0% found this document useful (0 votes)
3 views6 pages

Module 5

Microsoft Purview is a comprehensive data governance solution that integrates data from various environments to ensure compliance and security. It features tools for data discovery, classification, and lineage, enabling organizations to manage sensitive data effectively. Additionally, Azure Policy provides governance for Azure resources, ensuring compliance with organizational standards through hierarchical policy enforcement.

Uploaded by

ashutoshjha.mail
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
3 views6 pages

Module 5

Microsoft Purview is a comprehensive data governance solution that integrates data from various environments to ensure compliance and security. It features tools for data discovery, classification, and lineage, enabling organizations to manage sensitive data effectively. Additionally, Azure Policy provides governance for Azure resources, ensuring compliance with organizational standards through hierarchical policy enforcement.

Uploaded by

ashutoshjha.mail
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

1.

Microsoft Purview Overview


1. Microsoft Purview is a unified data governance, risk, and compliance solution
that provides visibility across on-premises, multicloud, and SaaS data
environments.
It collects and integrates data from different sources into one centralized system,
allowing organizations to understand where their data is stored, how it is used, and
who has access to it. This helps in maintaining control over large and complex data
environments.
2. It enables organizations to manage and monitor data securely while ensuring
compliance with regulatory standards.
By offering tools for classification, discovery, and lineage, Purview helps
organizations track sensitive data, reduce risks, and comply with standards like GDPR
and ISO, making it essential for modern data governance.

2. Data Discovery, Classification, and


Lineage
1. Data discovery automatically scans and identifies data across different
environments.
It helps organizations locate structured and unstructured data stored in various
systems, ensuring that no critical or sensitive data remains hidden or unmanaged.
2. Data classification and lineage provide deeper insights into data usage and flow.
Classification labels data based on sensitivity (e.g., confidential), while lineage tracks
the journey of data from source to destination, helping in auditing, troubleshooting,
and compliance.

3. Risk and Compliance (Purview)


1. Microsoft Purview helps protect sensitive data across applications, devices, and
cloud environments.
It identifies risks such as unauthorized access or data leaks and ensures that proper
security controls are applied to prevent data breaches.
2. It supports regulatory compliance by mapping data to required standards and
policies.
Organizations can monitor compliance requirements and generate reports to meet
regulations like GDPR, ISO 27001, and other legal standards.

4. Unified Data Governance


1. Unified data governance provides a complete view of the organization’s data
estate.
It helps map all data assets, classify them, and understand how data flows across
systems, enabling better decision-making and control.
2. It enables secure access and data insights at scale.
Organizations can allow authorized users to access data safely while maintaining
security and generating insights for business intelligence.

5. Azure Policy Overview


1. Azure Policy is a governance tool that allows organizations to define, enforce,
and manage rules for Azure resources.
It ensures that all resources follow organizational standards such as allowed locations,
required tags, and approved configurations.
2. It continuously evaluates resources and identifies non-compliance.
Azure Policy monitors existing and new resources, flags violations, and can even
prevent non-compliant resources from being created.

6. Azure Policy Scope and Inheritance


1. Azure Policy can be applied at multiple levels including management group,
subscription, resource group, and individual resources.
This hierarchical structure allows organizations to enforce policies at different levels
depending on their governance needs.
2. Policies are inherited from higher levels to lower levels automatically.
For example, if a policy is applied at the subscription level, it will automatically apply
to all resource groups and resources within that subscription.

7. Azure Policy Initiatives


1. An initiative is a collection of multiple related policies grouped together to
achieve a broader compliance goal.
Instead of managing individual policies separately, organizations can manage them as
a single unit.
2. Initiatives simplify compliance tracking and enforcement across multiple
resources.
For example, a security initiative can include policies for encryption, vulnerability
monitoring, and endpoint protection.
8. Resource Locks
1. Resource locks prevent accidental deletion or modification of critical Azure
resources.
Even users with high-level permissions cannot perform restricted actions unless the
lock is removed, ensuring protection of important resources.
2. Locks can be applied at different levels and are inherited by child resources.
Applying a lock to a resource group automatically applies it to all resources within
that group.

9. Types of Resource Locks


1. Delete Lock allows read and modify operations but prevents deletion of the
resource.
This is useful when you want to ensure that a resource is not accidentally removed
while still allowing updates.
2. ReadOnly Lock allows only read operations and blocks both modification and
deletion.
This is the strictest lock and is similar to assigning read-only access to a resource.

10. Service Trust Portal


1. The Service Trust Portal provides access to Microsoft’s security, privacy, and
compliance documentation.
It includes certifications, audit reports, and compliance details that help organizations
understand how Microsoft protects their data.
2. It helps organizations meet regulatory requirements by providing verified
compliance information.
Users can download reports (e.g., ISO, SOC, GDPR) and use them to demonstrate
compliance in audits and legal processes.

AZ-900 Governance & Compliance –


MCQs

1. What is the main purpose of Microsoft Purview?

A. Create virtual machines


B. Manage data governance and compliance
C. Monitor network traffic
D. Store data

✅ Answer: B
Explanation: Purview helps in data governance, risk, and compliance across environments.

2. What does Microsoft Purview provide?

A. Only storage
B. Only networking
C. Unified view of data across environments
D. Only backup

✅ Answer: C
Explanation: It provides a unified view of on-prem, multicloud, and SaaS data.

3. What is Azure Policy used for?

A. Deploy applications
B. Monitor performance
C. Enforce rules and compliance
D. Increase speed

✅ Answer: C
Explanation: Azure Policy ensures resources follow defined rules and standards.

4. What happens when a resource violates Azure Policy?

A. Nothing
B. It gets deleted automatically
C. It is flagged as non-compliant
D. It stops working

✅ Answer: C
Explanation: Non-compliant resources are identified and reported.

5. What is an Azure Policy initiative?

A. Single policy
B. Group of related policies
C. Storage account
D. Network rule

✅ Answer: B
Explanation: Initiative = collection of multiple policies.

6. What is the purpose of resource locks?

A. Increase performance
B. Prevent accidental deletion or modification
C. Backup data
D. Encrypt files

✅ Answer: B
Explanation: Locks protect resources from unintended changes.

7. Which type of lock prevents deletion but allows modification?

A. ReadOnly
B. Delete lock
C. Write lock
D. Access lock

✅ Answer: B
Explanation: Delete lock blocks deletion but allows updates.

8. Which lock prevents both modification and deletion?

A. Delete lock
B. ReadOnly lock
C. Network lock
D. Storage lock

✅ Answer: B
Explanation: ReadOnly lock allows only reading.

9. What is the Service Trust Portal used for?

A. Create resources
B. Access Microsoft security and compliance information
C. Manage users
D. Deploy apps

✅ Answer: B
Explanation: It provides documents about security, privacy, and compliance.

10. What is required to access some Service Trust Portal documents?

A. Free account
B. Admin permission
C. Microsoft login and NDA acceptance
D. Subscription only

✅ Answer: C
Explanation: Some documents require login and NDA agreement.

You might also like