Microsoft Cybersecurity Architect (SC-100)Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategiesHard

A financial institution is under increasing pressure from regulators to demonstrate continuous compliance with industry-specific regulations (e.g., PCI DSS, SWIFT CSP) and data privacy laws (e.g., GDPR, CCPA). The cybersecurity architect needs to implement a technical strategy that provides real-time visibility into the organization's compliance posture across its hybrid IT environment, automates evidence collection for audits, and proactively identifies non-compliant configurations before they become issues. Which GRC technical strategy is BEST suited to meet these continuous compliance and audit requirements?

  1. AUtilizing an advanced Data Loss Prevention (DLP) solution for sensitive data monitoring.
  2. BDeploying a comprehensive Enterprise GRC Platform with automated compliance mapping and control validation.
  3. CImplementing a federated Security Information and Event Management (SIEM) system for log correlation.
  4. DEstablishing a dedicated Vulnerability Management (VM) program with monthly penetration tests.
Show answer & explanation

Correct answer: B. Deploying a comprehensive Enterprise GRC Platform with automated compliance mapping and control validation.

An Enterprise GRC Platform is specifically designed to manage and automate compliance processes, map controls to regulations, validate their effectiveness continuously, and collect audit evidence across the entire IT estate, providing real-time compliance posture.

Why the other options are wrong

  • A. DLP focuses on preventing data exfiltration, which is a specific security control, but it does not provide the broad GRC capabilities for managing multiple regulations, controls, and audit evidence.
  • C. SIEM is for security event monitoring and incident detection, not for managing the overall GRC framework, continuous control validation, or automated audit evidence collection.
  • D. VM and penetration testing identify vulnerabilities, which is part of security, but it does not provide the overarching framework for continuous compliance management, control validation, and audit evidence collection for multiple regulatory standards.

Enterprise GRC Platform

An Enterprise GRC Platform is a centralized system that helps organizations manage governance, risk, and compliance activities, automate control validation, and provide real-time compliance posture.

  • Maps controls to multiple regulations.
  • Automates evidence collection for audits.
  • Provides real-time visibility into compliance posture.
  • Manages risks and policies centrally.

Memory trick: The 'GRC Platform' is the 'Financial Auditor's Best Friend'.

More Evaluate Governance Risk Compliance (GRC) technical strategies and security operations strategies questions