AZ-500 Manage identity and access Practice Question
A security analyst uses Microsoft Defender for Cloud. They need to view the current compliance status of their Azure subscription against the Payment Card Industry Data Security Standard (PCI DSS). Which feature in Defender for Cloud should they use?
⚠ Common exam trap
Many candidates confuse the general Security posture dashboard (which shows a security score) with the Regulatory compliance dashboard, which is the only place to see compliance against specific standards like PCI DSS, SOC 2, or ISO 27001.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory compliance dashboard
The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of your Azure subscription's compliance posture against specific standards like PCI DSS. It continuously assesses your resources against the controls defined in the selected compliance framework and displays a compliance score, passed/failed controls, and remediation steps. This is the dedicated feature for tracking regulatory compliance, not general security posture or vulnerability management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security posture dashboard
Why it's wrong here
The security posture dashboard in Defender for Cloud provides a unified view of your overall secure score, which aggregates the implementation of Microsoft security recommendations across subscriptions. It does not specifically map results to regulatory compliance standards such as PCI DSS, SOC 2, or ISO 27001; instead, it measures general security hygiene. While a strong secure score can improve compliance posture, this dashboard lacks the regulatory control mapping and standard-specific drill-down that the Regulatory compliance dashboard offers.
- ✓
Regulatory compliance dashboard
Why this is correct
The regulatory compliance dashboard in Defender for Cloud is specifically designed to display your environment's alignment with industry standards and regulatory frameworks, such as PCI DSS, SOC 2, ISO 27001, and Azure CIS. It continuously evaluates Azure Policy initiatives and maps discovered assessments to individual controls within each standard, showing pass/fail status per control and providing a detailed view of recommendations and affected resources. This makes it the correct tool for an analyst seeking to track compliance against a specific regulatory standard, unlike the other options which focus on security posture, vulnerabilities, or automation.
- ✗
Vulnerability assessment solutions
Why it's wrong here
Vulnerability assessment solutions in Defender for Cloud, such as the integrated Qualys or Microsoft Defender Vulnerability Management, are specialized tools that scan compute resources like VMs and containers for known CVEs, missing patches, and software misconfigurations. They output a list of vulnerabilities to remediate, but they do not evaluate or aggregate your infrastructure against an entire regulatory framework. Compliance with a standard like PCI DSS involves many controls beyond vulnerability findings (e.g., access control, logging, encryption), so the vulnerability assessment alone cannot provide a comprehensive compliance status.
- ✗
Workflow automation
Why it's wrong here
Workflow automation in Defender for Cloud is an orchestration feature that lets you define automated responses to security alerts and recommended actions, typically using Logic Apps to trigger events such as opening a ticket, sending email notifications, or running a remediation runbook. It is purely an action-oriented tool for operational response, not a reporting or assessment interface. Consequently, it does not display or track compliance status against regulatory standards, and an analyst would not use it to answer questions about overall compliance posture.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.