Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A company uses Microsoft Defender for Cloud to monitor its security posture. The compliance team wants to receive email notifications immediately when a control in the ISO 27001 regulatory compliance standard fails. They want to be alerted only when specific controls change from 'compliant' to 'non-compliant'. Which feature should they configure?

⚠ Common exam trap

A common mix-up: candidates confuse Security Alerts (which are threat-focused) with compliance state change notifications, or assume the Regulatory Compliance dashboard's continuous export can directly send real-time email alerts, but it only exports data to external sinks without built-in notification logic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Workflow automation based on regulatory compliance assessment changes

Workflow automation in Microsoft Defender for Cloud can be configured to trigger based on regulatory compliance assessment changes, specifically when a control transitions from 'compliant' to 'non-compliant'. This allows the compliance team to receive immediate email notifications for ISO 27001 control failures without manual polling or dashboard monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security Alerts from Microsoft Defender for Cloud

    Why it's wrong here

    Security alerts in Microsoft Defender for Cloud are triggered by detected threats such as suspicious sign-ins, malware, or anomalous resource behavior. They are not triggered by changes in regulatory compliance assessments, which are based on Azure Policy definitions and reflect control status like "Failed" or "Passed." Therefore, security alerts cannot be used to proactively notify an administrator when a compliance control fails. To receive such notifications, you need a mechanism specifically tied to assessment changes, not threat detections.

  • ✗

    Regulatory Compliance dashboard with continuous export

    Why it's wrong here

    The Regulatory Compliance dashboard provides a visual summary of your compliance posture against standards like CIS or PCI DSS, but it does not emit notifications when an assessment changes. Continuous export can stream assessment data to a Log Analytics workspace or Event Hubs, yet it only moves data; it does not generate email or SMS alerts directly. To trigger notifications from the exported data, you would need to layer Azure Monitor alert rules or an external automation solution on top. Thus, continuous export alone is not a notification mechanism for compliance violations.

  • ✓

    Workflow automation based on regulatory compliance assessment changes

    Why this is correct

    Workflow automation in Microsoft Defender for Cloud is the native mechanism to react to changes in regulatory compliance assessments. You configure an automation rule to watch for a specific assessment status change (e.g., a control failing) and then invoke a Logic App or Power Automate flow to send an email, post to Teams, or create a ticket. This provides the proactive notification (e.g., email) required by the scenario. It is the only built-in way to directly trigger external actions based on compliance assessment changes.

  • ✗

    Custom recommendations in Microsoft Defender for Cloud

    Why it's wrong here

    Custom recommendations allow you to define your own security best practices and assessments within Defender for Cloud, extending the built-in recommendations. However, they are only visible in the recommendations list and do not have any native notification capability on their own. If a custom recommendation's assessment changes, it does not trigger an email unless you explicitly attach a workflow automation rule to it. Therefore, custom recommendations are for defining rules, not for delivering alerts when standards are violated.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.