Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium
A global company needs to ensure that all data stored in Azure meets the regulatory requirements for GDPR in Europe, HIPAA in healthcare, and ISO 27001 for information security. They need a dashboard to track their compliance posture against these standards and receive actionable insights to improve it. Which Azure service should they use?
- AAzure Monitor
- BMicrosoft Purview Compliance Manager
- CAzure Policy
- DAzure Security Center (Defender for Cloud)
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Purview Compliance Manager
Microsoft Purview Compliance Manager is a feature in the Microsoft Purview compliance portal that helps manage your organization's compliance posture. It provides a dashboard to track progress, offers actionable recommendations, and simplifies the process of meeting regulatory requirements like GDPR, HIPAA, and ISO 27001.
Why the other options are wrong
- A. Azure Monitor collects and analyzes telemetry data, primarily for performance and availability, not for regulatory compliance management.
- C. Azure Policy helps enforce organizational standards and assess compliance, but doesn't provide a centralized dashboard for multiple regulatory standards like Compliance Manager.
- D. Azure Security Center (now Defender for Cloud) focuses on security posture management and threat protection, not broad regulatory compliance tracking.
Microsoft Purview Compliance Manager
A feature in the Microsoft Purview compliance portal that helps you manage your organization's compliance posture.
- Provides a dashboard to track compliance against regulatory standards.
- Offers actionable recommendations to improve compliance.
- Simplifies the process of meeting complex regulatory requirements like GDPR, HIPAA, and ISO 27001.
Memory trick: Purview: See, Score, Secure, Simplify Compliance.