SC-200 Governance & Compliance 2 — Questions and Answers
Question 1: In Microsoft Sentinel, which feature allows you to track compliance with regulatory frameworks such as NIST and ISO 27001?
- Workbooks with compliance templates
- Microsoft Defender for Cloud regulatory compliance dashboard (Correct answer)
- Sentinel Analytics rules mapped to MITRE ATT&CK
- Azure Policy compliance reports
Correct answer: Microsoft Defender for Cloud regulatory compliance dashboard
Microsoft Defender for Cloud provides a regulatory compliance dashboard that maps your resources against standards like NIST SP 800-53 and ISO 27001.
Question 2: A security analyst needs to ensure that audit logs are retained for 90 days in Microsoft Sentinel. Which workspace setting controls log retention?
- Data collection rules
- Log Analytics workspace retention settings (Correct answer)
- Microsoft Sentinel content hub configuration
- Azure Monitor diagnostic settings
Correct answer: Log Analytics workspace retention settings
Log retention in Microsoft Sentinel is controlled by the underlying Log Analytics workspace retention settings, configurable from 30 to 730 days.
Question 3: Which Microsoft Sentinel feature enables you to assign, track, and close security findings to meet audit and compliance requirements?
- Playbooks
- Incidents (Correct answer)
- Notebooks
- Watchlists
Correct answer: Incidents
Sentinel Incidents serve as the primary mechanism for tracking security findings, assigning owners, and documenting resolution for audit purposes.
Question 4: An organization must ensure no user can disable audit logging in Azure. Which governance control enforces this?
- Azure Blueprints
- Azure Policy with Deny effect (Correct answer)
- Microsoft Defender for Cloud recommendation
- Conditional Access policy
Correct answer: Azure Policy with Deny effect
An Azure Policy with a Deny effect can block actions that would disable diagnostic settings or audit logging, enforcing continuous compliance.
Question 5: Under GDPR requirements, a security operations team discovers a data breach. What is the maximum notification window to the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 6: A SOC team wants to use Microsoft Sentinel to generate evidence of compliance for a PCI DSS audit. Which artifact is most useful?
- Threat intelligence indicators
- Workbook reports showing log coverage and alert activity (Correct answer)
- UEBA anomaly scores
- Hunting query results
Correct answer: Workbook reports showing log coverage and alert activity
Workbook reports in Sentinel can visualize log coverage, alert trends, and incident statistics, providing auditors with evidence of monitoring controls.
Question 7: Which Microsoft Purview feature helps classify sensitive data that may be subject to compliance regulations within Microsoft 365?
- Sensitivity labels (Correct answer)
- Retention policies
- Communication compliance
- Insider risk management
Correct answer: Sensitivity labels
Microsoft Purview sensitivity labels classify and protect data based on its sensitivity level, enabling enforcement of compliance policies for regulated data.
In Microsoft Sentinel, which feature allows you to track compliance with regulatory frameworks such as NIST and ISO 27001?