Courseiva
mediumMultiple Choice

SC-100 Practice Question: Is planning to use Microsoft Defender for Cloud's…

An organization is planning to use Microsoft Defender for Cloud's regulatory compliance dashboard to track adherence to PCI DSS. The security team wants to ensure that all Azure resources are covered by the compliance assessment. What is the first step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Defender for Cloud on all subscriptions and ensure resources are covered.

For the regulatory compliance dashboard to assess resources, Microsoft Defender for Cloud must first be enabled on all subscriptions and resources must be covered by its enhanced security features. Without enabling Defender for Cloud, the compliance dashboard cannot collect the necessary data to evaluate compliance. Option B is incorrect because configuring the dashboard to show PCI DSS controls is a subsequent step after ensuring coverage. Option C is incorrect because creating a custom standard is not the first step; the built-in PCI DSS initiative should be used. Option D is incorrect because the built-in PCI DSS policy initiative in Azure Policy does not automatically apply to resources unless Defender for Cloud is already enabled and the initiative is assigned; enabling Defender for Cloud is the prerequisite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Microsoft Defender for Cloud on all subscriptions and ensure resources are covered.

    Why this is correct

    Microsoft Defender for Cloud is the required assessment engine that evaluates Azure resources against built-in regulatory compliance standards such as PCI DSS. Enabling Defender for Cloud on every subscription and confirming that all resources are covered ensures the underlying Azure Policy initiative is automatically assigned and the regulatory compliance dashboard can collect continuous assessment data. Without this onboarding step, the compliance standard will have no resources to evaluate and will display an incomplete or zero score, making this the mandatory first action.

  • ✗

    Configure the compliance dashboard to show PCI DSS controls.

    Why it's wrong here

    The regulatory compliance dashboard in Defender for Cloud is a visualization layer; selecting PCI DSS from the standard list merely changes which control categories are displayed, not the underlying assessment process. If resources have not been onboarded and evaluated, the dashboard will show an empty compliance score and no control results, even after configuration. Configuring the dashboard does not trigger assessments or assign policy initiatives, so it must occur after onboarding and is only a viewing convenience.

  • ✗

    Create a custom regulatory compliance standard for PCI DSS.

    Why it's wrong here

    Defender for Cloud already ships with a built-in PCI DSS regulatory compliance standard that is directly mapped to the official PCI DSS controls and linked to the appropriate Azure Policy initiatives. Creating a custom standard is unnecessary for meeting PCI DSS, and it involves manually selecting and mapping initiatives to controls, which is time-consuming and error-prone. Even if a custom standard were created, it would not solve the fundamental problem that resources are not yet assessed, so the compliance results would still be empty.

  • ✗

    Enable the built-in PCI DSS policy initiative in Azure Policy.

    Why it's wrong here

    Enabling the built-in PCI DSS policy initiative directly in Azure Policy does assess resource configuration, but it bypasses the Defender for Cloud regulatory compliance integration that displays the compliance score. Defender for Cloud automatically assigns the initiative as part of onboarding a subscription to the regulatory compliance standard, and it also requires the subscription to have Defender plans enabled for certain resource types. Manually assigning the initiative without first enabling Defender for Cloud leaves gaps in the compliance dashboard and duplicates the onboarding process, so it is not the correct first step.

About these practice questions

This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.