Courseiva
mediumMultiple Choice

How to Add Regulatory Compliance Standards to Defender for Cloud Dashboard

A security administrator is configuring Microsoft Defender for Cloud's regulatory compliance dashboard. The organization needs to be compliant with the NIST SP 800-53 standard. Which built-in initiative should the administrator assign to the subscription to populate the dashboard with NIST controls?

⚠ Common exam trap

Watch out — candidates often confuse the Azure Security Benchmark (a Microsoft best-practice framework) with a regulatory standard, assuming it covers NIST controls, when in fact it is a separate initiative that does not map to NIST SP 800-53.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NIST SP 800-53 R5

The NIST SP 800-53 R5 built-in initiative is the correct choice because Microsoft Defender for Cloud includes a dedicated regulatory compliance policy initiative that maps directly to the NIST SP 800-53 standard's controls. Assigning this initiative to the subscription populates the regulatory compliance dashboard with the specific NIST controls and their compliance status, enabling the organization to track and report against that framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Azure Security Benchmark

    Why it's wrong here

    The Azure Security Benchmark is a Microsoft-authored collection of security configuration baselines and recommendations for Azure, designed as a starting point for hardening workloads. It maps to well-known industry frameworks but does not itself implement the specific control families or assessment logic of NIST SP 800-53. In Defender for Cloud, selecting this initiative evaluates resources against Microsoft's own best-practice guidelines, not against NIST's federal compliance requirements.

  • ✓

    NIST SP 800-53 R5

    Why this is correct

    NIST SP 800-53 R5 is a built-in compliance initiative within Microsoft Defender for Cloud that automatically assesses Azure resources against the National Institute of Standards and Technology's Special Publication 800-53 Revision 5 controls. This initiative maps Azure Policy definitions to NIST control families such as access control, audit, and risk assessment, providing a compliance score in the regulatory compliance dashboard. When a regulatory requirement calls for NIST SP 800-53, this is the correct built-in standard to enable.

  • ✗

    CIS Microsoft Azure Foundations Benchmark

    Why it's wrong here

    The CIS Microsoft Azure Foundations Benchmark is a set of configuration recommendations published by the Center for Internet Security, focusing on security hardening for Azure services rather than regulatory compliance. It contains specific checks like enabling MFA and disabling insecure protocols, but its structure (CIS controls) is unrelated to NIST SP 800-53's containment and assessment methodology. Choosing this initiative would measure posture against CIS best practice, not against NIST's federal control framework.

  • ✗

    ISO 27001

    Why it's wrong here

    ISO 27001 is an international standard for information security management systems, with control objectives listed in Annex A rather than NIST's Rev 5 control families. Although both cover security governance, they have different control identifiers, inheritance rules, and assessment mappings. Acting on NIST SP 800-53 compliance requirements would not be satisfied by enabling the ISO 27001 initiative in Defender for Cloud, because that initiative verifies against a different set of requirements.

About these practice questions

This SC-200 question is part of Courseiva's 1,303-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.