CV0-002 · Question #185
Which of the following is included in a compliance audit?
The correct answer is C. Analyzing identity management and access controls. A compliance audit assesses an organization's adherence to regulatory requirements and internal policies, focusing on how data and systems are secured and managed.
Question
Which of the following is included in a compliance audit?
Options
- AAnalyzing chargeback agreements
- BAnalyzing cloud provider Service Level Agreements (SLAs)
- CAnalyzing identity management and access controls
- DAnalyzing the provider release calendar
How the community answered
(43 responses)- A2% (1)
- B2% (1)
- C86% (37)
- D9% (4)
Why each option
A compliance audit assesses an organization's adherence to regulatory requirements and internal policies, focusing on how data and systems are secured and managed.
Analyzing chargeback agreements is related to financial management and cost allocation, not a direct component of a compliance audit's scope.
Analyzing cloud provider Service Level Agreements (SLAs) primarily relates to service performance and availability guarantees, not the internal compliance of an organization's operations or controls.
Identity management and access controls are critical components of an organization's security posture and regulatory compliance, as they dictate who can access what resources and services. A compliance audit rigorously examines these controls to ensure they meet established standards like GDPR, HIPAA, or SOC 2, preventing unauthorized access and data breaches.
Analyzing the provider release calendar is related to change management and service updates, which is not a core focus of a compliance audit.
Concept tested: Compliance audit scope - identity and access management
Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr-data-access-identity-management
Topics
Community Discussion
No community discussion yet for this question.