Secure Azure using Microsoft Defender for Cloud and Microsoft Sentinel →mediumMultiple ChoiceObjective-mapped
Multicloud Regulatory Compliance in Defender for Cloud
Your organization uses Microsoft Defender for Cloud to secure a multi-cloud environment that includes Azure, AWS, and GCP resources. You need to ensure that all resources are assessed against a consistent set of security standards. What should you configure first?
Quick Answer
The correct answer is to add a regulatory compliance standard such as 'Azure CIS 1.4.0' and enable continuous export for all connected clouds. This works because Microsoft Defender for Cloud’s multicloud regulatory compliance feature allows you to apply a single, consistent compliance framework—like Azure CIS or NIST SP 800-53—across Azure, AWS, and GCP resources, ensuring unified assessment and reporting. On the AZ-500 exam, this question tests your understanding that Defender for Cloud acts as the central compliance hub for multicloud environments, while options like AWS Security Hub or Azure Policy are either cloud-specific or lack native integration. A common trap is assuming you need separate tools per cloud, but Defender for Cloud’s built-in standards cover them all. Memory tip: think “One standard to rule them all”—add a single compliance standard in Defender for Cloud, and it applies across every connected cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
In Defender for Cloud, add a regulatory compliance standard such as 'Azure CIS 1.4.0' and enable continuous export for all connected clouds.
In Microsoft Defender for Cloud, you can add regulatory compliance standards such as 'Azure CIS 1.4.0' and enable continuous export for all connected clouds. This ensures consistent security standards are applied across Azure, AWS, and GCP resources. Option B is wrong because connecting AWS and GCP accounts to AWS Security Hub and Google Security Command Center does not leverage Defender for Cloud's multicloud connector; the correct approach is to use Defender for Cloud's native multicloud capabilities. Option C is wrong because Azure Policy is designed for Azure-only resources, not for AWS or GCP. Option D is wrong because Microsoft Sentinel is a SIEM tool for security analytics, not for defining and enforcing compliance standards across clouds.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
In Defender for Cloud, add a regulatory compliance standard such as 'Azure CIS 1.4.0' and enable continuous export for all connected clouds.
Why this is correct
Defender for Cloud supports applying Azure compliance standards to multicloud resources via connectors.
- ✗
Connect the AWS and GCP accounts to AWS Security Hub and Google Security Command Center respectively, then enable Defender for Cloud's multicloud connector.
Why it's wrong here
This approach uses separate native tools, not a consistent standard across clouds.
- ✗
Create Azure Policy initiatives and assign them to the management groups that contain the multicloud resources.
Why it's wrong here
Azure Policy only applies to Azure resources, not AWS or GCP.
- ✗
Configure Microsoft Sentinel to ingest security findings from AWS and GCP, then create custom alerts for compliance deviations.
Why it's wrong here
Sentinel is for SIEM, not for applying compliance standards.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 194-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on AZ-500
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You need to prioritize security recommendations in Microsoft Defender for Cloud. Your compliance team requires a framework that maps to regulatory standards. What should you use?
easy- ✓ A.Regulatory compliance standards
- B.Azure Policy compliance dashboard
- C.Inventory feature
- D.Secure score
Why A: Regulatory compliance standards in Microsoft Defender for Cloud map security recommendations to specific regulatory frameworks (e.g., SOC 2, PCI DSS, ISO 27001), enabling the compliance team to prioritize based on regulatory requirements. The secure score (Option D) provides an overall posture but does not map to specific standards. Azure Policy compliance dashboard (Option B) is used for policy enforcement, not recommendation prioritization. Inventory (Option C) lists resources without compliance mapping.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.