exam questions

Exam SC-100 All Questions

View all questions & answers for the SC-100 exam

Exam SC-100 topic 7 question 4 discussion

Actual exam question from Microsoft's SC-100
Question #: 4
Topic #: 8
[All SC-100 Questions]

HOTSPOT -
You need to recommend a solution to meet the compliance requirements.
What should you include in the recommendation? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
krzys0
Highly Voted 2 years, 7 months ago
for second one it sould be update assignement: https://learn.microsoft.com/en-us/azure/governance/policy/tutorials/create-and-manage#update-assignment-with-exclusion
upvoted 47 times
...
TheMCT
Highly Voted 2 years, 7 months ago
The question is about what you can use to enforce compliance to regulatory standards not to remediate non-compliance - A Blueprint is Correct. Azure Blueprints are used to enforce standards.
upvoted 24 times
Aunehwet79
2 years, 3 months ago
I see your point - Tricky wording
upvoted 3 times
...
Toschu
2 years ago
Not correct in my opinion: "Fabrikam wants to automatically remediate the virtual machines in Sub1 to be compliant with the HIPAA HITRUST standard." MS says: Remediation is accomplished through remediation tasks that deploy the deployIfNotExists template or the modify operations of the assigned policy Defender Workflow Automation is described as follows: This feature can trigger consumption Logic Apps on security alerts, recommendations, and changes to regulatory compliance. https://learn.microsoft.com/en-us/azure/defender-for-cloud/workflow-automation From my point of view, Workflow Automation offers the best set of possibilities to enforce compliance. Also: Blueprint is still in PREVIEW and will be replaced in the future.
upvoted 1 times
...
...
TomRoute66
Most Recent 6 months, 2 weeks ago
The answer is right.
upvoted 1 times
...
Jonny_Cage
1 year, 2 months ago
For connectivity from App Service web apps to virtual machines, use: Private endpoints: This provides a private IP address for the App Service web app within the virtual network, enabling secure connectivity to virtual machines. For connectivity from virtual machines to App Service web apps, use: Service endpoints: This secures your Azure service resources to only your virtual network by extending your virtual network private address space and the identity of your VNet to the Azure services over a direct connection.
upvoted 1 times
...
slobav
1 year, 6 months ago
Box1: A blueprint Box2: Update an Azure policy assignment https://www.youtube.com/watch?v=r-P-2lGzPFQ&list=PLQ2ktTy9rklhzzkSEZvDZT4QSIVUQZD-Y&index=9 Question 111
upvoted 7 times
...
KrissB
1 year, 7 months ago
Seems like the following answers fit given https://learn.microsoft.com/en-us/azure/governance/policy/samples/hipaa-hitrust-9-2: 1 - Blueprint 2 - Update Azure Policy
upvoted 3 times
...
hydrillo
1 year, 10 months ago
First you need a managed identity to enforce policies with remediation tasks. 2nd Question: You need to modify the assignment not the definition.
upvoted 3 times
...
zellck
1 year, 11 months ago
1. Blueprint 2. Update an Azure policy assignment https://learn.microsoft.com/en-us/azure/governance/blueprints/overview#blueprint-definition Policy Assignment - Allows assignment of a policy or initiative to the subscription the blueprint is assigned to. The policy or initiative must be within the scope of the blueprint definition location. If the policy or initiative has parameters, these parameters are assigned at creation of the blueprint or during blueprint assignment.
upvoted 6 times
zellck
1 year, 10 months ago
Gotten this in May 2023 exam.
upvoted 5 times
...
...
Ssasid
2 years, 2 months ago
https://learn.microsoft.com/en-us/azure/governance/policy/concepts/exemption-structure#policy-assignment-id The Azure Policy exemptions feature is used to exempt a resource hierarchy or an individual resource from evaluation of initiatives or definitions. Excluded scopes The scope of the assignment includes all child resource containers and child resources. If a child resource container or child resource shouldn't have the definition applied, each can be excluded from evaluation by setting notScopes. This property is an array to enable excluding one or more resource containers or resources from evaluation. notScopes can be added or updated after creation of the initial assignment. So second one should be "update assignement"
upvoted 1 times
...
GoGetIt786786
2 years, 2 months ago
"Workflow Automation" for enforcing regulatory standard, it uses Logic App which can enforce compliance to the standard by reverting back a change. Second one should be update a policy assignment.
upvoted 3 times
...
ksksilva2022
2 years, 5 months ago
Answer is "Managed Identity" to enforce compliance to existing environment resources Other one is "Update a policy assignment" Tricky question but we need to know policies are already in place in their environment according to given background.
upvoted 12 times
...
bottom_feeder
2 years, 7 months ago
I think "Update a policy assignment" is the correct answer for second question. There is no exemption component in policy definition - https://docs.microsoft.com/en-us/azure/governance/policy/concepts/definition-structure, while it is in policy assignment - https://docs.microsoft.com/en-us/azure/governance/policy/concepts/assignment-structure
upvoted 12 times
...
SkippyTheMagnificent
2 years, 7 months ago
I believe “To enforce compliance…” is “A managed identity”, based on the info at this link: https://docs.microsoft.com/en-us/azure/governance/policy/how-to/remediate-resources The second answer looks correct to me.
upvoted 14 times
blopfr
2 years, 5 months ago
good catch, there will be an initiative assigne with remediation tasks and apply if not exist that can run on MI, the blueprint will only assign the policy or initiative, not really enforce it
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago