โ† All AZ-204 Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real AZ-204 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. An AZ-204 developer implements Azure Event Hubs to ingest financial transaction data. SOX compliance requires that audit logs cannot be altered. Which Event Hubs feature enforces log immutability?

    Answer: Azure Storage immutable blob policies linked to Capture output

    Combining Event Hubs Capture with immutable blob storage policies (WORM) ensures captured audit logs cannot be altered or deleted for SOX compliance.

  2. Your app must comply with PCI DSS Requirement 6.3 which mandates identifying and ranking security vulnerabilities. Which Azure developer tool provides vulnerability assessment for container images in Azure Container Registry?

    Answer: Microsoft Defender for Container Registry vulnerability scanning

    Microsoft Defender for Container Registry scans images for known CVEs and ranks vulnerabilities, directly satisfying PCI DSS Requirement 6.3.

  3. A developer must implement separation of duties for Azure Key Vault. Operators can manage keys but cannot read secret values. Which access model achieves this in Key Vault?

    Answer: Use Key Vault access policies with separate key and secret permissions

    Key Vault access policies allow granting key management permissions (create, rotate) separately from secret read permissions, enforcing separation of duties.

  4. Your organization undergoes a SOC 2 Type II audit. The auditor asks for evidence of continuous monitoring of Azure infrastructure changes over 12 months. Which service should you export logs from?

    Answer: Azure Activity Log archived to a Storage Account

    Azure Activity Log captures all control-plane changes and can be continuously exported to a Storage Account for 12+ month SOC 2 Type II audit evidence.

  5. A developer builds a multi-tenant SaaS app and must isolate each tenant's encryption keys to meet contractual compliance. Which Key Vault deployment model supports this?

    Answer: Separate Key Vault per tenant with tenant-managed customer keys

    Separate Key Vaults per tenant with customer-managed keys (BYOK) provide complete cryptographic isolation satisfying multi-tenant compliance contracts.

  6. Under GDPR, your application must be able to demonstrate that a user gave explicit consent for data processing. Where should consent records be stored to ensure tamper evidence?

    Answer: In Azure Blob Storage with immutable WORM policies and audit logging

    Immutable WORM blob storage ensures consent records cannot be altered after creation, providing tamper-evident compliance evidence under GDPR.

  7. An enterprise deploys Azure resources across 40 subscriptions and must enforce a compliance baseline (e.g., require TDE on all SQL databases). Which Azure feature applies policies at scale across all subscriptions?

    Answer: Azure Management Groups with Azure Policy initiative

    Management Groups allow Azure Policy initiatives (sets of policies) to be assigned at the root or intermediate group level, applying compliance baselines across all child subscriptions.