AZ-500 Practice Question: Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel
Your company uses Microsoft Defender for Cloud's Security Posture Management (CSPM) features. You need to identify resources that are not compliant with the organization's security baseline. What should you do?
⚠ Common exam trap
Candidates often confuse the secure score or security recommendations with compliance tracking, not realizing that the regulatory compliance dashboard is the dedicated tool for mapping resources to specific baseline controls and standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the regulatory compliance dashboard
The regulatory compliance dashboard in Microsoft Defender for Cloud provides a view of how your resources comply with specific security standards and baselines, such as the Microsoft Cloud Security Benchmark (MCSB) or custom regulatory frameworks. By selecting the appropriate compliance standard that matches your organization's security baseline, you can identify resources that are non-compliant with specific controls. This dashboard directly maps security assessments to compliance controls, making it the correct tool for identifying resources not meeting your baseline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
View the secure score
Why it's wrong here
The secure score is an aggregated percentage that reflects how well your environment aligns with security controls, but it does not map those controls to specific regulatory standards such as PCI DSS, ISO 27001, or SOC 2. It only gives you an overall posture score, not a detailed breakdown of which standards you satisfy or fail. Therefore, it cannot answer the question of whether a particular resource or workload is compliant with a given regulation.
- ✗
Review the security recommendations
Why it's wrong here
The security recommendations blade lists actionable hardening steps like enabling MFA, remediating vulnerabilities, or securing storage accounts, and each recommendation can be individually resolved or exempted. However, these recommendations are not organized by regulatory standard; the blade does not indicate which standards you pass or fail, and some recommendations are not part of any compliance initiative. It therefore cannot act as a compliance dashboard and would not show the required compliance status against standards.
- ✓
Use the regulatory compliance dashboard
Why this is correct
The regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it provides a continuous, standards-based assessment by mapping Azure Policy initiatives to controls from frameworks such as Azure CIS, PCI DSS, ISO 27001, SOC 2, and even custom standards. It shows a compliance percentage per standard, lets you drill down to non-compliant resources and controls, and tracks compliance history over time. You can select which standards to assess in the compliance policies settings, giving you exactly the detailed compliance status needed.
- ✗
Use the inventory blade
Why it's wrong here
The inventory blade is essentially an asset management view that lists resources by type, resource group, and subscription, along with any associated security findings or tags. It does not evaluate those resources against regulatory frameworks or produce a compliance score, so it cannot show adherence to HIPAA, PCI, or other standards. Its purpose is to help you locate and manage assets, not to report on regulatory compliance.
Go deeper
Related to this question
About these practice questions
One of 617 original AZ-500 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.