Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

A security team uses Microsoft Defender for Cloud's regulatory compliance dashboard to track compliance with PCI DSS. They notice that some controls are marked as 'N/A' even though they have relevant resources. What is the most likely reason?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The resources are in a subscription that is not included in the scope of the compliance standard.

The correct answer is C: resources in a subscription that is not included in the scope of the compliance standard. In Microsoft Defender for Cloud's regulatory compliance dashboard, a control is shown as 'N/A' when the standard's assessment scope does not cover the subscription containing those resources, so the control is not evaluated against them. This scoping is configured when assigning the regulatory compliance standard, and only in-scope subscriptions are assessed. Option A is incorrect because a missing custom assessment would leave a control unassessed or healthy/unhealthy, not scoped out as N/A. Option B is incorrect because the regulatory compliance dashboard is a Defender for Cloud capability and does not require a Microsoft Purview Compliance Manager license. Option D is incorrect because manual attestation affects a control's compliance state, not whether it is marked N/A due to scope.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The resources do not have the required custom assessment.

    Why it's wrong here

    Defender for Cloud's regulatory compliance standards rely on built-in assessments that are automatically derived from security policies and findings. Custom assessments are only used when you have implemented custom Azure Policy initiatives, and they are never a prerequisite for evaluating built-in controls. Therefore, missing custom assessments would not cause resources to be excluded from the compliance dashboard.

  • ✗

    The compliance dashboard requires a Microsoft Purview Compliance Manager license.

    Why it's wrong here

    Defender for Cloud includes a regulatory compliance dashboard as a core feature, so it does not require an additional Microsoft Purview Compliance Manager license. Purview Compliance Manager is a separate product for enterprise compliance management, while Defender for Cloud uses built-in policy assignments and Azure Policy to track regulatory standards. The dashboard is available within the Defender for Cloud portal without any extra licensing beyond Defender for Cloud.

  • ✓

    The resources are in a subscription that is not included in the scope of the compliance standard.

    Why this is correct

    In Defender for Cloud, each regulatory compliance standard is assigned to a specific scope, such as a subscription or management group, when you enable it. Only resources within that assigned scope are evaluated and reported in the compliance dashboard, and resources in unassigned subscriptions are completely ignored. If the subscription containing the resources is not part of the standard's assignment, those resources will not appear in the compliance view.

  • ✗

    The resources have not been manually claimed as compliant.

    Why it's wrong here

    In Defender for Cloud, compliance status is calculated automatically by the underlying Azure Policy initiative, not by manual declarations for each resource. Although some controls may be 'manual' and require you to mark them as compliant or not applicable, this is a control-level action and is not used to mark resources as 'N/A' for automated assessments. A failure to manually claim resources does not prevent them from being assessed or displayed.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.