Design solutions that align with security best practices and priorities →mediumMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design solutions that align with security best practices and priorities
Your organization uses Microsoft Defender for Cloud to assess the security posture of Azure resources. The security team wants to prioritize remediation of high-severity findings based on the greatest potential business impact. Which security policy or framework should you configure to align remediation with business priorities?
⚠ Common exam trap
Watch out — candidates often confuse the Secure Score dashboard (which measures overall security posture) with the Regulatory Compliance dashboard (which aligns remediation to specific business-impacting standards), leading them to select D instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the Regulatory Compliance dashboard
The Regulatory Compliance dashboard in Microsoft Defender for Cloud allows you to map security controls to specific regulatory standards (e.g., SOC 2, ISO 27001, PCI DSS) and track compliance posture. By selecting a framework that aligns with your organization's business obligations (e.g., a standard required by customers or regulators), you can prioritize remediation of high-severity findings based on the greatest potential business impact, such as fines or loss of certification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the Azure Security Benchmark initiative
Why it's wrong here
The Azure Security Benchmark initiative is a comprehensive set of security recommendations based on industry-accepted best practices, but it serves as a general security baseline rather than a business-impact-driven prioritization mechanism. While it helps you harden your environment across multiple domains, it does not incorporate organizational context such as asset criticality, data classification, or specific regulatory obligations that directly reflect business priorities. Consequently, following the benchmark alone will not tell you which findings to remediate first when business impact is the deciding factor.
- ✓
Enable the Regulatory Compliance dashboard
Why this is correct
The Regulatory Compliance dashboard in Microsoft Defender for Cloud maps security findings to specific regulatory standards (e.g., CIS, NIST SP 800-53, PCI DSS, ISO 27001) and tracks compliance status for each control. This directly ties security gaps to business and legal obligations, enabling you to prioritize remediation efforts based on which non-compliant controls carry the highest regulatory and business impact. By focusing on the standards that matter to your organization, you can align operational security work with audit deadlines, contractual obligations, and risk tolerance, making it the correct method for business-impact-centric prioritization.
- ✗
Set up workflow automation for high-severity findings
Why it's wrong here
Workflow automation for high-severity findings (e.g., using Azure Logic Apps or Microsoft Sentinel playbooks) is designed to trigger automated responses like opening incidents, sending emails, or creating tickets when a high-severity alert fires. However, severity in Defender for Cloud is determined by the potential security impact of the finding, not by the business criticality of the affected resource or its relevance to compliance mandates. Therefore, while automation improves response efficiency, it does not prioritize which findings matter most to your organization; it only reacts to a predefined, generic severity level without considering business context.
- ✗
Configure the Secure Score dashboard
Why it's wrong here
The Secure Score dashboard aggregates all security recommendations into a single posture score, giving you a high-level view of your overall security hygiene. However, it treats each recommendation equally for scoring purposes, so it does not weigh findings by business impact, asset sensitivity, or regulatory requirements. A low-severity finding on a non-critical resource can contribute as much score improvement as a high-impact finding on a crown-jewel asset, misleading prioritization. Thus, Secure Score is useful for tracking general security health but is not designed to guide business-driven remediation order.
Go deeper
Related to this question
About these practice questions
One of 208 original SC-100 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.