SC-400 Compliance Management & Risk Assessment 3 — Questions and Answers
Question 1: Your organization must comply with NIST 800-53. Which Compliance Manager assessment template tier includes NIST 800-53 without an additional license?
- Premium templates require a separate purchase
- Included templates available with Microsoft 365 E3
- Universal templates available with any Microsoft 365 plan
- Included templates available with Microsoft 365 E5 or Compliance add-on (Correct answer)
Correct answer: Included templates available with Microsoft 365 E5 or Compliance add-on
NIST 800-53 is a premium template in Compliance Manager available with Microsoft 365 E5 or the Compliance add-on license.
Question 2: A company operates in both the EU and the US. They need to assess compliance against both GDPR and CCPA. What is the recommended approach in Compliance Manager?
- Create a single combined custom assessment
- Create separate assessments for GDPR and CCPA (Correct answer)
- Use the Microsoft Data Protection Baseline only
- Configure a single assessment with multiple regulations
Correct answer: Create separate assessments for GDPR and CCPA
Creating separate assessments for GDPR and CCPA allows independent tracking of compliance posture and improvement actions for each regulation.
Question 3: In the context of SC-400, what does 'control testing' refer to in Compliance Manager?
- Running automated scripts to verify security configurations
- Documenting evidence and updating the implementation status of controls (Correct answer)
- Performing penetration testing against Microsoft 365 workloads
- Scanning for sensitive data using content search
Correct answer: Documenting evidence and updating the implementation status of controls
Control testing in Compliance Manager means documenting evidence and marking implementation status for each control to reflect real-world compliance.
Question 4: An administrator notices that some improvement actions in Compliance Manager show 'Microsoft managed' status. What does this indicate?
- Microsoft has completed those controls on behalf of the customer (Correct answer)
- The actions require Microsoft support to implement
- Those controls are customer responsibility but Microsoft provides guidance
- Microsoft will automatically remediate those issues
Correct answer: Microsoft has completed those controls on behalf of the customer
Microsoft managed controls are responsibilities that Microsoft fulfills as part of operating the cloud platform, contributing to the shared responsibility model.
Question 5: Which metric in Compliance Manager represents the weighted value of completing improvement actions relative to the total possible points?
- Compliance percentage
- Risk score
- Compliance score (Correct answer)
- Control coverage ratio
Correct answer: Compliance score
The compliance score in Compliance Manager is a percentage based on weighted points earned from completed improvement actions versus total possible points.
Question 6: A user asks why their organization's Microsoft Data Protection Baseline assessment shows 100% even though they haven't configured anything. What is the correct explanation?
- Compliance Manager auto-configures all baseline controls
- The baseline reflects only Microsoft-managed controls which Microsoft has already fulfilled (Correct answer)
- The assessment is pre-populated with default passing scores
- The baseline only measures identity controls which Azure AD handles automatically
Correct answer: The baseline reflects only Microsoft-managed controls which Microsoft has already fulfilled
The Microsoft Data Protection Baseline consists primarily of Microsoft-managed controls that Microsoft fulfills, so the score starts high without customer action.
Question 7: Which SC-400 feature allows you to set alert policies when users perform activities that might indicate compliance risk, such as mass deletion of sensitive files?
- Communication compliance policies
- Alert policies in the Microsoft Purview compliance portal
- Insider risk management policies (Correct answer)
- Sensitivity label auto-classification
Correct answer: Insider risk management policies
Insider risk management policies in Microsoft Purview detect and alert on risky user behaviors including mass deletion of sensitive content.
Your organization must comply with NIST 800-53.
Which Compliance Manager assessment template tier includes NIST 800-53 without an additional license?