Design security operations, identity, and compliance capabilities →hardMultiple ChoiceObjective-mapped
SC-100 Practice Question: Design security operations, identity, and compliance capabilities
Your organization uses Microsoft Defender for Cloud to secure multi-cloud workloads. You need to ensure that Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP) resources are assessed against the same security baseline. What should you do?
⚠ Common exam trap
Many candidates confuse enabling the CSPM plan and connectors (Option D) with the complete solution, forgetting that a specific baseline policy (MCSB) must be assigned via Azure Policy to enforce the unified assessment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Connect AWS and GCP accounts to Defender for Cloud and use Azure Policy to enforce the Microsoft Cloud Security Benchmark
Microsoft Defender for Cloud's multi-cloud CSPM capabilities allow you to connect AWS and GCP accounts directly, and then apply Azure Policy to enforce the Microsoft Cloud Security Benchmark (MCSB) across all connected clouds. This ensures a unified security baseline assessment for Azure, AWS, and GCP resources, as MCSB is the default policy initiative in Defender for Cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure AWS Config and GCP Security Command Center to export findings to Microsoft Sentinel
Why it's wrong here
Exporting AWS Config and GCP Security Command Center data to Microsoft Sentinel centralizes alerts and logs in a SIEM, enabling cross-cloud detection and investigation, but it does not enforce a security baseline. Sentinel is reactive—it analyzes ingested signals; it cannot automatically deploy configuration policies or remediate noncompliant resources. A single baseline requires continuous compliance assessment and governance, which Azure Policy in Defender for Cloud provides, not log ingestion.
- ✓
Connect AWS and GCP accounts to Defender for Cloud and use Azure Policy to enforce the Microsoft Cloud Security Benchmark
Why this is correct
Connecting AWS and GCP accounts to Defender for Cloud surfaces those resources in Azure Resource Graph, where Azure Policy can apply the Microsoft Cloud Security Benchmark (MCSB), a unified initiative built on CIS/NIST plus Microsoft controls. This gives continuous compliance assessment and enforcement, like DeployIfNotExists remediation, across all clouds. As a result, every subscription or cloud account is measured against the same baseline, regardless of native cloud tooling—this is the only option that both centralizes and enforces a single baseline.
- ✗
Use regulatory compliance standards for each cloud separately
Why it's wrong here
Using each cloud's own regulatory compliance standards—like Center for Internet Security benchmarks for AWS, GCP, and Azure—fragments the baseline because those standards differ in control mappings, versioning, and scope. Regulatory compliance is a framework mapping, not a customizable security policy that can be enforced across clouds; it only reports adherence. Without a common control framework like the Microsoft Cloud Security Benchmark, you cannot enforce a single, consistent security baseline across all environments.
- ✗
Enable the Cloud Security Posture Management (CSPM) plan and configure AWS and GCP connectors
Why it's wrong here
Enabling the CSPM plan and configuring AWS/GCP connectors provides asset visibility and security recommendations from Defender for Cloud, which is a necessary precursor for multi-cloud governance. However, by default CSPM assesses each cloud against its own native recommendations—AWS Security Hub controls and GCP security analytics—rather than a single policy set. To enforce a unified baseline, you must attach Azure Policy initiatives like MCSB to the connectors; otherwise, you have posture data but not standardized enforcement.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 208-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.