Microsoft Azure Fundamentals (AZ-900)Describe Azure management and governanceMedium

A global company needs to ensure that all data stored in Azure meets the regulatory requirements for GDPR in Europe, HIPAA in healthcare, and ISO 27001 for information security. They need a dashboard to track their compliance posture against these standards and receive actionable insights to improve it. Which Azure service should they use?

  1. AAzure Monitor
  2. BMicrosoft Purview Compliance Manager
  3. CAzure Policy
  4. DAzure Security Center (Defender for Cloud)
Show answer & explanation

Correct answer: B. Microsoft Purview Compliance Manager

Microsoft Purview Compliance Manager is a feature in the Microsoft Purview compliance portal that helps manage your organization's compliance posture. It provides a dashboard to track progress, offers actionable recommendations, and simplifies the process of meeting regulatory requirements like GDPR, HIPAA, and ISO 27001.

Why the other options are wrong

  • A. Azure Monitor collects and analyzes telemetry data, primarily for performance and availability, not for regulatory compliance management.
  • C. Azure Policy helps enforce organizational standards and assess compliance, but doesn't provide a centralized dashboard for multiple regulatory standards like Compliance Manager.
  • D. Azure Security Center (now Defender for Cloud) focuses on security posture management and threat protection, not broad regulatory compliance tracking.

Microsoft Purview Compliance Manager

A feature in the Microsoft Purview compliance portal that helps you manage your organization's compliance posture.

  • Provides a dashboard to track compliance against regulatory standards.
  • Offers actionable recommendations to improve compliance.
  • Simplifies the process of meeting complex regulatory requirements like GDPR, HIPAA, and ISO 27001.

Memory trick: Purview: See, Score, Secure, Simplify Compliance.

More Describe Azure management and governance questions