SC-400 Compliance Management & Risk Assessment 4 — Questions and Answers
Question 1: An organization wants to quantify the potential financial impact of a data breach to prioritize remediation. Which approach aligns with risk assessment best practices for SC-400?
- Use only qualitative risk ratings (high/medium/low)
- Combine asset sensitivity classification with likelihood and impact scoring (Correct answer)
- Run Microsoft Secure Score and use it as the financial risk figure
- Rely solely on Compliance Manager scores for financial impact
Correct answer: Combine asset sensitivity classification with likelihood and impact scoring
Effective data risk assessment combines sensitivity classification with likelihood and impact scoring to quantify potential financial exposure.
Question 2: A compliance team member is reviewing communication compliance alerts and finds a message flagged for regulatory violation. What is the recommended first action?
- Immediately escalate to HR and legal
- Review the message in context within the communication compliance portal (Correct answer)
- Delete the message to prevent further risk
- Notify the sender that they are under investigation
Correct answer: Review the message in context within the communication compliance portal
Reviewers should first examine the flagged message in context within the communication compliance portal before escalating or taking action.
Question 3: Your legal team needs to place a hold on all emails from a specific employee under investigation while allowing normal mail flow. Which feature accomplishes this?
- A retention policy scoped to the user's mailbox
- An eDiscovery hold placed on the custodian's mailbox (Correct answer)
- A DLP policy blocking email deletion for that user
- A litigation hold enabled on the mailbox
Correct answer: An eDiscovery hold placed on the custodian's mailbox
An eDiscovery hold on a custodian preserves all content in scope for legal review without affecting normal mail flow.
Question 4: When assessing third-party vendor risk for data protection under SC-400 principles, which Microsoft feature helps evaluate whether vendors meet compliance standards?
- Microsoft Compliance Manager third-party assessment templates (Correct answer)
- Azure Marketplace vendor certification badges
- Microsoft 365 Message Encryption for vendor communications
- Microsoft Purview Data Map for vendor data sources
Correct answer: Microsoft Compliance Manager third-party assessment templates
Compliance Manager includes templates and assessment frameworks that can be used to evaluate third-party vendors against compliance standards.
Question 5: A healthcare organization must comply with HIPAA and wants automated evidence collection for their Compliance Manager assessment. Which feature provides this?
- Manual evidence upload only
- Automated testing through Microsoft Secure Score integration (Correct answer)
- Azure Sentinel alert correlation
- Microsoft Defender for Endpoint compliance reports
Correct answer: Automated testing through Microsoft Secure Score integration
Compliance Manager integrates with Microsoft Secure Score to automatically test and gather evidence for certain improvement actions.
Question 6: An administrator needs to ensure that compliance assessments reflect configurations in Azure as well as Microsoft 365. What must be enabled?
- Azure Arc for hybrid compliance monitoring
- Azure Policy integration with Compliance Manager
- Microsoft Defender for Cloud connected to Compliance Manager (Correct answer)
- Azure Security Center compliance dashboard
Correct answer: Microsoft Defender for Cloud connected to Compliance Manager
Microsoft Defender for Cloud can be connected to Compliance Manager to extend compliance assessments to Azure resources.
Question 7: Which action in Compliance Manager allows an organization to document that a recommended action is handled through an alternative control not listed?
- Mark the action as 'Not in scope'
- Mark the action as 'Resolved through alternate implementation'
- Delete the improvement action from the assessment
- Set the implementation status to 'Third party' (Correct answer)
Correct answer: Set the implementation status to 'Third party'
Setting the implementation status to 'Third party' in Compliance Manager indicates that an alternative or compensating control handles the requirement.
An organization wants to quantify the potential financial impact of a data breach to prioritize remediation.
Which approach aligns with risk assessment best practices for SC-400?