← All AZ-204 Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Your Azure app stores EU citizen health data. Which Azure service helps you demonstrate GDPR Article 30 record-of-processing compliance?

    Answer: Microsoft Purview Data Map

    Microsoft Purview Data Map catalogs and classifies data assets, supporting GDPR Article 30 records-of-processing requirements.

  2. An AZ-204 developer must ensure Azure Blob Storage objects containing PII are automatically deleted after 7 years per company retention policy. Which feature should be used?

    Answer: Blob lifecycle management rules

    Blob lifecycle management rules can automatically delete blobs based on last-modified date to enforce retention policies.

  3. Your organization must comply with FedRAMP Moderate. Which Azure environment is pre-authorized for FedRAMP Moderate workloads?

    Answer: Azure Government cloud

    Azure Government is specifically designed and pre-authorized for U.S. government workloads requiring FedRAMP compliance.

  4. A developer needs to log all access to Azure Key Vault secrets for a PCI DSS audit. Which diagnostic setting destination provides the longest default retention at lowest cost?

    Answer: Azure Storage Account archive tier

    Storage Account archive tier offers the lowest cost for long-term audit log retention required by PCI DSS.

  5. Under HIPAA, your app must encrypt PHI in transit between a web front-end and Azure SQL Database. Which Azure feature enforces TLS for all SQL connections?

    Answer: SSL/TLS enforce connection policy

    The SQL Database enforce SSL/TLS connection policy rejects unencrypted connections, ensuring PHI is encrypted in transit.

  6. Your SOC 2 audit requires evidence that no unauthorized changes were made to production Azure resources. Which service provides an immutable audit trail of all control-plane operations?

    Answer: Azure Activity Log

    Azure Activity Log records all control-plane operations (create, update, delete) on Azure resources and can be exported for SOC 2 evidence.

  7. A developer must implement data residency for a UK customer — all data must remain in UK South or UK West. Which Azure mechanism enforces this at policy level?

    Answer: Azure Policy with allowed locations definition

    The built-in Azure Policy 'Allowed locations' definition blocks resource deployment to any region outside the approved list.