Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

Which TWO actions can you perform using Microsoft Defender for Cloud's regulatory compliance dashboard? (Select two.)

⚠ Common exam trap

Many candidates confuse the regulatory compliance dashboard's ability to assign standards (which is correct) with the ability to create custom recommendations or auto-remediate, which are separate functions handled by Azure Policy and Defender for Cloud's security recommendations, not the compliance dashboard itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

View the compliance status for built-in standards like SOC 2 or PCI DSS.

The regulatory compliance dashboard in Microsoft Defender for Cloud provides a pre-built view of compliance status against built-in standards such as SOC 2, PCI DSS, ISO 27001, and Azure CIS. This dashboard aggregates security assessments and displays pass/fail status for each control, allowing you to track your compliance posture without manual configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create custom regulatory compliance recommendations.

    Why it's wrong here

    The regulatory compliance dashboard in Microsoft Defender for Cloud is a visualization layer over Azure Policy regulatory compliance initiatives. It cannot generate custom recommendations by itself; to create custom regulatory compliance recommendations, you must author a custom Azure Policy initiative with custom policies and assign it to the relevant scope. Only then will the dashboard reflect those custom recommendations.

  • ✗

    Automatically remediate non-compliant resources.

    Why it's wrong here

    While Defender for Cloud surfaces compliance findings and provides remediation steps, the regulatory compliance dashboard itself does not execute automatic remediation. Non-compliant resources are remediated by configuring Azure Policy remediation tasks (e.g., deployIfNotExists or modify effect) or by applying the 'Fix' action from Defender recommendations. Merely viewing the compliance status on the dashboard has no effect on resource configuration.

  • ✓

    View the compliance status for built-in standards like SOC 2 or PCI DSS.

    Why this is correct

    The regulatory compliance view in Microsoft Defender for Cloud displays a continuous assessment of Azure resources against built-in regulatory standards such as SOC 2, PCI DSS, ISO 27001, and GDPR. For each assigned standard, the dashboard shows controls, policy mappings, and pass/fail status, making it the primary interface for monitoring compliance posture across subscriptions. This is a read-only visibility function, distinct from modifying standards or plans.

  • ✓

    Assign a compliance standard (e.g., SOC 2) to a subscription.

    Why this is correct

    You can assign built-in compliance standards like SOC 2 to a subscription through the compliance standards page in the regulatory compliance dashboard. Assigning a standard applies the corresponding Azure Policy regulatory compliance initiative to that subscription, enabling continuous scanning and status updates. This is a management action performed from the dashboard, separate from viewing the resulting compliance data.

  • ✗

    Enable or disable Microsoft Defender plans for a subscription.

    Why it's wrong here

    Enabling or disabling Microsoft Defender plans (e.g., Defender for Servers, Defender for SQL, or Defender for Storage) is done in the Microsoft Defender plans section within Environment settings, not in the regulatory compliance dashboard. These plan toggles control the deployment of monitoring agents and security features, whereas the regulatory compliance dashboard is focused on compliance assessment and reporting. Trying to switch plans from the compliance blade is unsupported.

About these practice questions

This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.