Courseiva
Manage identity and access →mediumMultiple Choice

AZ-500 Manage identity and access Practice Question

A security analyst uses Microsoft Defender for Cloud. They need to assess their Azure environment's compliance against the Payment Card Industry Data Security Standard (PCI DSS). Which dashboard in Defender for Cloud should they use to view the compliance status?

⚠ Common exam trap

Candidates often confuse Secure Score (which measures general security hygiene) with regulatory compliance scoring, but Secure Score does not map to specific standards like PCI DSS, while Regulatory Compliance does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regulatory Compliance

The Regulatory Compliance dashboard in Microsoft Defender for Cloud provides a pre-built assessment of your Azure environment against specific compliance standards, including PCI DSS. It maps your security controls to the requirements of the standard and shows a compliance score based on the results of continuous assessments. This is the correct tool for viewing compliance status against PCI DSS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Secure Score

    Why it's wrong here

    Secure Score is a posture metric that calculates a percentage based on how many of the available security recommendations you have remediated. It aggregates recommendations into security controls but does not map those controls to specific regulatory standards or clauses. While a high Secure Score indicates better security hygiene, it does not provide a pass/fail audit trail for frameworks such as CIS, PCI DSS, or NIST. Therefore, it does not directly display compliance with a regulatory standard.

  • ✗

    Security Alerts

    Why it's wrong here

    Security Alerts are generated by Defender for Cloud's detection engines when suspicious or malicious activity is identified on your workloads, such as sign-in anomalies, botnets, or unusual resource activity. These alerts are resource-centric and time-sensitive, designed for incident response, not for measuring configuration drift against compliance baselines. They contain threat intelligence and attack narratives but lack the control-to-requirement mapping that a compliance assessment requires. Thus, Security Alerts cannot serve as a compliance display.

  • ✓

    Regulatory Compliance

    Why this is correct

    The Regulatory Compliance dashboard in Defender for Cloud provides a dedicated view of how your Azure environment scores against a specific regulatory standard, such as CIS 1.4, NIST SP 800-53, or PCI DSS v3.2.1. It uses Azure Policy initiatives with policy definitions underlying each compliance control; each control displays a Pass/Fail status and a list of non-compliant resources based on continuous policy evaluation. The dashboard also shows the compliance score for that standard, giving you an immediate audit-ready overview. This directly meets the analyst's need to display compliance against a specific regulatory standard.

  • ✗

    Workbooks

    Why it's wrong here

    Azure Workbooks are interactive, customizable reporting tools that combine data from multiple sources using Kusto Query Language (KQL) to create visualizations and dashboards. You can build a custom compliance workbook by querying Azure Resource Graph or security recommendations, but it is a manual, effort-intensive process and does not automatically map resources to regulatory controls. The built-in Regulatory Compliance dashboard is the standard, out-of-the-box tool that performs this mapping for you, so Workbooks are not the appropriate choice when you need immediate regulatory compliance visibility.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.