Courseiva

AZ-500 Manage identity and access Practice Question

A security analyst uses Microsoft Defender for Cloud. They want to view a list of all security recommendations for their Azure subscription, prioritized by their potential impact. Which Defender for Cloud dashboard should they use?

⚠ Common exam trap

It's easy for candidates to confuse the Secure Score dashboard with the Regulatory Compliance dashboard, thinking compliance standards inherently prioritize recommendations, but Secure Score is the only dashboard that explicitly ranks recommendations by their potential impact on your security score.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Secure Score

The Secure Score dashboard in Microsoft Defender for Cloud provides a prioritized list of security recommendations based on their potential impact on your overall security posture. Each recommendation is assigned a score contribution, allowing you to focus on the actions that will most improve your secure score. This directly matches the requirement to view recommendations prioritized by impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Secure Score

    Why this is correct

    The Secure Score blade in Microsoft Defender for Cloud is specifically designed as a prioritized, actionable list of security recommendations. Each recommendation is shown with its potential score impact, so you can see how many points you gain by remediating it, and the list is sorted to highlight the highest-impact actions first. Because it consolidates all recommendations from applied security policies and weights them by severity and resource health, it directly answers the analyst's need to prioritize remediation work.

  • ✗

    Regulatory Compliance

    Why it's wrong here

    The Regulatory Compliance dashboard maps your environment's compliance state against specific standards you assign, such as PCI DSS, ISO 27001, or SOC 2, and groups recommendations under each standard's control requirements. It does not serve as a general prioritized recommendation list; instead, it is filtered to show only the controls defined by the selected regulatory framework. An analyst looking for an overall prioritization across all security posture gaps would find this too narrowly scoped, as it omits recommendations that don't align to a chosen standard.

  • ✗

    Inventory

    Why it's wrong here

    The Inventory page provides a resource-centric view of all Azure resources connected to Defender for Cloud, showing each resource's security state, resource type, resource group, and subscription. While you can drill into a specific resource to see its applicable recommendations, the page does not aggregate and rank recommendations globally by their impact on your overall security score. It is meant for browsing and filtering individual assets, not for triaging a cross-subscription remediation queue.

  • ✗

    Workload protections

    Why it's wrong here

    Workload Protections is the dashboard for managing Microsoft Defender plans and viewing security alerts from threats like malware, suspicious logins, and anomalies across supported workload types. It surfaces alerts and threat detections rather than the hardening recommendations that make up Secure Score; although it may show a few 'recommendation' tiles for enabling plans, its primary purpose is to monitor active attacks and signals. An analyst wanting a prioritized list of remediation actions would be looking at the wrong blade, as this one is geared toward threat response and plan configuration.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.