AZ-500 Manage identity and access Practice Question
A compliance team wants evidence that Azure resources are evaluated against the Microsoft Cloud Security Benchmark. Which Defender for Cloud area should they use?
⚠ Common exam trap
Many exam-takers confuse the Regulatory compliance dashboard with general log querying or network security controls, overlooking that the MCSB is specifically enforced through Azure Policy initiatives within Defender for Cloud's compliance monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory compliance and security policy assignments
The Regulatory compliance dashboard in Microsoft Defender for Cloud provides continuous monitoring of Azure resources against the Microsoft Cloud Security Benchmark (MCSB). It maps built-in policy assignments to compliance controls, generates a compliance score, and offers remediation steps. This is the designated area for evidence of MCSB evaluation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Regulatory compliance and security policy assignments
Why this is correct
Regulatory compliance and security policy assignments are the primary mechanism in Azure for evidence that resources comply with standards. Azure Policy initiative definitions (e.g., CIS Microsoft Azure Foundations Benchmark, NIST SP 800-53, HIPAA) continuously evaluate resource configuration against required controls and report compliance states per resource. Defender for Cloud's regulatory compliance blade aggregates these policy assignments into a dashboard showing pass/fail status, making them the direct evidence source for a compliance team.
- ✗
Microsoft Entra app consent settings
Why it's wrong here
Microsoft Entra app consent settings govern whether users or admins can grant applications permission to sign in and access tenant resources, and they do not assess or report on the compliance state of Azure workloads. While important for identity security, this setting is unrelated to regulatory frameworks like CIS or ISO and produces no evidence that individual resources meet compliance requirements. Therefore, it cannot answer the compliance team's evidence request.
- ✗
Azure Firewall DNAT rules
Why it's wrong here
Azure Firewall DNAT rules define how inbound traffic is translated to a private IP address, which is a network-layer control used for routing or exposing services. Even if firewall logs are later used as audit evidence, the presence of a DNAT rule itself does not indicate or document whether a resource is compliant with regulatory standards. This option fails because it addresses a specific technical configuration, not an overarching compliance assessment policy.
- ✗
Log Analytics saved searches only
Why it's wrong here
Log Analytics saved searches are reusable Kusto queries that retrieve log data, but the queries alone do not assign, evaluate, or record regulatory compliance status. A compliance team could use saved searches to pull audit logs, yet without a policy assignment or Defender for Cloud recommendation, the search results lack the formal control-framework mapping needed to be evidence. Thus saved searches are an auxiliary tool, not the authoritative compliance evidence source.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.