Courseiva
easyMultiple Choice

SC-200 Practice Question: Continuously assess the compliance of their Azure…

A company wants to continuously assess the compliance of their Azure resources against the CIS (Center for Internet Security) benchmark. Which Microsoft Defender for Cloud feature should they use?

⚠ Common exam trap

It's easy for candidates to confuse Secure score (which measures overall security hygiene) with the Regulatory compliance dashboard (which measures adherence to specific standards like CIS), leading them to select Secure score when the question explicitly asks for compliance against a benchmark.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regulatory compliance dashboard

The Regulatory compliance dashboard in Microsoft Defender for Cloud provides pre-built assessments and continuous monitoring against specific compliance standards, including the CIS benchmark. It automatically evaluates Azure resources against CIS controls and displays compliance status, making it the correct feature for this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Regulatory compliance dashboard

    Why this is correct

    The Regulatory compliance dashboard in Defender for Cloud is the dedicated feature that continuously assesses your Azure resources against built-in standards such as the CIS Microsoft Azure Foundations Benchmark and NIST SP 800-53. When you add a standard, Defender for Cloud assigns the corresponding Azure Policy initiative to your subscriptions, and the dashboard then shows the compliance state for each control, including the number of passed and failed resources. This dashboard is the correct choice because it explicitly links continuous policy evaluation to regulatory frameworks, allowing you to track and prove compliance over time.

  • ✗

    Secure score

    Why it's wrong here

    Secure score is a percentile-based measure of how well you have implemented Microsoft's recommended security controls, aggregated across all resources in the environment. It is calculated from the remediation of Defender for Cloud recommendations, not from the specific control requirements of a compliance standard like CIS. Although a secure score of 100% may indicate a strong hardening posture, it does not demonstrate compliance with any particular regulatory framework, and you can have a high secure score while still failing specific CIS controls.

  • ✗

    Azure Policy

    Why it's wrong here

    Azure Policy is the underlying rule-authoring and enforcement engine that applies initiatives to subscriptions, but by itself it does not present a consolidated compliance view against benchmark frameworks. Defender for Cloud does use Azure Policy to run the built-in CIS assignments, yet the service's Regulatory compliance dashboard is the actual interface that aggregates those continuous evaluations and shows which standards and controls are passing. Simply assigning a policy in Azure Policy does not give you the compliance dashboard experience; that is a Defender for Cloud feature.

  • ✗

    Workload protections

    Why it's wrong here

    Workload protections in Defender for Cloud are focused on runtime threat detection and vulnerability management for compute, storage, and databases—not on evaluating resource configuration against regulatory frameworks. While those protections may generate alerting and recommendations, they do not provide a standards-based compliance scorecard that tracks controls like CIS MIS or NIST SP 800-53. Compliance assessment is about continuous configuration auditing and control mapping, which is fundamentally different from detecting an ongoing attack or suspicious activity.

About these practice questions

Courseiva writes every SC-200 question from scratch — 1,303 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.