SC-100 Practice Question: Design solutions that align with security best practices and priorities
A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They need to ensure that all resources are compliant with the Payment Card Industry Data Security Standard (PCI DSS). What should they do?
⚠ Common exam trap
Test-takers frequently confuse Azure Policy or Blueprints as the primary tool for compliance assessment, when in fact Defender for Cloud's built-in regulatory compliance standards are the correct, out-of-the-box solution for monitoring against frameworks like PCI DSS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the PCI DSS regulatory compliance standard in Microsoft Defender for Cloud
Microsoft Defender for Cloud includes built-in regulatory compliance standards, such as PCI DSS, that can be enabled directly. Once enabled, Defender for Cloud continuously assesses your Azure subscriptions against the PCI DSS controls and provides a compliance score with detailed remediation steps. This is the simplest and most effective method to monitor compliance without creating custom policies or blueprints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create Azure Policy initiatives to enforce PCI DSS controls
Why it's wrong here
Azure Policy can enforce guardrails, but it does not natively provide a PCI DSS compliance score or a built-in regulatory standard. To assess PCI DSS, you would need to manually map each policy to specific PCI controls and build a custom dashboard, whereas Defender for Cloud already ships with an integrated PCI DSS assessment that continuously scans your subscriptions and surfaces non-compliant resources.
- ✗
Use Microsoft Purview to classify data and apply PCI DSS labels
Why it's wrong here
Microsoft Purview focuses on data estate governance, including data classification, sensitivity labels, and data lineage; it is not an infrastructure security assessment tool. It can label and govern data assets, but it cannot evaluate Azure resource configurations (like network security rules or storage encryption) against PCI DSS requirements, which is the core need for a compliance assessment.
- ✗
Deploy Azure Blueprints that include PCI DSS policies
Why it's wrong here
Azure Blueprints is deprecated and will be retired; it also only packages Azure Resource Manager templates, policies, and role assignments into a single deployable object. While you could embed Azure Policy definitions, Blueprints does not offer continuous regulatory compliance monitoring, a compliance score, or the ability to assess a live environment against PCI DSS controls over time — Defender for Cloud's regulatory compliance blade is the replacement.
- ✓
Enable the PCI DSS regulatory compliance standard in Microsoft Defender for Cloud
Why this is correct
Microsoft Defender for Cloud includes built-in regulatory compliance standards, including PCI DSS 3.2.1 (and newer versions), directly under the 'Regulatory compliance' blade. When you enable the PCI DSS standard, Defender for Cloud automatically maps your Azure Policy and security configurations to the applicable PCI controls, provides a compliance score, and generates prioritized recommendations with remediation steps, all updated continuously as your environment changes.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.