SC-900 Practice Question: Describe the concepts of security, compliance, and identity
A healthcare organization must comply with HIPAA regulations regarding the protection of patient health information (PHI). Which cloud compliance concept ensures that the organization has controls in place to meet regulatory requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance management
Compliance management is the discipline of ensuring that an organization adheres to regulations like HIPAA by implementing controls. Security management focuses on protecting assets from threats. Identity management deals with authentication and authorization. Privacy management addresses personal data protection. The question specifically asks about meeting regulatory requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Privacy management
Why it's wrong here
Privacy management specifically focuses on the collection, use, disclosure, and retention of personal data, ensuring individuals' rights are protected. While HIPAA has a Privacy Rule, privacy management alone does not encompass the full scope of HIPAA, which also includes the Security Rule, Breach Notification Rule, and Enforcement Rule, requiring a broader approach than just data privacy principles.
- ✗
Identity management
Why it's wrong here
Identity management (IdM) systems are critical for controlling access to resources by authenticating users and authorizing their permissions. While IdM is a foundational security control that supports HIPAA's technical safeguards by ensuring only authorized personnel access Protected Health Information (PHI), it is a specific technical domain and not the comprehensive framework for managing an organization's adherence to all HIPAA regulations.
- ✗
Security management
Why it's wrong here
Security management encompasses the processes and controls designed to protect information systems and data from unauthorized access, use, disclosure, disruption, modification, or destruction. While the HIPAA Security Rule mandates robust security measures for electronic Protected Health Information (ePHI), security management is an operational discipline focused on threat mitigation and asset protection, rather than the strategic oversight and documentation required to demonstrate adherence to all regulatory mandates.
- ✓
Compliance management
Why this is correct
Compliance management is the overarching discipline that ensures an organization adheres to external laws, regulations, and internal policies, such as HIPAA. It involves establishing frameworks, implementing controls, conducting risk assessments, monitoring adherence, and maintaining documentation to systematically meet all regulatory requirements and demonstrate due diligence to auditors and regulators.
Go deeper
Related to this question
Learn chapter
Core Security Concepts
Key term
Privacy
Privacy in IT is the control over how personal data is collected, stored, used, and shared by systems and organizations.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every SC-900 question from scratch — 1,250 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.