SC-100 - Design Security Operations, Identity, and Compliance Capabilities (27% of the exam) - Section 2.4

Design solutions for regulatory compliance by translating requirements into security controls.

Translate regulatory and privacy requirements into security controls by mapping them to Microsoft Purview compliance features, Microsoft Priva privacy management, and Azure Policy guardrails. Use Microsoft Defender for Cloud regulatory compliance dashboards to measure and evidence control coverage against industry and government frameworks.

Microsoft PurviewMicrosoft PrivaAzure PolicyMicrosoft Defender for Cloud regulatory compliancecompliance controlsprivacy requirements

Practice question for this objective

Free sampleDesign Security Operations, Identity, and Compliance Capabilitiesmedium

A financial regulator requires the organisation to demonstrate continuous, control-mapped compliance against a named security standard across two estates at once: its Azure and multicloud infrastructure, and its Microsoft 365 collaboration platform, each shown as a scored posture against the standard's controls. The architect must pick the design surfaces that satisfy this assurance for both estates. Which TWO design choices together meet the requirement? Select TWO.

  • AAdd the standard to the Microsoft Defender for Cloud regulatory compliance dashboard so its controls are continuously assessed against the live configuration of the Azure and multicloud infrastructure and scored. Correct
  • BStream the Azure activity log and Microsoft 365 audit log into Microsoft Sentinel and build a workbook that visualises how often each of the standard's controls is breached over time.
  • CBuild a Microsoft Purview Compliance Manager assessment for the standard so its Microsoft 365 controls each carry an owner, test evidence, and a contribution to a tracked compliance score for the collaboration platform. Correct
  • DAssign one Azure Policy initiative containing every control in the standard and treat the resulting policy compliance percentage as the single posture score covering both the infrastructure and the Microsoft 365 estate.
Map a cross-estate regulatory assurance need to Defender for Cloud regulatory compliance for cloud infrastructure plus Purview Compliance Manager for Microsoft 365 controls. No single surface scores both cloud infrastructure configuration and Microsoft 365 governance against a standard, so the design pairs the Microsoft Defender for Cloud regulatory compliance dashboard, which continuously scores live cloud resource configuration, with a Microsoft Purview Compliance Manager assessment, which scores owned, evidence-backed Microsoft 365 controls.

Why A is correct: The Microsoft Defender for Cloud regulatory compliance dashboard maps a standard's controls to continuous assessments of live cloud resource configuration and produces a per-control score, which satisfies the infrastructure half of the regulator's assurance need.

Why B is wrong: Microsoft Sentinel can visualise control breaches in a workbook and is tempting for unified reporting, but a SIEM dashboard counts events rather than maintaining an authoritative control-mapped compliance score for either estate, so it does not deliver the scored posture required.

Why C is correct: A Microsoft Purview Compliance Manager assessment turns the standard's Microsoft 365 controls into owned, evidence-backed improvement actions with a tracked score, which satisfies the collaboration-platform half of the regulator's control-mapped assurance need.

Why D is wrong: An Azure Policy initiative scores Azure resource settings and underpins the dashboard, which makes it a plausible single answer, but it neither assesses Microsoft 365 collaboration controls nor presents the standard's controls as a regulatory posture, so it covers only part of one estate.

See more SC-100 practice questions, answers explained.

Exam traps in Design Security Operations, Identity, and Compliance Capabilities

Answers that look right on this material and are not. Each one is a distractor from a different question in the SC-100 bank for this domain.

  • Track the framework's controls as improvement actions in Microsoft Purview Compliance Manager and attach evidence of each Azure configuration setting for auditors to review.

    Why it is wrong: Compliance Manager tracks control implementation with owners and evidence and is tempting for a bespoke framework, but it relies on attested evidence rather than continuously evaluating live Azure resource configuration as the requirement demands.

  • Onboard the subscriptions to Microsoft Sentinel and build analytics rules that alert when a configuration drifts from the documented PCI DSS and ISO 27001 baseline.

    Why it is wrong: Microsoft Sentinel is tempting because it centralises signals and can alert on drift, but it is a SIEM for threat detection and lacks a maintained control-to-resource mapping that produces an auditor-ready compliance score against named standards.

  • Track the Microsoft Defender for Cloud secure score, which reflects how many security recommendations across the cloud estate have been remediated over time.

    Why it is wrong: The Defender for Cloud secure score measures cloud security posture and is a tempting single metric, but it reflects technical security recommendations for cloud resources rather than implementation of named regulatory controls across Microsoft 365.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.