AZ-301 Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: A US federal agency is deploying workloads to Azure and requires FedRAMP High authorization. Which Azure environment is specifically designed to meet this requirement?
- Azure Government (Correct answer)
- Azure Public with FedRAMP policy applied
- Azure Stack Hub
- Azure China
Correct answer: Azure Government
Azure Government is a physically isolated cloud specifically designed and authorized for US federal government workloads at FedRAMP High impact level.
Question 2: Under the NIST Cybersecurity Framework, your organization needs to implement controls in the 'Identify' function. Which Azure service best helps you discover and classify sensitive data assets?
- Azure Defender for Cloud
- Microsoft Purview Data Map (Correct answer)
- Azure Monitor
- Azure Service Health
Correct answer: Microsoft Purview Data Map
Microsoft Purview Data Map scans and classifies data assets across your Azure environment, supporting the NIST CSF 'Identify' function's asset management requirements.
Question 3: A healthcare organization needs to implement the minimum necessary standard under HIPAA. Which Azure feature enforces least-privilege access to PHI stored in Azure Storage?
- Azure Storage encryption at rest
- Azure RBAC with custom roles scoped to specific containers (Correct answer)
- Azure Storage firewalls
- Azure Backup policies
Correct answer: Azure RBAC with custom roles scoped to specific containers
HIPAA's minimum necessary standard is implemented through Azure RBAC custom roles that grant only the specific permissions required for each user's job function.
Question 4: Your organization must retain financial records for 7 years to comply with SEC regulations. Which Azure feature prevents deletion or modification of records during the retention period?
- Azure Backup with long-term retention
- Azure Blob Storage immutable storage with time-based retention policies (Correct answer)
- Azure Archive Storage tier
- Azure Site Recovery
Correct answer: Azure Blob Storage immutable storage with time-based retention policies
Azure Blob immutable storage with WORM (Write Once, Read Many) time-based retention policies prevents records from being deleted or modified for SEC-required retention periods.
Question 5: Which compliance framework specifically addresses the security of payment card data and requires quarterly network scans by an Approved Scanning Vendor (ASV)?
- SOC 2 Type II
- HIPAA Security Rule
- PCI DSS (Correct answer)
- ISO 27001
Correct answer: PCI DSS
PCI DSS requires quarterly external vulnerability scans performed by an ASV as part of its ongoing security requirements for cardholder data environments.
Question 6: A company wants to demonstrate continuous compliance rather than point-in-time audits. Which Azure feature provides a real-time compliance score across multiple regulatory frameworks?
- Azure Advisor recommendations score
- Microsoft Compliance Manager compliance score (Correct answer)
- Azure Security Center secure score
- Azure Policy compliance dashboard
Correct answer: Microsoft Compliance Manager compliance score
Microsoft Compliance Manager provides a continuous compliance score that reflects your organization's current posture across multiple regulatory frameworks in real time.
Question 7: Under GDPR Article 35, when is a Data Protection Impact Assessment (DPIA) required before processing personal data in Azure?
- For all cloud workloads processing any personal data
- When processing is likely to result in high risk to individuals' rights and freedoms (Correct answer)
- Only for processing of EU citizens' health data
- When data is transferred outside the organization's country
Correct answer: When processing is likely to result in high risk to individuals' rights and freedoms
GDPR Article 35 requires a DPIA when processing is likely to result in high risk to the rights and freedoms of natural persons, particularly for systematic profiling or sensitive data.
A US federal agency is deploying workloads to Azure and requires FedRAMP High authorization.
Which Azure environment is specifically designed to meet this requirement?