Courseiva

SC-900 Practice Question: Describe the concepts of security, compliance, and identity

A healthcare organization must comply with HIPAA regulations regarding the protection of patient health information (PHI). Which cloud compliance concept ensures that the organization has controls in place to meet regulatory requirements?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Compliance management

Compliance management is the discipline of ensuring that an organization adheres to regulations like HIPAA by implementing controls. Security management focuses on protecting assets from threats. Identity management deals with authentication and authorization. Privacy management addresses personal data protection. The question specifically asks about meeting regulatory requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Privacy management

    Why it's wrong here

    Privacy management specifically focuses on the collection, use, disclosure, and retention of personal data, ensuring individuals' rights are protected. While HIPAA has a Privacy Rule, privacy management alone does not encompass the full scope of HIPAA, which also includes the Security Rule, Breach Notification Rule, and Enforcement Rule, requiring a broader approach than just data privacy principles.

  • Identity management

    Why it's wrong here

    Identity management (IdM) systems are critical for controlling access to resources by authenticating users and authorizing their permissions. While IdM is a foundational security control that supports HIPAA's technical safeguards by ensuring only authorized personnel access Protected Health Information (PHI), it is a specific technical domain and not the comprehensive framework for managing an organization's adherence to all HIPAA regulations.

  • Security management

    Why it's wrong here

    Security management encompasses the processes and controls designed to protect information systems and data from unauthorized access, use, disclosure, disruption, modification, or destruction. While the HIPAA Security Rule mandates robust security measures for electronic Protected Health Information (ePHI), security management is an operational discipline focused on threat mitigation and asset protection, rather than the strategic oversight and documentation required to demonstrate adherence to all regulatory mandates.

  • Compliance management

    Why this is correct

    Compliance management is the overarching discipline that ensures an organization adheres to external laws, regulations, and internal policies, such as HIPAA. It involves establishing frameworks, implementing controls, conducting risk assessments, monitoring adherence, and maintaining documentation to systematically meet all regulatory requirements and demonstrate due diligence to auditors and regulators.

About these practice questions

Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.