Unit3 - Subjective Questions

INT327 • Practice Questions with Detailed Answers

1

Explain the fundamental concept of cloud compliance and its critical importance in today's cloud-first environments.

2

Describe the "Shared Responsibility Model" in cloud computing. How does it delineate compliance obligations between a cloud service provider (CSP) and a customer?

3

Outline the primary objectives and key principles of India's Digital Personal Data Protection Act (DPDP Act).

4

Discuss the rights granted to "Data Principals" under the DPDP Act. How do these rights empower individuals regarding their personal data?

5

Explain the obligations of a "Data Fiduciary" under the DPDP Act, particularly concerning data processing and security safeguards.

6

What is HIPAA, and which entities are considered "Covered Entities" under this act? Explain its primary purpose.

7

Describe the key components of the HIPAA Security Rule and how it impacts cloud storage and processing of Protected Health Information (PHI).

8

Enumerate and explain at least five key principles of the General Data Protection Regulation (GDPR).

9

Differentiate between a "Data Controller" and a "Data Processor" under GDPR, providing examples of their respective responsibilities in a cloud context.

10

Discuss the territorial scope of GDPR. How can a cloud service provider based outside the EU still be subject to GDPR compliance?

11

Explain the "Right to be Forgotten" (Erasure) and the "Right to Data Portability" as enshrined in GDPR.

12

Describe Microsoft's overarching approach to compliance for its cloud services. How does it assist customers in meeting their regulatory obligations?

13

Explain the role of Microsoft Trust Center and Compliance Manager in helping organizations understand and manage their compliance posture in Azure.

14

What is Azure Policy? Explain its core purpose and how it helps enforce organizational standards and assess compliance at scale.

15

Describe the key components of Azure Policy, including Policy Definitions, Initiatives (Policy Set Definitions), and Assignments.

16

Provide a practical scenario where Azure Policy would be crucial for enforcing compliance. For example, ensuring all VMs have specific tags or approved SKUs.

17

Introduce Microsoft Purview. What are its primary capabilities, and how does it contribute to unified data governance and compliance management?

18

Explain how Microsoft Purview aids in compliance automation. Provide specific examples of features that support this.

19

Discuss the audit reporting capabilities within Microsoft Purview. How can organizations leverage these features to demonstrate compliance to auditors?

20

Define Cloud Compliance in simple terms and explain why it's a shared responsibility.

21

Briefly explain the concept of "Data Residency" and its relevance to Cloud Compliance, particularly in the context of GDPR and DPDP Act.

22

What are the potential consequences of non-compliance with regulations like GDPR or HIPAA for an organization using cloud services?

23

Discuss how the principles of "Privacy by Design" and "Privacy by Default" are incorporated into cloud compliance frameworks and Microsoft's approach.

24

How does Azure Policy integrate with other Azure services to provide a holistic compliance solution? Give specific examples.

25

What is the difference between an "audit" effect and a "deny" effect in Azure Policy? When would you choose one over the other?

26

Describe the main components and functionality of Microsoft Purview's Data Loss Prevention (DLP) capabilities.

27

Explain the role of "Data Protection Impact Assessments (DPIAs)" under GDPR and how cloud providers can support customers in conducting them.

28

Compare and contrast the primary roles of Azure Policy and Microsoft Purview in an organization's cloud compliance strategy. When would you use one over the other, or both?