SC-200 Manage a security operations environment Practice Question
Which THREE capabilities are provided by Microsoft Defender for Cloud's Cloud Security Posture Management (CSPM) plan? (Select THREE.)
⚠ Common exam trap
Watch out — candidates often confuse the CSPM plan's compliance and secure score capabilities with workload protection features like vulnerability assessment or EDR, which belong to separate Defender plans (e.g., Defender for Servers or Defender for Endpoint).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compliance dashboard that shows your posture against regulatory standards.
Microsoft Defender for Cloud's CSPM plan includes a compliance dashboard that continuously assesses your cloud resources against regulatory standards such as SOC 2, ISO 27001, and PCI DSS. This dashboard provides a real-time view of your compliance posture, mapping security controls to specific regulatory requirements and highlighting non-compliant resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compliance dashboard that shows your posture against regulatory standards.
Why this is correct
The compliance dashboard in Microsoft Defender for Cloud provides a continuous view of your regulatory compliance posture, mapping security assessments to standards such as CIS Controls, NIST SP 800-53, and Azure CIS. It tracks compliance against these frameworks over time, shows which controls are failing, and lets you download evidence for audits. This is a core Cloud Security Posture Management (CSPM) capability, distinct from individual workload protections.
- ✓
Continuous assessment of your cloud resources against security best practices.
Why this is correct
Microsoft Defender for Cloud continuously evaluates your Azure and hybrid cloud resources against built-in security best practices and industry benchmarks, detecting misconfigurations and drift from a secure baseline. Using the assessment engine and Azure Policy integrations, it produces a list of prioritized recommendations with remediation steps. Unlike a one-time audit, this is an ongoing, always-on assessment, making it a foundational capability of CSPM.
- ✗
Endpoint detection and response for on-premises machines.
Why it's wrong here
Endpoint detection and response (EDR) for on-premises machines is provided by Microsoft Defender for Endpoint, not by the CSPM features of Microsoft Defender for Cloud. While Defender for Cloud can onboard and surface alerts from Defender for Endpoint as part of workload protections, the EDR functionality itself—behavioral analysis, threat hunting, and incident response on endpoints—is a distinct product capability. Therefore this is not one of the three core CSPM capabilities.
- ✓
Secure score calculation based on implemented security controls.
Why this is correct
Secure score in Microsoft Defender for Cloud measures your security posture by calculating a percentage derived from the security controls you have implemented relative to the total possible score. Each recommendation contributes to a specific control, and the score weights controls based on exploitability and potential impact, helping prioritize remediation. This aggregated metric, along with continuous assessment and compliance dashboards, forms the heart of Cloud Security Posture Management.
- ✗
Integrated vulnerability assessment for virtual machines.
Why it's wrong here
Although Microsoft Defender for Cloud can include integrated vulnerability assessment for virtual machines, this capability is part of the Defender for Servers workload protection plan (a paid add-on), not the core CSPM feature set. The VM vulnerability scanner, powered by Qualys or Microsoft Defender Vulnerability Management, is delivered as a workload protection rather than a default posture management capability. Thus it is incorrectly listed among the three foundational CSPM capabilities.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.