Regulatory Frameworks & Compliance Flashcards
7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
You are building an app for a healthcare organization. Under HIPAA, a Business Associate Agreement (BAA) with Microsoft is required. Where do you accept the Azure BAA?
Answer: Through the Microsoft Online Services Terms (OST) acceptance process
Microsoft's BAA is included in the Online Services Terms (OST/DPA); customers accept it by agreeing to the volume licensing agreement terms.
An organization must comply with NIST SP 800-53. A developer wants to understand which Azure services satisfy specific NIST controls. Which Microsoft resource provides this mapping?
Answer: Microsoft Defender for Cloud regulatory compliance dashboard
Defender for Cloud's regulatory compliance dashboard maps Azure control assessments directly to NIST SP 800-53 controls.
Your app must comply with California's CCPA. A user requests a copy of all personal data held about them. Which Azure capability helps you locate that data across storage services?
Answer: Microsoft Purview data discovery and classification
Microsoft Purview scans and classifies personal data across storage services, enabling Data Subject Access Request fulfillment under CCPA.
An AZ-204 candidate must configure Azure Functions to use Managed Identity instead of connection strings for Key Vault access. What is the primary compliance benefit?
Answer: Eliminates static credentials that must be rotated and audited
Managed Identity eliminates long-lived static credentials, reducing the risk of credential leakage and simplifying compliance with rotation requirements.
Your EU-based SaaS product transfers Azure data to a US-based analytics partner. Under GDPR Chapter V, which mechanism legally authorizes this international transfer?
Answer: Standard Contractual Clauses (SCCs) in the data processing agreement
Standard Contractual Clauses are the primary GDPR-approved mechanism for transferring personal data from the EU to third countries.
A developer configures Azure Monitor to alert when a user account makes more than 10 failed login attempts in 5 minutes. This control satisfies which compliance requirement type?
Answer: Intrusion detection / account lockout monitoring requirement
Monitoring failed authentication attempts is a detective control satisfying intrusion detection requirements in frameworks like PCI DSS and NIST.
Which Azure Key Vault object type should be used to store a TLS/SSL certificate for an Azure App Service, enabling automated renewal for compliance with certificate lifecycle policies?
Answer: Key Vault Certificate with auto-renewal policy
Key Vault Certificate objects support integrated CA issuers and auto-renewal policies that satisfy certificate lifecycle compliance requirements.