Courseiva
Describe Azure management and governanceeasyMultiple ChoiceObjective-mapped

AZ-900 Describe Azure management and governance Practice Question

What does 'compliance' mean in the context of Azure?

⚠ Common exam trap

Test-takers frequently confuse 'compliance' with general operational reliability or service restrictions, overlooking that it specifically involves meeting external legal and regulatory mandates rather than internal performance or approval criteria.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Meeting regulatory standards, laws, and organizational policies for data and security

In Azure, compliance refers to adhering to regulatory standards, laws, and organizational policies that govern data security, privacy, and handling. Azure provides a compliance framework with over 100 offerings (e.g., ISO 27001, SOC 2, GDPR, HIPAA) and tools like Microsoft Purview Compliance Manager to assess and manage compliance posture. This ensures that workloads meet specific legal and industry requirements, not just performance or error-free operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Achieving maximum performance for Azure workloads

    Why it's wrong here

    Achieving maximum performance for Azure workloads is an operational and architectural goal focused on throughput, latency, and scalability, typically measured via Azure Monitor and Application Insights. Compliance, by contrast, is a regulatory and audit requirement independent of speed or efficiency; a workload can be extremely fast while still failing data-handling mandates such as GDPR data minimization or residency rules. Maximizing performance may even trade against compliance controls, such as disabling encryption or logging to reduce overhead, so it is not the definition of compliance.

  • Meeting regulatory standards, laws, and organizational policies for data and security

    Why this is correct

    In Azure, compliance is the state of adhering to binding regulatory standards, statutory laws, and internal organizational policies that govern data handling, access, and security. Azure provides certifications and attestations such as GDPR, HIPAA, ISO/IEC 27001, and FedRAMP, with services like Azure Policy and Microsoft Purview to enforce and evidence that adherence. This broad definition covers both legal obligations and enterprise governance criteria, which is why it precisely matches the meaning of compliance.

  • Ensuring all Azure resources are running without errors

    Why it's wrong here

    Ensuring all Azure resources are running without errors describes operational health monitoring and availability management, using tools like Azure Monitor and Service Health to detect faults and maintain uptime. Compliance is a distinct discipline centered on meeting external legal and regulatory standards; a resource might be healthy and error-free yet non-compliant because it stores sensitive data in an unapproved region or lacks required audit logs. Conversely, a compliant environment can still experience transient errors, so this option confuses operational reliability with regulatory adherence.

  • Using only Microsoft-approved Azure services in your environment

    Why it's wrong here

    Using only Microsoft-approved Azure services in your environment is about restricting service adoption, but compliance is not a matter of service selection or vendor endorsement. Regulatory frameworks like ISO 27001 or HIPAA do not certify individual Azure services; rather, compliance depends on how any service is configured, what data it processes, and where that data resides. Microsoft offers many compliant services, but choosing only 'approved' ones does not automatically satisfy regulations, and non-Microsoft or third-party tools can be part of a compliant architecture if properly governed.

About these practice questions

One of 981 original AZ-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-900 exam.