Courseiva

SC-100 Practice Question: Design solutions that align with security best practices and priorities

A company uses Microsoft Defender for Cloud to assess the security posture of their Azure subscriptions. They need to ensure that all resources are compliant with the Payment Card Industry Data Security Standard (PCI DSS). What should they do?

⚠ Common exam trap

Test-takers frequently confuse Azure Policy or Blueprints as the primary tool for compliance assessment, when in fact Defender for Cloud's built-in regulatory compliance standards are the correct, out-of-the-box solution for monitoring against frameworks like PCI DSS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the PCI DSS regulatory compliance standard in Microsoft Defender for Cloud

Microsoft Defender for Cloud includes built-in regulatory compliance standards, such as PCI DSS, that can be enabled directly. Once enabled, Defender for Cloud continuously assesses your Azure subscriptions against the PCI DSS controls and provides a compliance score with detailed remediation steps. This is the simplest and most effective method to monitor compliance without creating custom policies or blueprints.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create Azure Policy initiatives to enforce PCI DSS controls

    Why it's wrong here

    Azure Policy can enforce guardrails, but it does not natively provide a PCI DSS compliance score or a built-in regulatory standard. To assess PCI DSS, you would need to manually map each policy to specific PCI controls and build a custom dashboard, whereas Defender for Cloud already ships with an integrated PCI DSS assessment that continuously scans your subscriptions and surfaces non-compliant resources.

  • ✗

    Use Microsoft Purview to classify data and apply PCI DSS labels

    Why it's wrong here

    Microsoft Purview focuses on data estate governance, including data classification, sensitivity labels, and data lineage; it is not an infrastructure security assessment tool. It can label and govern data assets, but it cannot evaluate Azure resource configurations (like network security rules or storage encryption) against PCI DSS requirements, which is the core need for a compliance assessment.

  • ✗

    Deploy Azure Blueprints that include PCI DSS policies

    Why it's wrong here

    Azure Blueprints is deprecated and will be retired; it also only packages Azure Resource Manager templates, policies, and role assignments into a single deployable object. While you could embed Azure Policy definitions, Blueprints does not offer continuous regulatory compliance monitoring, a compliance score, or the ability to assess a live environment against PCI DSS controls over time — Defender for Cloud's regulatory compliance blade is the replacement.

  • ✓

    Enable the PCI DSS regulatory compliance standard in Microsoft Defender for Cloud

    Why this is correct

    Microsoft Defender for Cloud includes built-in regulatory compliance standards, including PCI DSS 3.2.1 (and newer versions), directly under the 'Regulatory compliance' blade. When you enable the PCI DSS standard, Defender for Cloud automatically maps your Azure Policy and security configurations to the applicable PCI controls, provides a compliance score, and generates prioritized recommendations with remediation steps, all updated continuously as your environment changes.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.