SC-200 Compliance & Regulatory Frameworks 3 — Questions and Answers
Question 1: A security analyst is using Microsoft Purview Compliance Manager. What does the 'improvement actions' section provide?
- A list of active security incidents requiring remediation
- Step-by-step guidance for implementing controls to improve compliance scores (Correct answer)
- Automated scripts that fix compliance gaps automatically
- A report of all failed Azure Policy assignments
Correct answer: Step-by-step guidance for implementing controls to improve compliance scores
Improvement actions in Compliance Manager provide detailed, step-by-step guidance for implementing specific controls that will increase the organization's compliance score.
Question 2: Under the CCPA (California Consumer Privacy Act), which right allows California residents to request deletion of their personal information held by a business?
- Right to Know
- Right to Opt-Out
- Right to Delete (Correct answer)
- Right to Non-Discrimination
Correct answer: Right to Delete
The Right to Delete under CCPA allows California residents to request that businesses delete personal information collected about them, subject to certain exceptions.
Question 3: An analyst needs to search for sensitive data across Microsoft 365 services to meet GDPR data mapping requirements. Which tool should be used?
- Microsoft Sentinel UEBA
- Microsoft Purview Content Search (Correct answer)
- Microsoft Defender for Endpoint Advanced Hunting
- Azure Security Center data classification
Correct answer: Microsoft Purview Content Search
Microsoft Purview Content Search allows analysts to search across Exchange, SharePoint, OneDrive, and Teams to locate sensitive data for GDPR data mapping purposes.
Question 4: FedRAMP authorization requires that cloud services used by US federal agencies meet which baseline security controls framework?
- NIST SP 800-53 (Correct answer)
- ISO 27001
- PCI DSS
- CIS Controls
Correct answer: NIST SP 800-53
FedRAMP is based on NIST SP 800-53 security controls, requiring cloud providers to implement and document these controls at Low, Moderate, or High impact levels.
Question 5: A SOC analyst receives a Microsoft Defender for Cloud alert about a resource that violates a regulatory compliance control. What is the recommended first step?
- Immediately disable the non-compliant resource
- Review the compliance recommendation details and assess the risk before remediating (Correct answer)
- Escalate directly to executive leadership
- Open a ticket with Microsoft Support
Correct answer: Review the compliance recommendation details and assess the risk before remediating
The recommended first step is to review the compliance recommendation details in Defender for Cloud to understand the violation and assess risk before taking remediation action.
Question 6: Which Microsoft Sentinel built-in feature allows SOC teams to map their detection coverage to the MITRE ATT&CK framework?
- Sentinel Workbooks
- Fusion ML detections
- MITRE ATT&CK coverage blade in Sentinel (Correct answer)
- Threat Intelligence import
Correct answer: MITRE ATT&CK coverage blade in Sentinel
Microsoft Sentinel includes a dedicated MITRE ATT&CK blade that visually maps active analytics rules and detections to ATT&CK tactics and techniques.
Question 7: PCI DSS Requirement 10 mandates which security control to protect cardholder data?
- Encrypt transmission of cardholder data across open networks
- Track and monitor all access to network resources and cardholder data (Correct answer)
- Use and regularly update anti-virus software
- Restrict access to cardholder data by business need to know
Correct answer: Track and monitor all access to network resources and cardholder data
PCI DSS Requirement 10 specifically mandates tracking and monitoring all access to network resources and cardholder data through comprehensive logging and log review.
A security analyst is using Microsoft Purview Compliance Manager.
What does the 'improvement actions' section provide?