SC-900 - Microsoft Compliance Solutions - Section 4.1

Describe the Service Trust Portal and Microsoft privacy principles.

Describe the Service Trust Portal as the resource that provides audit reports, compliance documentation, and trust information about Microsoft cloud services. Recognise Microsoft's core privacy principles and how Microsoft Priva helps organisations manage personal data and privacy risks at scale.

Service Trust PortalMicrosoft privacy principlesMicrosoft Priva

Practice question for this objective

Free sampleMicrosoft Compliance Solutionseasy

A compliance analyst is preparing for an audit and wants to use the Service Trust Portal as the public face of Microsoft's trust and compliance information. Which TWO kinds of material does the Service Trust Portal make available to support this work? Select TWO.

  • AIndependent third-party audit reports covering Microsoft cloud services Correct
  • BCompliance documents and whitepapers describing how Microsoft protects customer data Correct
  • CDirect access to Microsoft datacentres so that a customer's own staff can run their own audits
  • DPer-tenant insider risk alerts raised in a customer's environment
  • EEditable improvement actions that raise the tenant compliance score
The Service Trust Portal publishes independent audit reports and Microsoft compliance documents so customers can evaluate cloud service trust and security. The Service Trust Portal is a documents library: it surfaces independent third-party audit reports and Microsoft-written compliance whitepapers, so those two are correct. It never grants hands-on access to Microsoft datacentres, and tenant operations such as insider risk alerts and compliance-score improvement actions live in Microsoft Purview, not the portal, so the rest are wrong.

Why A is correct: The Service Trust Portal publishes external audit reports so customers can review how Microsoft cloud services are independently assessed.

Why B is correct: It hosts Microsoft-authored compliance guides and whitepapers that explain the security and privacy controls behind the services.

Why C is wrong: Tempting because audits are the theme, but the portal supplies audit reports and documentation, never physical or hands-on access to Microsoft datacentres, which customers never receive.

Why D is wrong: Insider risk alerts come from Microsoft Purview Insider Risk Management inside a tenant, not from the public Service Trust Portal.

Why E is wrong: Improvement actions belong to Compliance Manager; the Service Trust Portal is a documents resource, so this conflates two distinct tools.

See more SC-900 practice questions, answers explained.

More in this domain

Back to all Microsoft Compliance Solutions objectives, or the SC-900 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.