AZ-500 Manage identity and access Practice Question
A company uses Microsoft Defender for Cloud to manage its security posture. The compliance team wants to monitor the subscription's compliance with the Payment Card Industry Data Security Standard (PCI DSS). They need to view a detailed compliance report and track progress over time. What should they do in Defender for Cloud?
⚠ Common exam trap
Candidates often confuse enabling Defender plans (which provide threat detection) with adding a compliance standard (which provides a compliance assessment), leading them to select Option A instead of the correct dashboard action in Option B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Add the PCI DSS standard from the regulatory compliance dashboard.
The regulatory compliance dashboard in Microsoft Defender for Cloud allows you to add built-in compliance standards like PCI DSS. Once added, the dashboard automatically assesses your subscription against the standard's controls, provides a detailed compliance report, and tracks progress over time with a compliance score and historical trend. This is the direct method to monitor PCI DSS compliance without needing to enable specific Defender plans or create custom initiatives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the relevant Defender for Cloud plans (e.g., Defender for Servers, Defender for SQL).
Why it's wrong here
Enabling Defender for Cloud plans such as Defender for Servers or Defender for SQL activates workload protection and produces security alerts and recommendations. However, this action only provides the underlying security findings; it does not register the PCI DSS standard in the regulatory compliance dashboard. Without explicitly adding the PCI DSS standard, the dashboard will not show PCI DSS-specific compliance posture, even though the prerequisite plans are active.
- ✓
Add the PCI DSS standard from the regulatory compliance dashboard.
Why this is correct
Adding the PCI DSS standard from the regulatory compliance dashboard is the correct action because Defender for Cloud includes a built-in regulatory compliance initiative pre-mapped to PCI DSS controls. This initiative automatically runs assessments against your environment and presents the results in a dedicated compliance view, allowing you to track progress against each control requirement. This is the straightforward, intended method to start monitoring PCI DSS compliance.
- ✗
Create a custom regulatory compliance initiative based on PCI DSS controls.
Why it's wrong here
Creating a custom regulatory compliance initiative based on PCI DSS controls is possible but unnecessary and suboptimal. The built-in PCI DSS standard already aggregates the appropriate Azure Policy definitions and control mappings, saving you from manually assembling policies and ensuring alignment with the official PCI DSS requirements. A custom initiative risks missing controls, requires extra maintenance, and does not provide the out-of-the-box compliance experience that the dashboard's built-in standard offers.
- ✗
Configure continuous export to send compliance data to a Log Analytics workspace.
Why it's wrong here
Configuring continuous export to a Log Analytics workspace is used to stream security alerts, recommendations, and compliance data to external tools for analytics or long-term retention. This action does not enable or surface the PCI DSS compliance dashboard within Defender for Cloud; the dashboard only appears after the PCI DSS standard is added from the regulatory compliance dashboard. Continuous export is a separate feature for data integration, not a method for activating a compliance standard.
Go deeper
Related to this question
About these practice questions
One of 194 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company needs to demonstrate compliance with the Payment Card Industry Data Security Standard (PCI DSS) for their Azure workloads. They use Microsoft Defender for Cloud for security management. Which feature should they use to view their current compliance status against PCI DSS controls and track progress over time?
easy- A.Security policy
- B.Recommendations
- ✓ C.Regulatory compliance dashboard
- D.Security incidents
Why C: The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance posture against standards like PCI DSS. It maps Azure resource configurations to specific PCI DSS controls, shows pass/fail status per control, and tracks compliance score over time, enabling continuous monitoring and evidence collection for auditors.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.