AZ-500 Manage identity and access Practice Question
An organization is required to comply with the Health Insurance Portability and Accountability Act (HIPAA). They use Microsoft Defender for Cloud to manage their Azure security posture. Which feature in Defender for Cloud should they use to view their current compliance status against HIPAA controls?
⚠ Common exam trap
Candidates often confuse the Security posture dashboard (which shows overall security health) with the Regulatory compliance dashboard, mistakenly thinking the former includes compliance status against specific standards like HIPAA.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory compliance dashboard.
The Regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of your compliance posture against various standards, including HIPAA. It continuously assesses your Azure environment against HIPAA controls and displays the current compliance status, enabling you to track and improve adherence to regulatory requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Regulatory compliance dashboard.
Why this is correct
The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it continuously assesses your Azure environment against built-in regulatory standards such as HIPAA HITRUST, GDPR, and ISO 27001. It uses Azure Policy initiatives to map specific controls to resources, presenting a compliance score and per-control pass/fail status. This dashboard directly provides the evidence and remediation tracking needed to demonstrate adherence to HIPAA requirements, unlike the other dashboards.
- ✗
Security posture dashboard.
Why it's wrong here
The Security posture dashboard displays a Secure Score that aggregates the implementation status of security recommendations and controls across your subscriptions. While a higher secure score often correlates with stronger security, this score is not tied to any specific regulatory framework like HIPAA, and it does not show control-level mapping or compliance attestation. Therefore, it cannot be used to prove compliance with healthcare regulations.
- ✗
Recommendations dashboard.
Why it's wrong here
The Recommendations dashboard lists actionable security findings, such as enabling encryption or fixing network vulnerabilities, prioritized by severity and potential impact. These recommendations are derived from security policies and industry best practices, but they are not organized by regulatory controls, nor do they provide a compliance score or per-regulation status. Thus, it is suitable for hardening posture, not for reporting against HIPAA or other frameworks.
- ✗
Inventory dashboard.
Why it's wrong here
The Inventory dashboard presents an asset-centric view of all your resources, including their metadata, configurations, and relationships across subscriptions. It allows you to search and filter resources but does not evaluate them against any regulatory framework or track compliance controls. For fulfilling HIPAA compliance requirements, you need a solution that maps controls to resources and provides continuous assessment, which this dashboard lacks.
Go deeper
Related to this question
About these practice questions
Courseiva writes every AZ-500 question from scratch — 617 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.