Courseiva

SC-100 Design security solutions for infrastructure Practice Question

You are designing a secure infrastructure for an e-commerce platform hosted on Azure. The platform must meet PCI DSS compliance. Which Azure service should you use to centrally manage and monitor security policies across subscriptions?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Azure Policy

Azure Policy is the correct choice because it is the Azure service designed to centrally create, assign, and manage policy definitions that enforce and audit security and compliance rules across subscriptions, which directly supports PCI DSS governance at scale. It evaluates resources against built-in or custom policies and reports compliance state, making it suitable for monitoring policy adherence across multiple subscriptions. Azure Firewall (B) is a network security service that filters traffic but does not manage or monitor security policies across subscriptions. Microsoft Defender for Cloud (C) provides security posture management and threat protection, but it is not the primary mechanism for centrally defining and enforcing policy rules across subscriptions. Azure Blueprints (D) is used to package and deploy governed environments with artifacts like policies and role assignments, but it is not the central ongoing policy management and monitoring service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Azure Policy

    Why this is correct

    Azure Policy is the correct service for centrally managing and monitoring security policies because it provides a unified governance plane for creating, assigning, and managing policy definitions and initiatives at management group, subscription, or resource group scope. It continuously evaluates resources against your compliance rules using effects such as Deny, Audit, Append, and DeployIfNotExists, and it presents a compliance dashboard showing the state of your environment. Built-in initiatives like the Microsoft Cloud Security Benchmark are delivered through Azure Policy, making it the primary service for enforcing security and compliance standards across all Azure resources.

  • ✗

    Azure Firewall

    Why it's wrong here

    Azure Firewall is a stateful, cloud-native network security service that inspects and filters traffic at layers 3-7 using application and network rule collections. While you can use Azure Policy to govern how Azure Firewall is deployed or to enforce firewall configuration, Azure Firewall itself is not a policy management tool. The term 'policy' in Azure Firewall refers to firewall policy objects that define NAT, network, and application rules—these are distinctly different from Azure Policy's compliance and audit rules, so it cannot centrally manage security policies across subscriptions.

  • ✗

    Microsoft Defender for Cloud

    Why it's wrong here

    Microsoft Defender for Cloud is a cloud security posture management (CSPM) and workload protection platform that aggregates security findings and gives prioritized recommendations, such as enabling encryption or fixing vulnerable configurations. Under the hood, Defender for Cloud assigns and consumes Azure Policy definitions—for example, the built-in security policies it creates are actually Azure Policy assignments—but it is not the central policy management service. It uses policy results to drive its regulatory compliance dashboard and recommendations, and it does not replace Azure Policy as the engine for policy enforcement or the single source of truth for policy definitions.

  • ✗

    Azure Blueprints

    Why it's wrong here

    Azure Blueprints is an orchestration service for composing deployable environments, allowing you to package ARM templates, role assignments, policy assignments, and resource groups into a single blueprint artifact. However, it relies on Azure Policy for any compliance enforcement it includes; it does not provide the evaluation engine, effects, or compliance reporting that define a central policy management service. Its purpose is repeatable environment deployment, not ongoing policy governance across subscriptions.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.