Regulatory Frameworks & Compliance Flashcards
7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
Under the ISO 27001 standard, your development team must manage cryptographic keys with defined rotation schedules. Which Azure service provides automated key rotation with audit trails?
Answer: Azure Key Vault with rotation policy
Azure Key Vault supports automated key rotation policies that rotate keys on a configurable schedule with full audit logging.
A financial app must meet FFIEC guidelines requiring multi-factor authentication for privileged access to Azure resources. Which Azure AD feature should the developer configure?
Answer: Conditional Access with MFA policy
Conditional Access policies can require MFA for privileged users or specific applications, satisfying FFIEC MFA requirements.
You store credit card data in Azure SQL Database and need to comply with PCI DSS Requirement 3.5 to protect stored cardholder data. Which feature encrypts specific columns without application changes?
Answer: Always Encrypted with deterministic encryption
Always Encrypted encrypts sensitive columns at rest and in transit; only client-side drivers with the column master key can decrypt the data.
Your GDPR-compliant app must honor data subject deletion requests ('right to erasure'). Blob data is replicated via geo-redundant storage. What must the developer also do after deleting the primary blobs?
Answer: Ensure deletion propagates to paired region via replication SLA
GRS asynchronously replicates deletions to the paired region; the developer must account for replication lag when confirming erasure.
An AZ-204 developer must prevent secrets from being committed to source control as part of a DevSecOps pipeline. Which Azure DevOps feature scans for credential leaks?
Answer: Microsoft Security DevOps (MSDO) with credential scanner
Microsoft Security DevOps includes the CredScan tool that detects hardcoded credentials in source code during CI/CD pipelines.
Your app processes children's data in the US. Which regulation requires verifiable parental consent before collecting data from users under 13?
Answer: COPPA
COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent before collecting personal information from children under 13.
A developer must ensure that Azure App Service running a regulated workload cannot deploy code unless it has passed a security scan. Which DevOps control enforces this gate?
Answer: Release pipeline approval gates with security scan task
Release pipeline approval gates with a security scan task block deployment promotion until scan results meet defined quality criteria.