliance dashboard
- Microsoft Sentinel compliance workbook
Correct answer: Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager provides pre-built assessments for HIPAA and other frameworks, tracking control implementation and offering improvement actions.
Question 2: Under GDPR, a data breach affecting EU residents must be reported to the supervisory authority within how many hours of discovery?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 96 hours
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 3: An SOC analyst is reviewing alerts in Microsoft Sentinel and needs to identify which incidents involve assets in scope for PCI DSS. What is the most effective approach?
- Filter incidents by severity level Critical
- Tag cardholder data environment (CDE) assets and use entity mapping in Sentinel (Correct answer)
- Enable all PCI DSS analytics rules in Sentinel
- Review all incidents involving network traffic
Correct answer: Tag cardholder data environment (CDE) assets and use entity mapping in Sentinel
Tagging CDE assets and leveraging Sentinel's entity mapping allows analysts to quickly identify incidents involving PCI DSS in-scope systems.
Question 4: Which NIST Cybersecurity Framework function focuses on developing organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities?
- Protect
- Identify (Correct answer)
- Detect
- Respond
Correct answer: Identify
The Identify function of NIST CSF focuses on developing organizational understanding of cybersecurity risks across systems, assets, data, and capabilities.
Question 5: A SOC team must ensure log retention meets both HIPAA and SOX requirements. When these requirements conflict, what approach should the team take?
- Apply the HIPAA retention period as it is healthcare-focused
- Apply the SOX retention period as it is financially focused
- Apply the longer retention period to satisfy both frameworks (Correct answer)
- Apply the shorter period to reduce storage costs
Correct answer: Apply the longer retention period to satisfy both frameworks
When multiple compliance frameworks apply, organizations should retain logs for the longest required period to satisfy all applicable regulations simultaneously.
Question 6: Microsoft Defender for Cloud assigns a Secure Score to an Azure subscription. What does a higher Secure Score indicate?
- More security recommendations have been generated
- A greater percentage of security recommendations have been implemented (Correct answer)
- The subscription has fewer resources
- The subscription has been audited recently
Correct answer: A greater percentage of security recommendations have been implemented
A higher Secure Score in Microsoft Defender for Cloud indicates that a greater percentage of security recommendations have been implemented, reducing overall risk.
Question 7: An organization must comply with ISO 27001. Which control domain specifically addresses the management of information security incidents?
- A.12 - Operations Security
- A.16 - Information Security Incident Management (Correct answer)
- A.17 - Business Continuity Management
- A.14 - System Acquisition, Development and Maintenance
Correct answer: A.16 - Information Security Incident Management
ISO 27001 Annex A.16 specifically covers Information Security Incident Management, including reporting, assessment, and response to incidents.
A security analyst needs to demonstrate that the organization's Azure environment meets HIPAA requirements.
Which Microsoft Purview feature provides a consolidated view of compliance posture against HIPAA controls?