mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Deploying Microsoft Defender for Cloud to secure…
A company is deploying Microsoft Defender for Cloud to secure their hybrid cloud environment. They need to ensure that regulatory compliance with PCI DSS is continuously monitored and reported. Which solution should they use to automatically assess and report compliance posture?
⚠ Common exam trap
It's easy for candidates to confuse Azure Policy (the enforcement engine) with the Regulatory compliance dashboard (the reporting interface), leading them to select Azure Policy as the direct solution for compliance reporting, when in fact the dashboard is the correct tool for continuous monitoring and reporting of regulatory posture.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regulatory compliance dashboard in Microsoft Defender for Cloud
The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct solution because it provides built-in, automated assessment of compliance against regulatory standards like PCI DSS. It continuously monitors your hybrid cloud environment against the PCI DSS controls, generates a compliance score, and produces detailed reports without requiring custom policy definitions. This dashboard integrates with Azure Policy to map controls to assessments, but the dashboard itself is the dedicated tool for viewing and reporting compliance posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Azure Policy
Why it's wrong here
Azure Policy enforces and audits resource configurations through initiatives such as 'Deploy prerequisites for enabling Microsoft Defender for Cloud', but its core 'compliance' is about matching Azure resources to written policy rules (custom or built-in), not about assessing against external regulatory standards like PCI DSS. While Azure Policy can be used behind the scenes by Defender for Cloud to evaluate security controls, it lacks the pre-packaged regulatory standards library, the continuous regulatory compliance scoring, and the downloadable compliance reports that the Defender for Cloud Regulatory Compliance dashboard provides. In short, Azure Policy is a governance and configuration assurance mechanism, not a compliance reporting solution.
- ✗
Microsoft Purview Information Protection
Why it's wrong here
Microsoft Purview Information Protection (MIP) focuses on data classification, sensitivity labels, and rights management—protecting documents and emails by classifying them and applying encryption or usage restrictions. It does not assess the security configuration of cloud workloads against frameworks like PCI DSS, nor does it produce compliance reports for cloud infrastructure. MIP is a data protection layer, whereas cloud regulatory compliance monitoring is a security posture management capability that evaluates whether workloads meet specific regulatory control requirements.
- ✓
Regulatory compliance dashboard in Microsoft Defender for Cloud
Why this is correct
The Regulatory compliance dashboard in Microsoft Defender for Cloud is the correct tool because it continuously monitors subscribed cloud resources against a wide range of industry and regulatory standards (for example, PCI DSS, ISO 27001, SOC 2, and NIST). It provides a real-time compliance score, a control-by-control breakdown, automated evidence collection, and the ability to download authoritative PDF/CSV compliance reports. Unlike Azure Policy's raw policy compliance, this dashboard maps assessments directly to regulatory control gaps and maintains a standards-specific view, making it the purpose-built solution for continuous compliance assessment and reporting (e.g., PCI DSS).
- ✗
Microsoft Entra ID Governance
Why it's wrong here
Microsoft Entra ID Governance is an identity and access management solution that handles user lifecycle automation, access reviews, entitlement management, and privileged identity management (PIM). It is not designed to assess the security posture of cloud workloads or to map their configurations to external compliance mandates such as PCI DSS. While a strong identity governance program contributes to overall security and can support certain compliance frameworks (like SOX access controls), it does not provide continuous cloud compliance monitoring or generate regulatory compliance reports for infrastructure, thereby making it an incorrect answer here.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.