Courseiva

Regulatory Compliance Dashboard in Defender for Cloud — Upload Evidence and View Score

Which TWO actions can be performed using Microsoft Defender for Cloud's 'Regulatory Compliance' dashboard?

Quick Answer

The correct answer is that the Regulatory Compliance dashboard in Defender for Cloud allows you to view the compliance score against a specific regulatory standard and upload manual evidence. This is because the dashboard aggregates continuous assessments from Azure Policy into a single score per standard, while the manual evidence upload feature lets you document controls that cannot be automatically scanned, such as physical security logs. On the AZ-500 exam, this question tests your ability to distinguish between the dashboard’s reporting functions and separate configuration tasks like remediation or continuous export, which are common distractors. A frequent trap is assuming the dashboard itself performs remediation actions, but those are handled through policy initiatives, not the compliance view. Remember the tip: “Score and store” — the dashboard shows the score and stores your manual proof, but it does not fix or export.

⚠ Common exam trap

AZ-500 often tests the distinction between viewing/attesting compliance versus remediating or exporting it, so candidates mistakenly select remediation or export options that belong to other Defender for Cloud blades.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Upload evidence documents for manual controls.

Option A is correct because the Regulatory Compliance dashboard in Microsoft Defender for Cloud lets you attach evidence files to manual controls that cannot be assessed automatically, so auditors can verify attestation-based requirements. Option C is correct because the dashboard displays a compliance score for each selected regulatory standard (for example, PCI DSS, ISO 27001, or NIST SP 800-53), showing the percentage of passed controls and the breakdown by control domain. Options B, D, and E are not actions available from this dashboard: automatic remediation is driven by workflow automation or remediation logic in recommendations, continuous export is configured separately under Environment settings, and third-party GRC integration is not performed directly from the Regulatory Compliance dashboard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Upload evidence documents for manual controls.

    Why this is correct

    The Regulatory Compliance dashboard supports manual attestation: for controls Defender for Cloud cannot assess automatically, you upload evidence files and mark them as compliant, which feeds the assessment. This satisfies the scenario's requirement to document manual control evidence within the dashboard.

  • ✗

    Automatically remediate non-compliant resources.

    Why it's wrong here

    Remediation is via policy, not the dashboard.

  • ✓

    View compliance score against a specific regulatory standard.

    Why this is correct

    The dashboard continuously assesses resources against a chosen regulatory standard, such as PCI DSS or ISO 27001, and displays the resulting compliance score with pass/fail control breakdowns. This satisfies the requirement to view compliance posture against a specific standard.

  • ✗

    Configure continuous export of compliance data.

    Why it's wrong here

    Continuous export streams security alerts, recommendations and secure score data to Log Analytics or Event Hubs; compliance data is not among the exportable tables. The dashboard itself offers download to CSV or Excel. Continuous export would be the right choice when feeding alert and recommendation telemetry into SIEM or reporting pipelines.

  • ✗

    Integrate with third-party GRC tools directly from the dashboard.

    Why it's wrong here

    The Regulatory Compliance dashboard only displays assessments against built-in standards and offers remediation links and Excel/CSV export; direct third-party GRC integration is not provided there. It is tempting because the dashboard does surface compliance posture, but that integration belongs to Microsoft Purview Compliance Manager or custom API work.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on AZ-500

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO actions can you perform using Microsoft Defender for Cloud's regulatory compliance dashboard? (Select two.)

medium
  • A.Create custom regulatory compliance recommendations.
  • B.Automatically remediate non-compliant resources.
  • ✓ C.View the compliance status for built-in standards like SOC 2 or PCI DSS.
  • ✓ D.Assign a compliance standard (e.g., SOC 2) to a subscription.
  • E.Enable or disable Microsoft Defender plans for a subscription.

Why C: The regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance status against built-in standards such as SOC 2, PCI DSS, ISO 27001, and Azure CIS. This dashboard aggregates security assessments and displays pass/fail status for each control, allowing you to track your compliance posture without manual configuration.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.