A compliance analyst is preparing for an audit and wants to use the Service Trust Portal as the public face of Microsoft's trust and compliance information. Which TWO kinds of material does the Service Trust Portal make available to support this work? Select TWO.
- AIndependent third-party audit reports covering Microsoft cloud services Correct
- BCompliance documents and whitepapers describing how Microsoft protects customer data Correct
- CDirect access to Microsoft datacentres so that a customer's own staff can run their own audits
- DPer-tenant insider risk alerts raised in a customer's environment
- EEditable improvement actions that raise the tenant compliance score
Why A is correct: The Service Trust Portal publishes external audit reports so customers can review how Microsoft cloud services are independently assessed.
Why B is correct: It hosts Microsoft-authored compliance guides and whitepapers that explain the security and privacy controls behind the services.
Why C is wrong: Tempting because audits are the theme, but the portal supplies audit reports and documentation, never physical or hands-on access to Microsoft datacentres, which customers never receive.
Why D is wrong: Insider risk alerts come from Microsoft Purview Insider Risk Management inside a tenant, not from the public Service Trust Portal.
Why E is wrong: Improvement actions belong to Compliance Manager; the Service Trust Portal is a documents resource, so this conflates two distinct tools.