Courseiva

AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel

You are configuring Microsoft Defender for Cloud's regulatory compliance dashboard. Your organization must comply with SOC 2. You have enabled the SOC 2 regulatory compliance standard. After a week, some controls show as 'Unhealthy'. What is the most likely reason for the 'Unhealthy' status?

⚠ Common exam trap

A common mix-up: candidates assume 'Unhealthy' means the standard is misconfigured or not fully enabled, rather than understanding that it directly reflects Azure Policy non-compliance results from the underlying resources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The underlying Azure Policy initiatives have resources that are non-compliant.

The 'Unhealthy' status in Defender for Cloud's regulatory compliance dashboard indicates that the underlying Azure Policy initiatives associated with the SOC 2 standard have identified resources that are non-compliant. Defender for Cloud maps regulatory standards to Azure Policy definitions, and the compliance score is derived from the compliance state of those policies. Therefore, when controls show as 'Unhealthy', it is because the corresponding Azure Policy evaluations have found resources that do not meet the required configuration or security controls defined by SOC 2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The standard is not fully enabled for all subscriptions.

    Why it's wrong here

    When a regulatory compliance standard is enabled in Defender for Cloud, it provisions an Azure Policy initiative and begins assessing resource compliance. If the standard were not fully enabled for a subscription, that subscription would appear as 'Not registered' or the compliance dashboard would show no assessment data; it would not display controls with 'Unhealthy' status. Therefore, the observed unhealthy controls indicate the standard is actively assigned and evaluated.

  • ✗

    The SOC 2 standard is not supported by Defender for Cloud.

    Why it's wrong here

    Defender for Cloud supports a wide range of regulatory standards, including SOC 2 Type 2, which can be added through the Regulatory Compliance blade for a subscription. The engine maps SOC 2 requirements to Azure Policy definitions and evaluates resources against them, producing health states. Thus, the possibility that SOC 2 is unsupported is categorically false; if it were unsupported, the standard would not appear in the list of available standards to add.

  • ✗

    You need to manually attest to the controls to mark them as healthy.

    Why it's wrong here

    Manual attestation is an optional feature that lets you override an assessment with a declared compliance status, backed by security evidence, but it is not a prerequisite for a control to become healthy. Automated policy evaluation runs continuously and determines health based on resource compliance with the associated policy definitions. If a control shows 'Unhealthy', it is because at least one resource violates the policy—not because you failed to attest to it. Attestation is primarily for manual controls, not a universal gateway to healthy status.

  • ✓

    The underlying Azure Policy initiatives have resources that are non-compliant.

    Why this is correct

    Regulatory compliance in Defender for Cloud is built on Azure Policy initiatives: each control is backed by one or more policy definitions that continuously audit your resources. When a resource is found to be non-compliant with a policy assignment, the corresponding control is marked 'Unhealthy', since compliance is aggregated at the control level across all evaluated resources. This is the direct and expected cause of the unhealthy status you are seeing, rather than a misconfiguration of the standard assignment.

About these practice questions

One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.