What to Create First to Review GDPR Compliance in Compliance Manager?

Answer Correct answer: A — Create a GDPR assessment in Compliance Manager, which applies the Microsoft GDPR template and scores M365 E5 controls with minimal effort.

You have a Microsoft 365 E5 subscription. You need to review the compliance of the subscription with the General Data Protection Regulation (GDPR) by using Compliance Manager. The solution must minimize administrative effort. What should you create first?

  1. an assessment Correct Answer
  2. an alert policy to monitor for score changes
  3. a template
  4. review assessments

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the order of operations inside Compliance Manager — an assessment must exist before any compliance score, improvement action, or score-change alert is meaningful; the trap is selecting "a template" because templates appear to be the starting point.

Compliance Manager measures regulatory compliance by scoring the controls of an assessment that is built from a Microsoft-provided template. The correct first action for reviewing GDPR compliance in a Microsoft 365 E5 subscription is to create a GDPR assessment (A), not a template, an alert policy, or a review of existing assessments.

Selecting "a template" on the assumption that you must build the GDPR framework yourself. Microsoft already ships a ready-made GDPR template, so the only thing an administrator creates is the assessment that binds that template to the M365 E5 tenant.

Community Discussion (3 comments)

thetootall 👍 2 Selected: A
A is correct https://learn.microsoft.com/en-us/compliance/regulatory/gdpr
Amin4799 👍 3 Selected: A
The first step you should take is to create an assessment in Compliance Manager. This will allow you to evaluate the compliance of your Microsoft 365 E5 subscription with the requirements of the General Data Protection Regulation (GDPR). Once the assessment is created, you can proceed with reviewing the compliance status and taking appropriate actions to address any gaps or issues identified. Therefore, the correct answer is: A. an assessment
CheMetto 👍 1
Correct. https://learn.microsoft.com/en-us/compliance/regulatory/gdpr as said here, you need as first to create an assesment where you'll choose the template created by microsoft

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Compliance Manager separates the reusable content (templates, which Microsoft supplies for regulations such as GDPR) from the tenant-specific object (assessments, which bind a template to your Microsoft 365 E5 environment and start generating a compliance score). Option A, an assessment, is therefore the object you create first: it applies the Microsoft GDPR template, maps its controls to your tenant, and produces the compliance score and improvement actions you need for the review. This also satisfies "minimize administrative effort", because the built-in template is used as-is rather than authored from scratch. As Amin4799 put it, "The first step you should take is to create an assessment in Compliance Manager." Once that assessment exists, reviewing the score and working improvement actions is the follow-up activity, not the first step.

Why the Other Options Are Wrong

Option C, a template, is wrong because Microsoft already publishes the GDPR template inside Compliance Manager; creating your own template would add administrative effort rather than reduce it, and a tenant-specific template alone produces no score until an assessment uses it. Option B, an alert policy to monitor for score changes, is a monitoring convenience that presupposes an assessment and a changing score — it cannot perform the GDPR review itself. Option D, review assessments, describes the Compliance Manager page where existing assessments are listed; it is not an artifact you create, and with no GDPR assessment present there would be nothing relevant to review.

Community Comment Notes

Every recorded vote went to A, and the comments converge on the same reasoning. thetootall simply states "A is correct" and links Microsoft's GDPR regulatory documentation, which describes creating an assessment to evaluate GDPR compliance. CheMetto agrees and points out that you first create an assessment in which you'll pick the Microsoft-provided template — "you'll choose the template created by microsoft" — which is exactly why option C is the distractor and not the answer. No commenter argued for an alert policy or for merely reviewing the assessments list.

Official Reference

Exam Strategy

When a question says "minimize administrative effort" in Compliance Manager, prefer the action that reuses Microsoft's built-in templates rather than one that creates new content. Remember the sequence: template (provided by Microsoft) → assessment (created by you) → score and improvement actions → optional alerts on score changes.

Frequently Asked Questions

Why can't I just create a template instead of an assessment in Compliance Manager?

Templates are the prebuilt regulatory frameworks Microsoft provides, including GDPR. An assessment is what binds that GDPR template to your Microsoft 365 E5 tenant and produces the compliance score and improvement actions.

Does an alert policy for compliance score changes satisfy the GDPR review requirement?

No. An alert policy only notifies you after a score changes; it performs no evaluation. It also depends on an assessment already existing, so it cannot be the first thing you create.

Related Analysis

← Back to SC-400 Study Guide