SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A healthcare organization must comply with HIPAA regulations regarding the protection of patient health information (PHI). Which cloud compliance concept ensures that the organization has controls in place to meet regulatory requirements?
⚠ Common exam trap
SC-900 often tests the distinction between privacy, security, and compliance management — candidates confuse privacy (data subject rights) with compliance (regulatory control mapping) and pick the wrong one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance management
Compliance management is the cloud compliance concept focused on ensuring an organization has the controls, policies, and evidence in place to satisfy regulatory frameworks such as HIPAA. It maps cloud controls to regulatory requirements and provides audit-ready reporting. Privacy management focuses on handling personal data subject rights, while security management addresses technical safeguards rather than regulatory alignment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Privacy management
Why it's wrong here
Privacy management specifically focuses on the collection, use, disclosure, and retention of personal data, ensuring individuals' rights are protected. While HIPAA has a Privacy Rule, privacy management alone does not encompass the full scope of HIPAA, which also includes the Security Rule, Breach Notification Rule, and Enforcement Rule, requiring a broader approach than just data privacy principles.
- ✗
Identity management
Why it's wrong here
Identity management (IdM) systems are critical for controlling access to resources by authenticating users and authorizing their permissions. While IdM is a foundational security control that supports HIPAA's technical safeguards by ensuring only authorized personnel access Protected Health Information (PHI), it is a specific technical domain and not the comprehensive framework for managing an organization's adherence to all HIPAA regulations.
- ✗
Security management
Why it's wrong here
Security management encompasses the processes and controls designed to protect information systems and data from unauthorized access, use, disclosure, disruption, modification, or destruction. While the HIPAA Security Rule mandates robust security measures for electronic Protected Health Information (ePHI), security management is an operational discipline focused on threat mitigation and asset protection, rather than the strategic oversight and documentation required to demonstrate adherence to all regulatory mandates.
- ✓
Compliance management
Why this is correct
Compliance management is the overarching discipline that ensures an organization adheres to external laws, regulations, and internal policies, such as HIPAA. It involves establishing frameworks, implementing controls, conducting risk assessments, monitoring adherence, and maintaining documentation to systematically meet all regulatory requirements and demonstrate due diligence to auditors and regulators.
Go deeper
Related to this question
Learn chapter
Microsoft Defender for Cloud
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,279 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.