Regulatory Frameworks & Compliance Flashcards
7 cards from real AZ-301 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
A healthcare company must ensure patient data stored in Azure meets HIPAA requirements. Which Azure service provides built-in HIPAA compliance documentation and audit reports?
Answer: Microsoft Service Trust Portal
The Microsoft Service Trust Portal provides HIPAA audit reports, compliance guides, and third-party assessments for regulated industries.
Under GDPR, a user requests deletion of all their personal data stored in your Azure SQL Database. Which approach best supports the 'right to be forgotten' requirement?
Answer: Delete the specific records and purge from backups within the required timeframe
GDPR's right to erasure requires actual deletion of personal data records, including purging from backups within a compliant timeframe.
Your organization is subject to PCI DSS and stores cardholder data in Azure. Which Azure feature helps you restrict access to cardholder data environments based on network segmentation?
Answer: Azure Virtual Network with Network Security Groups
PCI DSS requires network segmentation of the cardholder data environment, which is achieved using Azure VNets with NSGs to control traffic flow.
A financial services firm needs SOC 2 Type II compliance for their Azure-hosted application. Which statement accurately describes Microsoft's responsibility in this shared model?
Answer: Microsoft provides SOC 2 reports for Azure infrastructure that customers can inherit
Microsoft maintains SOC 2 Type II certification for Azure infrastructure, and customers can inherit these controls for their own compliance attestations.
Which Azure feature allows you to create guardrails that prevent resource deployments in non-compliant Azure regions to meet data residency requirements?
Answer: Azure Policy with allowed locations definition
The built-in 'Allowed locations' Azure Policy definition prevents resources from being deployed outside specified geographic regions.
A company must comply with ISO 27001 and wants to map Azure security controls to ISO 27001 requirements. Which tool provides this mapping?
Answer: Microsoft Compliance Manager
Microsoft Compliance Manager provides control mappings between Azure security features and regulatory frameworks including ISO 27001.
Your organization processes EU citizen data and must comply with GDPR's data transfer restrictions. Which mechanism allows lawful transfer of personal data from the EU to the US when using Azure?
Answer: Standard Contractual Clauses (SCCs) included in Microsoft's DPA
Microsoft's Data Processing Agreement includes Standard Contractual Clauses approved by EU authorities, enabling lawful cross-border data transfers.