Courseiva
Manage identity and accessmediumMultiple ChoiceObjective-mapped

AZ-500 Manage identity and access Practice Question

A company wants to use Microsoft Defender for Cloud to continuously assess their Azure resources against the Microsoft cloud security benchmark (MCSB). They need to view the current compliance score and specific recommendations for failing controls. Which feature in Defender for Cloud should they use?

⚠ Common exam trap

Many candidates confuse Secure Score (which shows overall security posture) with Regulatory Compliance (which shows adherence to a specific benchmark), leading candidates to pick Secure Score when the question explicitly asks for compliance against MCSB.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Regulatory Compliance dashboard

The Regulatory Compliance dashboard in Microsoft Defender for Cloud is specifically designed to assess resources against compliance standards like the Microsoft cloud security benchmark (MCSB). It provides a current compliance score, a breakdown of failing controls, and actionable recommendations to remediate those controls, directly meeting the company's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Security Policy

    Why it's wrong here

    Security Policy is the configuration surface where you define which regulatory standards and custom initiatives are assigned to a scope, such as the Microsoft Cloud Security Benchmark (MCSB). It establishes the compliance baseline and maps recommendations to controls, but it does not produce a real-time compliance score or a visual breakdown of passing versus failing controls. Compliance data is only observable after you provision standards to a scope, and then you must separately navigate to the Regulatory Compliance dashboard to view the assessment results. In short, Security Policy is the control plane for compliance measurement, not the reporting tool.

  • Regulatory Compliance dashboard

    Why this is correct

    The Regulatory Compliance dashboard is the dedicated reporting interface within Microsoft Defender for Cloud that continuously aggregates assessment results for assigned standards like MCSB. It provides a compliance score per standard, a per-control breakdown of pass and fail status, and drill-down details for each recommendation that impacts a control. This dashboard directly answers the requirement to assess compliance against a chosen regulatory framework by showing exactly which controls are not met and why. It is the correct tool because it maps Azure Security benchmark recommendations to regulatory compliance controls and offers a visual, actionable score.

  • Secure Score

    Why it's wrong here

    Secure Score is a metric that reflects your overall security posture by summing the potential improvement points from all security recommendations, regardless of any regulatory standard. It measures how well you are following Azure's best-practice baseline (which is aligned with MCSB), but it does not show you a compliance score for a specific regulation or display controls broken out by standard. For example, Secure Score will not tell you which specific MCSB controls you failed or how your compliance posture differs across standards you have assigned. Thus, while Secure Score is useful for prioritizing hardening actions, it is not a compliance assessment tool.

  • Workload Protections

    Why it's wrong here

    Workload Protections is a feature set in Defender for Cloud that enables paid detection capabilities, such as Microsoft Defender for servers, databases, and containers, to provide threat detection, vulnerability management, and security alerts. It is designed to secure your workloads in real time and investigate attacks, not to generate compliance reports or track adherence to regulatory standards. While some vulnerability findings from Workload Protections may feed into recommendations that affect compliance, the service itself does not display a regulatory compliance status or a control-by-control assessment. Therefore, choosing Workload Protections would fail to meet the requirement for continuously assessing compliance with MCSB.

About these practice questions

Courseiva writes every AZ-500 question from scratch — 194 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.