Question 1,254 of 209
mediumMultiple ChoiceObjective-mapped
SC-200 Practice Question: Uses Microsoft Defender for Cloud and needs to…
An organization uses Microsoft Defender for Cloud and needs to track compliance with internal security policies that are not covered by any built-in regulatory standard. They want to see the compliance status for these internal controls in the Regulatory Compliance dashboard alongside other standards. What should they configure?
⚠ Common exam trap
Many exam-takers confuse custom assessments in the recommendations dashboard with custom compliance controls, not realizing that only custom Azure Policy initiatives are surfaced in the Regulatory Compliance dashboard.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom Azure Policy initiative with the required controls and assign it to the relevant scopes.
To track compliance with internal security policies not covered by built-in regulatory standards, you must create a custom Azure Policy initiative that defines the required controls and assign it to the relevant scopes. Defender for Cloud automatically evaluates resources against assigned initiatives and surfaces the compliance status in the Regulatory Compliance dashboard alongside built-in standards, allowing unified visibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a custom Azure Policy initiative with the required controls and assign it to the relevant scopes.
Why this is correct
Defender for Cloud's Regulatory Compliance dashboard is implemented through Azure Policy initiatives, so to track internal or custom controls you must create a custom initiative that includes the required policy definitions (e.g., audit, deny, or deployIfNotExists effects). Assign that initiative to the relevant management group or subscription, and map its controls to the compliance framework in Defender for Cloud. This automatically generates continuous compliance assessments and integrates the results into the secure score and compliance dashboard, which is exactly the intended method for tracking custom requirements.
- ✗
Create a custom assessment in the Microsoft Defender for Cloud recommendations dashboard.
Why it's wrong here
The Microsoft Defender for Cloud recommendations dashboard is not a canvas for creating custom assessments; recommendations are generated exclusively from security policies and built-in Azure Policy initiatives. There is no UI, PowerShell cmdlet, or REST API to author an ad-hoc custom assessment directly in the recommendations view. The only supported way to introduce custom recommendations—which are essentially assessments—is by adding custom Azure Policy initiatives, so attempting to create a custom assessment in the dashboard is not a valid action.
- ✗
Use the Secure Score API to develop a custom dashboard outside Defender for Cloud.
Why it's wrong here
The Secure Score API returns Microsoft-defined secure scores and per-control scores based on built-in recommendations; it does not contain data for custom compliance frameworks or internally defined controls. While you could build an external dashboard to visualize those scores, that dashboard would only reflect the standard security posture, not the custom controls you need to track. This approach also bypasses the native Regulatory Compliance dashboard, so it is not an equivalent mechanism for fulfilling the requirement of tracking internal controls within Defender for Cloud.
- ✗
Enable the "Custom compliance" feature in Defender for Cloud's pricing tier.
Why it's wrong here
Defender for Cloud's pricing tiers include Free and paid plans like Defender for Servers, but none of them expose a standalone feature named "Custom compliance." Regulatory compliance is not a separately toggled capability; rather, it is driven entirely by assigning Azure Policy initiatives that define the controls and standards to evaluate. There is no setting in the pricing tier that enables custom compliance tracking—you must create and assign custom Azure Policy initiatives to achieve that outcome, so this option is invalid.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 11, 2026
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.