hardMultiple ChoiceObjective-mapped
SC-200 Practice Question: Needs to meet PCI DSS compliance requirements and…
An organization needs to meet PCI DSS compliance requirements and also enforce a custom policy requiring that encryption keys be stored in a specific Azure Key Vault. The security administrator wants to view a unified compliance score that includes both the built-in PCI DSS standard and the custom policy. What should the administrator do in Microsoft Defender for Cloud?
⚠ Common exam trap
Test-takers frequently assume simply assigning the built-in standard and adding a custom policy separately will merge their scores, but Defender for Cloud requires all policies to be part of the same initiative for a unified compliance score.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a custom initiative that includes the PCI DSS built-in policy set and the custom key vault policy, then assign it to the scope
Microsoft Defender for Cloud's regulatory compliance dashboard can only display a unified compliance score when all relevant standards and custom policies are grouped into a single initiative. By creating a custom initiative that includes both the built-in PCI DSS policy set and the custom Key Vault policy, then assigning that initiative to the scope, the administrator ensures the compliance score reflects both requirements in one view.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the built-in PCI DSS regulatory compliance standard and add a custom policy through Azure Policy
Why it's wrong here
The built-in PCI DSS regulatory compliance standard in Defender for Cloud is an Azure Policy initiative that is read-only; you cannot append a custom policy definition to it. Trying to "add a custom policy through Azure Policy" to this built-in initiative is not supported because built-in initiative definitions are immutable across the tenant. To enforce a custom Key Vault policy alongside the standard, you must create a new custom initiative that references the built-in PCI DSS policy set plus your custom policy, then assign that custom initiative to the target scope.
- ✓
Create a custom initiative that includes the PCI DSS built-in policy set and the custom key vault policy, then assign it to the scope
Why this is correct
Creating a custom initiative lets you combine the built-in PCI DSS policy set with a custom Key Vault policy definition into one assignable Azure Policy object, which overcomes the read-only nature of built-in regulatory standards. After assignment to the management group, subscription, or resource group, this initiative appears under Defender for Cloud's Regulatory Compliance dashboard because custom initiatives are supported there and are evaluated against the corresponding compliance controls. This is the only option that both enforces the custom Key Vault requirement and surfaces the result as part of the PCI DSS compliance view.
- ✗
Use Azure Blueprints to deploy the PCI DSS standard and custom policies
Why it's wrong here
Azure Blueprints can deploy policy definitions and assignments as artifacts, but those assignments are not mapped to Defender for Cloud's regulatory compliance standards in the same way as a custom initiative created from the compliance dashboard. The PCI DSS built-in standard is still an Azure Policy initiative; to include a custom Key Vault policy, the definition must be part of a custom initiative, and Blueprints does not provide that composition mechanism for the regulatory compliance view. Thus, a blueprint may enforce compliance mechanically but fails to satisfy the dashboard/reporting requirement.
- ✗
Enable the Secure Score dashboard to measure compliance
Why it's wrong here
Secure Score is a quantitative posture assessment based on the Microsoft cloud security benchmark, not on PCI DSS regulatory requirements, so merely enabling the Secure Score dashboard cannot enforce a custom Key Vault policy or demonstrate PCI DSS compliance. The score reflects recommendations from built-in security controls and changes as those recommendations are remediated, but it does not map to PCI DSS control IDs and does not include your custom policy as an enforceable initiative. Regulatory compliance needs an assigned initiative that contains both the PCI DSS definitions and the custom policy, not just a scoreboard.
Go deeper
Related to this question
About these practice questions
One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SC-200
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A company wants to continuously assess the compliance of their Azure resources against the CIS (Center for Internet Security) benchmark. Which Microsoft Defender for Cloud feature should they use?
easy- ✓ A.Regulatory compliance dashboard
- B.Secure score
- C.Azure Policy
- D.Workload protections
Why A: The Regulatory compliance dashboard in Microsoft Defender for Cloud provides pre-built assessments and continuous monitoring against specific compliance standards, including the CIS benchmark. It automatically evaluates Azure resources against CIS controls and displays compliance status, making it the correct feature for this requirement.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.