Compliance, Governance & Data Security Flashcards
7 cards from real SC-100 practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance, Governance & Data Security flashcards as text
A cybersecurity architect must ensure that sensitive documents labeled 'Top Secret' can only be opened by users on compliant, Intune-managed devices. Which combination of technologies achieves this?
Answer: Sensitivity labels with RMS protection + Conditional Access device compliance policy
Sensitivity labels with RMS protection define who can access content, and Conditional Access policies with device compliance requirements restrict access to managed devices.
An insider threat investigation reveals an employee copied 10,000 files to a USB drive. Which Microsoft solution could have detected and blocked this data exfiltration in real time?
Answer: Microsoft Purview Endpoint DLP
Microsoft Purview Endpoint DLP monitors and can block sensitive data from being copied to removable storage devices on Windows endpoints.
A compliance officer needs to prove that a document was unaltered since it was originally saved. Which Microsoft Purview feature locks a labeled record so it cannot be modified or deleted?
Answer: Retention label declared as a regulatory record
Retention labels declared as regulatory records lock the content, preventing modification or deletion for the full retention period.
An organization wants to use Microsoft Defender for Cloud to assess compliance with the Azure CIS Benchmark. What must be done before the assessment appears in the regulatory compliance dashboard?
Answer: Assign the CIS standard in the Defender for Cloud environment settings
The CIS Benchmark (or any regulatory standard) must be explicitly assigned in Defender for Cloud environment settings to appear in the compliance dashboard.
A security architect is designing a solution to detect when employees send emails that contain confidential competitor analysis documents externally. Which Microsoft 365 capability provides this detection with policy-based alerting?
Answer: Microsoft Purview DLP with sensitive information types and email conditions
Microsoft Purview DLP policies can detect sensitive information types in emails and trigger alerts or blocks when sent to external recipients.
An organization must implement data minimization per GDPR principles for customer data in Azure SQL Database. Which approach best supports this architectural requirement?
Answer: Implement dynamic data masking and column-level encryption for non-essential data access
Dynamic data masking restricts non-privileged users from seeing full sensitive data, and column-level encryption limits data exposure, supporting GDPR data minimization principles.
A governance team wants quarterly reviews of all external users who have been granted access to Microsoft Teams and SharePoint. Which Microsoft Entra ID feature automates this review process?
Answer: Microsoft Entra Access Reviews
Microsoft Entra Access Reviews enable scheduled, automated reviews of group memberships and access rights, including external/guest users.