Courseiva
hardMultiple ChoiceObjective-mapped

SC-200 Practice Question: Needs to meet PCI DSS compliance requirements and…

An organization needs to meet PCI DSS compliance requirements and also enforce a custom policy requiring that encryption keys be stored in a specific Azure Key Vault. The security administrator wants to view a unified compliance score that includes both the built-in PCI DSS standard and the custom policy. What should the administrator do in Microsoft Defender for Cloud?

⚠ Common exam trap

Test-takers frequently assume simply assigning the built-in standard and adding a custom policy separately will merge their scores, but Defender for Cloud requires all policies to be part of the same initiative for a unified compliance score.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Create a custom initiative that includes the PCI DSS built-in policy set and the custom key vault policy, then assign it to the scope

Microsoft Defender for Cloud's regulatory compliance dashboard can only display a unified compliance score when all relevant standards and custom policies are grouped into a single initiative. By creating a custom initiative that includes both the built-in PCI DSS policy set and the custom Key Vault policy, then assigning that initiative to the scope, the administrator ensures the compliance score reflects both requirements in one view.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assign the built-in PCI DSS regulatory compliance standard and add a custom policy through Azure Policy

    Why it's wrong here

    The built-in PCI DSS regulatory compliance standard in Defender for Cloud is an Azure Policy initiative that is read-only; you cannot append a custom policy definition to it. Trying to "add a custom policy through Azure Policy" to this built-in initiative is not supported because built-in initiative definitions are immutable across the tenant. To enforce a custom Key Vault policy alongside the standard, you must create a new custom initiative that references the built-in PCI DSS policy set plus your custom policy, then assign that custom initiative to the target scope.

  • Create a custom initiative that includes the PCI DSS built-in policy set and the custom key vault policy, then assign it to the scope

    Why this is correct

    Creating a custom initiative lets you combine the built-in PCI DSS policy set with a custom Key Vault policy definition into one assignable Azure Policy object, which overcomes the read-only nature of built-in regulatory standards. After assignment to the management group, subscription, or resource group, this initiative appears under Defender for Cloud's Regulatory Compliance dashboard because custom initiatives are supported there and are evaluated against the corresponding compliance controls. This is the only option that both enforces the custom Key Vault requirement and surfaces the result as part of the PCI DSS compliance view.

  • Use Azure Blueprints to deploy the PCI DSS standard and custom policies

    Why it's wrong here

    Azure Blueprints can deploy policy definitions and assignments as artifacts, but those assignments are not mapped to Defender for Cloud's regulatory compliance standards in the same way as a custom initiative created from the compliance dashboard. The PCI DSS built-in standard is still an Azure Policy initiative; to include a custom Key Vault policy, the definition must be part of a custom initiative, and Blueprints does not provide that composition mechanism for the regulatory compliance view. Thus, a blueprint may enforce compliance mechanically but fails to satisfy the dashboard/reporting requirement.

  • Enable the Secure Score dashboard to measure compliance

    Why it's wrong here

    Secure Score is a quantitative posture assessment based on the Microsoft cloud security benchmark, not on PCI DSS regulatory requirements, so merely enabling the Secure Score dashboard cannot enforce a custom Key Vault policy or demonstrate PCI DSS compliance. The score reflects recommendations from built-in security controls and changes as those recommendations are remediated, but it does not map to PCI DSS control IDs and does not include your custom policy as an enforceable initiative. Regulatory compliance needs an assigned initiative that contains both the PCI DSS definitions and the custom policy, not just a scoreboard.

About these practice questions

One of 209 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SC-200

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company wants to continuously assess the compliance of their Azure resources against the CIS (Center for Internet Security) benchmark. Which Microsoft Defender for Cloud feature should they use?

easy
  • A.Regulatory compliance dashboard
  • B.Secure score
  • C.Azure Policy
  • D.Workload protections

Why A: The Regulatory compliance dashboard in Microsoft Defender for Cloud provides pre-built assessments and continuous monitoring against specific compliance standards, including the CIS benchmark. It automatically evaluates Azure resources against CIS controls and displays compliance status, making it the correct feature for this requirement.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.