Regulatory Frameworks & Compliance Flashcards
7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
Your Azure app stores EU citizen health data. Which Azure service helps you demonstrate GDPR Article 30 record-of-processing compliance?
Answer: Microsoft Purview Data Map
Microsoft Purview Data Map catalogs and classifies data assets, supporting GDPR Article 30 records-of-processing requirements.
An AZ-204 developer must ensure Azure Blob Storage objects containing PII are automatically deleted after 7 years per company retention policy. Which feature should be used?
Answer: Blob lifecycle management rules
Blob lifecycle management rules can automatically delete blobs based on last-modified date to enforce retention policies.
Your organization must comply with FedRAMP Moderate. Which Azure environment is pre-authorized for FedRAMP Moderate workloads?
Answer: Azure Government cloud
Azure Government is specifically designed and pre-authorized for U.S. government workloads requiring FedRAMP compliance.
A developer needs to log all access to Azure Key Vault secrets for a PCI DSS audit. Which diagnostic setting destination provides the longest default retention at lowest cost?
Answer: Azure Storage Account archive tier
Storage Account archive tier offers the lowest cost for long-term audit log retention required by PCI DSS.
Under HIPAA, your app must encrypt PHI in transit between a web front-end and Azure SQL Database. Which Azure feature enforces TLS for all SQL connections?
Answer: SSL/TLS enforce connection policy
The SQL Database enforce SSL/TLS connection policy rejects unencrypted connections, ensuring PHI is encrypted in transit.
Your SOC 2 audit requires evidence that no unauthorized changes were made to production Azure resources. Which service provides an immutable audit trail of all control-plane operations?
Answer: Azure Activity Log
Azure Activity Log records all control-plane operations (create, update, delete) on Azure resources and can be exported for SOC 2 evidence.
A developer must implement data residency for a UK customer — all data must remain in UK South or UK West. Which Azure mechanism enforces this at policy level?
Answer: Azure Policy with allowed locations definition
The built-in Azure Policy 'Allowed locations' definition blocks resource deployment to any region outside the approved list.