SC-200 Manage a security operations environment Practice Question
Your company uses Microsoft Defender for Cloud to monitor multi-cloud resources. You want to ensure that all critical security recommendations are automatically assigned to the appropriate team leads based on the resource's tags. Which feature should you configure?
⚠ Common exam trap
Many exam-takers confuse governance rules (which enforce compliance standards or auto-remediation) with the 'Assign ownership' feature, which specifically handles tag-based assignment of recommendations to users.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the 'Assign ownership' feature in Microsoft Defender for Cloud to map tags to owners.
The 'Assign ownership' feature in Microsoft Defender for Cloud allows you to map resource tags to specific owners (e.g., team leads) via an automated rule. When a critical security recommendation is generated for a resource with a matching tag, the recommendation is automatically assigned to the designated owner, ensuring accountability without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a regulatory compliance standard to send email notifications.
Why it's wrong here
Regulatory compliance standards in Defender for Cloud, such as Azure Security Benchmark or CIS, continuously assess resources against a defined set of controls, but they have no built-in mechanism to send email notifications or to route recommendations to specific owners. Email notifications are configured separately in the portal's email alert settings and only alert about a selected set of alerts, not assign accountability. Even if a standard is applied, every recommendation remains unowned until an explicit ownership rule is defined, so this approach does not address the core assignment problem.
- ✗
Create a workbook that lists recommendations and manually assign them.
Why it's wrong here
A workbook in Defender for Cloud is an Azure Monitor workbook that provides a customizable, read-only dashboard built from KQL queries; it can surface recommendation lists and compliance trends, but it has no API or portal action to write back ownership assignments. Manually tracking ownership in a workbook would require a separate, continuous update process and would not integrate with Defender for Cloud's governance engine, so owners never receive notifications or see a personalized view. Because there is no authoritative record that Defender for Cloud recognizes, this method is both unscalable and ineffective for ensuring accountability.
- ✓
Use the 'Assign ownership' feature in Microsoft Defender for Cloud to map tags to owners.
Why this is correct
The 'Assign ownership' feature in Microsoft Defender for Cloud lets you configure resource tag keys (for example, 'owner' or 'business-unit') and map the tag values to Microsoft Entra ID users or groups, which then become recommendation owners. This creates a governance rule that automatically assigns every recommendation for resources with matching tags to the designated owner, optionally with a fix timeframe and escalation path. This is the native, purpose-built mechanism for distributing security recommendation ownership across teams, and it is the correct way to ensure each recommendation is acted upon.
- ✗
Create a governance rule that automatically applies a compliance standard.
Why it's wrong here
Governance rules in Defender for Cloud are designed to enforce ownership assignment and remediation timeframes on recommendations, not to apply or enable regulatory compliance standards. Applying a compliance standard (such as NIST SP 800-53 or HIPAA) is done by adding the standard in the 'Regulatory compliance' blade, which only adds the corresponding security assessments to your environment. Creating a governance rule to 'apply a compliance standard' is not a valid operation; governance rules act on existing recommendations after a standard is active, so this option is fundamentally mismatched with the required outcome.
Go deeper
Related to this question
About these practice questions
One of 1,303 original SC-200 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-200 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-200 exam.