Courseiva
hardMultiple ChoiceObjective-mapped

SC-200 Practice Question: A global organization has Azure subscriptions…

A global organization has Azure subscriptions organized under a single management group. The security team wants to ensure that the Azure Security Benchmark initiative is assigned once to cover all current and future subscriptions within that management group, without needing to assign it individually. They also want to see compliance results aggregated at the management group level. In Microsoft Defender for Cloud, what is the correct approach to achieve this?

⚠ Common exam trap

Candidates often think enabling enhanced security features in Defender for Cloud automatically applies the Azure Security Benchmark, but in reality, the benchmark must be explicitly assigned as a policy initiative, and the management group scope is the correct way to cover all subscriptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assign the Azure Security Benchmark initiative directly to the management group via Azure Policy, and use the Defender for Cloud's Regulatory Compliance dashboard.

Assigning the Azure Security Benchmark initiative directly to the management group via Azure Policy ensures that the policy initiative is inherited by all current and future subscriptions under that management group. Defender for Cloud's Regulatory Compliance dashboard then aggregates compliance results at the management group level, providing a single view of compliance across the entire hierarchy without requiring individual assignments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign the Azure Security Benchmark initiative directly to the management group via Azure Policy, and use the Defender for Cloud's Regulatory Compliance dashboard.

    Why this is correct

    Assigning the Azure Security Benchmark initiative at the management group scope via Azure Policy applies the policy definitions to every subscription within that group through inheritance. Defender for Cloud's Regulatory Compliance dashboard then evaluates those assigned initiatives and aggregates the compliance results for the whole management group, providing a single-pane view of security controls. This is the intended method for centralized, organization-wide compliance monitoring because it avoids the need to assign the initiative separately to each subscription.

  • Enable Defender for Cloud's enhanced security features on each subscription, and the benchmark will be automatically applied.

    Why it's wrong here

    Enabling Defender for Cloud's enhanced security features (previously the Standard tier) activates Defender plans such as Defender for Servers or Defender for SQL, but it does not assign the Azure Security Benchmark policy initiative. The benchmark must be explicitly assigned as an Azure Policy initiative before Defender for Cloud can score compliance against it. Without that explicit assignment, no regulatory compliance data for the benchmark will appear, even if enhanced security features are turned on everywhere.

  • Create a custom assessment in Defender for Cloud that queries the management group scope.

    Why it's wrong here

    Defender for Cloud does not provide a feature to create custom assessments that aggregate compliance results across a management group scope. Custom assessments in Defender for Cloud are limited to specific subscriptions or workloads and cannot perform the governance-wide aggregation needed for regulatory compliance tracking. To track custom compliance requirements, you would author a custom Azure Policy initiative and assign it at the management group scope, then bring that initiative into Defender for Cloud's Regulatory Compliance dashboard—something the scenario's option does not describe.

  • Assign the initiative to the root management group using Azure Policy, then configure Defender for Cloud to ignore individual subscription assignments.

    Why it's wrong here

    Assigning the initiative to the root management group would indeed cause all subscriptions in the tenant to inherit the policy, but the scenario already identifies a specific management group as the target scope, so using root would unnecessarily apply the benchmark to unrelated subscriptions. Furthermore, Defender for Cloud has no configuration setting to 'ignore' individual subscription assignments, so the proposed second step is not a valid operation. Mixing scopes without a clear inheritance/exclusion strategy can lead to duplicate assignments or unintended policy effects, making this an incorrect and nonstandard approach.

About these practice questions

Courseiva writes every SC-200 question from scratch — 209 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.